Today's Top Stories:

  • FBI classifies China hack as "major incident." Hackers linked to the Chinese government breached an FBI system containing wiretap data, surveillance returns, and PII on investigation subjects. It's the first "major incident" designation on FBI systems since at least 2020.
  • EU Chat Control scanning expires today. The European Parliament killed the extension. Starting April 4, Meta, Google, and Microsoft can no longer scan private messages in the EU.
  • PCLOB drops new Section 702 report. FBI warrantless queries dropped from 57,000 in 2023 to 7,400 in 2025. Good news, but Section 702 still expires in 17 days with no clear path forward.
  • Hasbro breached, weeks of recovery ahead. The toymaker disclosed an SEC filing on April 1 after detecting an intrusion on March 28. Systems taken offline, scope unknown.
  • 60+ groups demand Congress block Meta facial recognition glasses. April 6 senator deadline approaching.

FBI Declares China Hack of Surveillance System a "Major Incident"

The FBI notified Congress on April 1-2 that a suspected Chinese hacking group breached one of its surveillance systems, and they're calling it a "major incident" under the Federal Information Security Modernization Act [1].

That designation matters. Former FBI Cyber Division deputy assistant director Cynthia Kaiser told Politico that, to the best of her knowledge, the FBI hasn't declared a major cyber incident since 2020. The thresholds under FISMA are high. The FBI just cleared them.

What was hit: An unclassified system containing law enforcement sensitive information: returns from pen registers and trap-and-trace surveillance, and personally identifiable information on subjects of active FBI investigations. The kind of data that tells a foreign intelligence service exactly who the FBI is watching, including potentially their own operatives inside the United States [2].

How they got in: The attackers exploited a commercial ISP vendor's infrastructure. Same strategy as Salt Typhoon, which compromised at least nine US telecom companies and their lawful intercept systems. Find the surveillance infrastructure, break into it through a third-party vendor, turn the watchers' tools against them.

The intrusion was detected February 17 and reportedly contained quickly. But "contained quickly" and "no damage done" aren't the same thing when the stolen data reveals the targets of active investigations.

The irony writes itself. The FBI wants warrantless access to Americans' communications under Section 702, which expires in 17 days. The FBI also can't keep its own surveillance databases safe from the exact adversaries it's supposed to be monitoring.

Related: FBI Surveillance System Breach (March) | Salt Typhoon: Worst Telecom Hack in US History

EU Chat Control Scanning Dies Today

It's April 3. Chat Control 1.0 expires today [3].

On March 26, the European Parliament voted 311-228 (with 92 abstentions) to reject extending the temporary derogation from the ePrivacy Directive that let platforms voluntarily scan private messages for child sexual abuse material. That framework officially dies today [4].

What changes immediately: Starting April 4, Meta, Google, Microsoft, and other platforms operating in the EU will no longer have a legal basis to conduct mass scanning of private messages. The indiscriminate monitoring of EU citizens' private communications, which privacy advocates have fought for years, ends.

The European People's Party pushed hard to keep scanning alive, arguing it was necessary to detect and prevent online abuse. But the Socialists & Democrats, most of Renew Europe, the Greens, and The Left held the line. CDT Europe called the vote a "necessary step toward protecting fundamental rights in the digital age" [5].

This isn't the end of the fight. Negotiations for the permanent CSAR regulation (Chat Control 2.0) continue, with trilogue sessions scheduled for May 4 and June 29. The Commission still wants mandatory scanning. The question now is whether they'll try to mandate what they can no longer authorize voluntarily, and whether they'll go after end-to-end encryption.

Platforms still have to remove illegal content under the Digital Services Act. But they can't fish through everyone's messages to find it anymore.

Related: EU Chat Control: Why April 3 Matters | Signal Threatened to Leave EU Over Chat Control | CSAR: The Encryption Scanning Fight

PCLOB Drops New Section 702 Report: 17 Days to Go

The Privacy and Civil Liberties Oversight Board released its updated report on FISA Section 702 on April 2, right as Congress is supposed to decide whether to renew, reform, or kill the program by April 20 [6].

The numbers that matter:

  • FBI warrantless US person queries dropped from roughly 57,000 in 2023 to 7,400 in 2025
  • Targeting compliance exceeds 99%
  • FBI query compliance hit 98.5% under new rules
  • Almost two-thirds of the President's Daily Brief in 2025 contained Section 702 intelligence

The compliance numbers give reformers ammunition to say oversight works. The intelligence value numbers give hawks ammunition to say the program is essential. Neither side gets a clean win.

Meanwhile, the political math hasn't changed. The Congressional Progressive Caucus (98 House Democrats) voted to oppose any reauthorization without "dramatic reforms." A dozen-plus GOP holdouts want the same. Senate Intel Chair Tom Cotton wants an 18-month clean extension with zero reforms [7].

The ODNI also dropped its annual transparency report on April 1, showing Section 702 targets increased again, consistent with prior years. More targets, fewer FBI queries, same fundamental question: should any of this happen without a warrant?

Related: FISA 702 Countdown | Government Surveillance Reform Act Analysis | 98 Democrats Oppose Clean Extension

Hasbro Breached: Weeks of Recovery Ahead

Hasbro (the company behind Monopoly, Magic: The Gathering, and My Little Pony) disclosed to the SEC on April 1 that it detected an intrusion on March 28 [8].

The company took systems offline for containment and says it may take "several weeks" to fully recover. An investigation with third-party cybersecurity professionals is underway, but Hasbro hasn't confirmed whether any data was stolen or what type of attack this was. No ransomware group has claimed responsibility yet.

With over 5,000 employees and millions of customers across its gaming and entertainment properties, the potential blast radius is significant. Hasbro says it's running business continuity plans to keep taking orders and shipping products, but the fact that they're filing with the SEC and warning of weeks-long disruption tells you this isn't a minor incident.

Meta Smart Glasses: 60+ Groups Tell Congress to Act

The opposition to Meta's facial recognition smart glasses plans keeps growing. More than 60 civil society organizations, led by the Consumer Federation of America and UltraViolet Action, have written to Congress urging action against the technology [9].

Their argument: Meta Ray-Bans with facial recognition would let any user scan thousands of faces in a single day. No consent mechanism for bystanders. No practical way for anyone to know they're being identified in real time. The groups call it a "creepy and unacceptable escalation of surveillance."

The letter follows a Swedish media investigation that uncovered Meta subcontractors in Kenya data-labeling video from the smart glasses, including footage of bathroom visits, sex, and personal information like bank accounts [10]. Senators Markey, Wyden, and Merkley gave Meta until April 6 to respond to their questions about consent, data retention, AI training, and law enforcement sharing.

April 6 is Sunday. Meta's silence or response will say a lot about where this is headed.

Related: Senators Press Meta on Smart Glasses | 64 Groups Oppose Meta Facial Recognition Glasses | Kenya Contractors and Intimate Footage

Quick Hits

  • ODNI transparency report confirms Section 702 target increase. The 13th annual Intelligence Community Transparency Report, released April 1, shows the number of FISA Section 702 targets continued to rise in 2025. The report also covers NSL usage and other national security authorities [11].
  • Navia breach notification continues rolling out. Benefits administrator Navia Benefit Solutions is still notifying 2.7 million affected individuals whose SSNs, dates of birth, and health plan data were exposed during a Dec 22, 2025 - Jan 15, 2026 intrusion. Multiple class actions expected [12]. Our Coverage
  • Washington state deepfake protections signed. Governor Bob Ferguson signed Senate Bill 5886, expanding personality rights law to cover "forged digital likenesses": AI-manipulated audio, video, or images that misrepresent someone's appearance, speech, or conduct [13].
  • Data broker warrant bill gains traction. The Government Surveillance Reform Act (Wyden-Lee-Davidson-Lofgren) would close the data broker loophole, require warrants for communications access, and ban reverse targeting. 130+ civil society organizations back it [14]. Our Analysis

What to Watch

  • April 6: Meta's deadline to respond to Senators Markey, Wyden, and Merkley on facial recognition smart glasses plans
  • April 16: Next EU CSAR trilogue session, the fight for Chat Control 2.0 continues
  • April 20: FISA Section 702 sunset. 17 days. No deal in sight.
  • Developing: Hasbro breach investigation, watch for data theft confirmation or ransomware claim
  • Developing: FBI "major incident" fallout, congressional hearings likely given the timing with 702 reauthorization

References

  1. Yahoo News - FBI declares suspected Chinese hack of US surveillance system a 'major cyber incident'
  2. IBTimes - Chinese Cyberattack on FBI Systems Reveals Sensitive Surveillance Processes
  3. Gigazine - EU decided to repeal Chat Control 1.0
  4. CDT Europe - Response to European Parliament Rejection of Chat Control Extension
  5. EU Perspectives - Child protection rules set to expire as EU lawmakers reject Chat Control 1.0
  6. Reason/Volokh - New PCLOB Report on Section 702
  7. IAPP - PCLOB report further divides FISA Section 702 reauthorization talks
  8. TechCrunch - Hasbro says it was hacked, may take several weeks to recover
  9. Biometric Update - Meta's facial recognition smart glasses plan sees increasing opposition
  10. Gizmodo - Calls to Regulate Smart Glasses Are Officially Deafening
  11. GlobalSecurity - ODNI Releases 13th Annual IC Transparency Report
  12. HIPAA Journal - Navia Benefit Solutions Discloses Data Breach Affecting 2.7 Million
  13. National Law Review - BR Privacy, Security & AI Download: April 2026
  14. Senator Lee - Government Surveillance Reform Act

Last updated: April 3, 2026