Network server room with rows of blue-lit data cables and blinking lights in a dark facility
Photo via Unsplash

Today's Top Stories:

  • EU Chat Control scanning officially expired today. As of April 4, Meta, Google, and Microsoft must stop mass-scanning private messages in the EU. But the Parliament already voted to extend interim rules to August 2027, with limits.
  • FISA 702: 16 days to sunset. The gutted PCLOB, down to one member, released a staff report backing the warrantless spying program. Critics say a one-person watchdog shouldn't be signing off on mass surveillance.
  • Perplexity AI sued for sharing user data with Meta and Google. Class action alleges the AI search engine sends your private chats to advertisers before it even processes them, including in "incognito" mode.
  • North Korea stole $285M from Drift Protocol in 12 minutes. Biggest DeFi hack of 2026. The money funds Pyongyang's surveillance apparatus and weapons programs.
  • Meta facial recognition deadline: 2 days. April 6 response deadline from Senators Markey, Wyden, and Merkley on smart glasses surveillance plans.

Day One Without Mass Scanning: EU Chat Control Is Officially Dead

Today's the day. The temporary ePrivacy derogation (EU 2021/1232) that let platforms scan private messages in the EU expired at midnight. Chat Control 1.0 is done [1].

Meta, Google, Microsoft, and every other platform operating in the EU no longer have a legal basis for indiscriminate scanning of private communications. Years of privacy activists fighting mass message surveillance, over. At least this round.

On March 26, the European Parliament voted 311-228 to reject extending the scanning framework. The Socialists & Democrats, Greens, The Left, and most of Renew Europe held the line against the European People's Party's push to keep scanning alive [2].

The catch: Parliament voted 458-103 to extend a narrower interim derogation through August 2027. This version demands scanning remain proportional and explicitly bars applying it to end-to-end encrypted communications. CDT Europe praised the Parliament for rejecting an "unlimited extension" [3].

Political trilogues for the permanent CSAR regulation (Chat Control 2.0) are scheduled May 4 and June 29. The Commission still wants mandatory scanning. Signal previously threatened to pull out of the EU entirely rather than comply with encryption backdoors.

Today, though? Platforms must comply. Stop scanning, or explain why you haven't.

Related: Why April 3 Mattered | Signal's EU Exit Threat | CSAR: The Encryption Fight

A One-Person Watchdog Just Signed Off on Warrantless Spying: 16 Days Before It Expires

The Privacy and Civil Liberties Oversight Board released its staff report on FISA Section 702 on April 2. The conclusion: the warrantless surveillance program is valuable, compliance is improving, and the FBI should probably be doing more queries, not fewer [4].

One problem. The PCLOB has one member left.

Trump pushed three Democratic board members to resign last year, leaving sole Republican Beth Williams as the only person on a five-member oversight body. A staff report produced under the direction of a single political appointee isn't oversight. It's a press release [5].

The numbers the report highlights:

  • FBI warrantless US person queries dropped from 57,000 (2023) to 7,400 (2025)
  • Targeting compliance exceeds 99%
  • Almost two-thirds of the President's Daily Brief contained 702 intelligence in 2025

The report actually warns that declining query numbers could be a problem, suggesting agents may be hesitating to use the tool, potentially missing threats. That's a remarkable position for a privacy watchdog to take: not enough warrantless surveillance.

CDT and the Brennan Center have both challenged the report's credibility. As the Brennan Center put it: a board with one member can't meaningfully oversee an intelligence community that surveils millions of communications [6].

Section 702 expires April 20. Sixteen days. The political math is still ugly: 98 House Democrats oppose clean reauthorization, a dozen GOP holdouts want reforms, House Speaker Johnson is pushing a clean extension, and Rep. Luna wants to attach the SAVE Act (voter citizenship proof) to the bill [7].

Related: 702 Countdown: Johnson's Delay Gambit | Government Surveillance Reform Act | 98 Democrats Oppose Clean Extension | The SAFE Act Is Back | Three Months to Fix FISA

Perplexity AI Caught Shipping Your "Private" Chats to Meta and Google

A 135-page class action filed in federal court in San Francisco alleges Perplexity AI's search engine sends your conversations directly to Google and Meta, even before Perplexity processes them [8].

The lawsuit claims tracking tools embedded in Perplexity's code download onto user devices the moment they log in. From there, Meta and Google get "full access" to conversations between users and the AI, including health questions, legal queries, and personal data. The kicker: it happens in "incognito" mode too [9].

The proposed class covers all users who chatted with Perplexity between December 7, 2022, and February 4, 2026. Paid Pro and Max subscribers are excluded. Apparently you have to pay for actual privacy.

Perplexity's chief communications officer Jesse Dwyer said the company hasn't been served and "cannot verify the existence or claims" of the lawsuit. Make of that what you will.

This lands as state privacy enforcers in California, Connecticut, and elsewhere said this week they're ramping up enforcement against AI companies. California's privacy agency is specifically investigating whether AI companies comply with the new CCPA transparency provisions that took effect January 1 [10].

North Korea Stole $285 Million in 12 Minutes, And It's Funding a Surveillance State

On April 1, hackers drained $285 million from Drift Protocol, the largest decentralized perpetual futures exchange on Solana. It's the biggest DeFi hack of 2026 [11].

Both TRM Labs and Elliptic attribute the attack to North Korean state-sponsored hackers. The methods match prior DPRK-linked crypto theft: weeks of preparation, a fabricated fake token (CarbonVote), social engineering of multisig signers, and cross-chain laundering that mirrors the Lazarus Group's playbook [12].

Why this matters for surveillance: North Korea's crypto theft program directly funds the regime's surveillance apparatus and weapons development. The DPRK has stolen billions in cryptocurrency since 2017, and the money goes toward maintaining one of the most complete surveillance states on earth, plus missile and nuclear programs. When Pyongyang steals $285 million in one operation, it's not abstract financial crime. It's state-sponsored infrastructure funding.

The attack timeline is surgical: on-chain staging started March 11 with a 10 ETH withdrawal from Tornado Cash at approximately 9:00 AM Pyongyang time. The attackers manufactured a worthless token, got Drift's oracles to treat it as legitimate collateral, then drained the entire protocol in minutes [13].

DRIFT token dropped 40%. The protocol's total value locked fell from $550 million to under $300 million in an hour.

Seventh Circuit Guts Illinois Biometric Privacy Damages, Retroactively

The Seventh Circuit ruled on April 1 that the 2024 amendment to Illinois' Biometric Information Privacy Act applies retroactively to every pending lawsuit, reversing three federal court decisions that said otherwise [14].

Translation: BIPA plaintiffs can no longer collect per-scan damages. The amendment caps recovery at $5,000 per person for intentional violations and $1,000 for negligent ones, regardless of how many times your biometrics were scanned without consent.

Before this ruling, a company that scanned an employee's fingerprint every day for three years faced damages calculated per violation, potentially millions per plaintiff. Now it's a flat cap per person. The court called the amendment "remedial" because it changes damages, not liability, so standard Illinois retroactivity rules apply.

BIPA was the strongest biometric privacy law in the country. It produced a $650 million settlement from Facebook (now Meta) in 2021 for facial recognition without consent. This ruling dramatically reduces the financial pressure on companies to respect biometric consent requirements going forward.

Related: Illinois Biometric Surveillance Act | 23 States With Biometric Privacy Laws

Quick Hits

  • Meta facial recognition deadline: 2 days. Senators Markey, Wyden, and Merkley gave Meta until April 6 to answer questions about consent, data retention, AI training, and law enforcement sharing related to smart glasses facial recognition. Over 60 civil society groups are demanding Congress act. Still no response from Meta [15]. Our Coverage
  • North Yorkshire Police announces LFR rollout. Another UK force signing up for live facial recognition. North Yorkshire Police announced April 2-3 they're preparing to deploy LFR across York and the wider county, joining the Met, Norfolk, Merseyside, and others in the UK's accelerating facial recognition expansion [16]. UK Surveillance State Coverage
  • State privacy enforcement escalating. Privacy regulators from California, Connecticut, and other states said this week their behind-the-scenes work will "soon yield public actions", targeting AI companies, consumer opt-outs, and ensuring fines are more than "a cost of doing business" [17].
  • Hasbro breach: still no ransomware claim, no scope confirmation. One week after detecting the intrusion. Systems still offline. Investigation ongoing. TechCrunch
  • Nissan hit by Everest ransomware group. Nature and quantity of data compromised still under investigation [18].

What to Watch

  • April 6 (Sunday): Meta's deadline to respond to senators on facial recognition smart glasses. Silence speaks volumes.
  • April 8: Congressional hearing on federal surveillance practices: ATF Clearview AI testimony expected.
  • April 20: FISA Section 702 sunset. 16 days. SAVE Act attachment could blow the whole thing up.
  • May 4: EU CSAR trilogue session: Chat Control 2.0 negotiations resume.
  • Developing: Platform responses to EU Chat Control expiry: have Meta, Google, and Microsoft actually stopped scanning?
  • Developing: Perplexity AI lawsuit could trigger broader investigation into AI data-sharing practices.

References

  1. ByteIota - EU Parliament Blocks Mass Chat Scanning: April 4 Deadline
  2. EU Perspectives - Brussels rejects extension of Chat Control scanning rules
  3. CDT Europe - Response to European Parliament Rejection of Chat Control 1.0 Extension
  4. Reason/Volokh - New Report on Section 702 from PCLOB
  5. Nextgov - Single-member surveillance watchdog backs 702 powers, raising independence questions
  6. Brennan Center - PCLOB Report on FISA Section 702
  7. American Prospect - Warrantless Spying Reform Just Got More Interesting
  8. Bloomberg - Perplexity AI Accused of Sharing Data With Meta, Google
  9. The Almanac - Class action suit alleges users' chats with Perplexity go straight to Meta, Google
  10. IAPP - Higher fines, age assurance on California agenda; enforcement to ramp up in other states
  11. Fortune - Crypto hack sees thieves make off with $280 million from Solana DeFi platform Drift
  12. TRM Labs - North Korean Hackers Attack Drift Protocol in $285 Million Heist
  13. The Hacker News - Drift Loses $285 Million in Durable Nonce Social Engineering Attack Linked to DPRK
  14. Duane Morris - Seventh Circuit Holds BIPA Amendment Applies Retroactively
  15. Senator Markey - Demand Transparency from Meta on Facial Recognition Smart Glasses
  16. North Yorkshire Police - Exploring the Roll Out of Live Facial Recognition
  17. National Law Review - Privacy, Security & AI Download: April 2026
  18. SharkStriker - April 2026 Data Breaches: Major Incidents & Updates

Last updated: April 4, 2026