Today's Top Stories:
- ICE admitted it uses zero-click spyware. Acting Director Todd Lyons confirmed ICE deployed Paragon's Graphite tool to intercept encrypted messages on American soil. The same spyware that got Paragon kicked out of Italy for targeting journalists.
- Adobe got breached through an outsourcer. A threat actor called "Mr. Raccoon" claims 13 million support tickets, 15,000 employee records, and every HackerOne bug bounty submission. The bug bounty data is the real danger: it contains step-by-step instructions for exploiting Adobe's software.
- ATF's facial recognition hearing is today. House Judiciary will grill ATF over 549+ Clearview AI searches on gun owners. Zero policy, zero training, zero oversight. Gun Owners of America and the ACLU are on the same side.
- FISA 702: 12 days to sunset. Congress is back from recess. Speaker Johnson still doesn't have the votes for a clean extension. The math hasn't changed.
- EU killed mass chat scanning, then voted to bring it back. Parliament rejected Chat Control 1.0 but extended limited scanning through August 2027. Permanent surveillance proposal still alive.
ICE Admits It Uses Spyware That Can Break Into Encrypted Messages
On April 1, ICE Acting Director Todd Lyons sent a letter to three Democratic members of Congress confirming what privacy advocates feared: Immigration and Customs Enforcement purchased and deployed Paragon Solutions' Graphite spyware inside the United States [1].
Graphite is a "zero-click" tool. It doesn't need anyone to tap a phishing link or download a malicious file. It can silently infiltrate a phone and extract encrypted messages from Signal, WhatsApp, and other apps that are supposed to be secure. The target never knows.
Lyons justified the purchase as a counter-narcotics measure, claiming HSI (Homeland Security Investigations) uses it to "disrupt foreign terrorist organizations' exploitation of encrypted communication platforms." He assured Congress that use would "comply with constitutional requirements."
Here's why that matters:
- Paragon had its contract terminated by Italy in 2025 after the government was caught targeting journalists and immigration activists with Graphite [2]
- ICE's track record with surveillance tools isn't exactly confidence-inspiring. This is the same agency with an $8.5 billion surveillance arsenal, Clearview AI contracts, Palantir integration, and a history of denying it tracks citizens while its databases say otherwise
- "Counter-narcotics" is how every domestic surveillance expansion starts. The tool is on American phones. The scope creep is already baked in
This is the first official acknowledgment that ICE operates commercial-grade spyware domestically. Not overseas. Not against foreign targets. On phones inside the United States.
Related: Paragon Graphite: ICE's Phone-Hacking Tool | ICE Paragon Spyware Overview
Adobe Breached Through Indian Outsourcer: 13 Million Support Tickets, All Bug Bounty Data Leaked
A threat actor calling themselves "Mr. Raccoon" claims to have exfiltrated a massive trove of data from Adobe, not by hacking Adobe directly, but by compromising an Indian business process outsourcing (BPO) firm that handles Adobe's customer support [3].
What was allegedly stolen:
- ~13 million customer support tickets containing personal data
- ~15,000 employee records
- All HackerOne bug bounty submissions
- Internal documents and operational data
The bug bounty data is uniquely dangerous. HackerOne submissions contain detailed, step-by-step instructions for exploiting security vulnerabilities in Adobe's products. If any of those flaws remain unpatched, attackers now have a roadmap.
How it happened: Mr. Raccoon deployed a remote access trojan (RAT) on a BPO contractor's machine through a phishing email, then escalated by phishing the employee's manager. From there, they found Adobe's support ticketing system allowed bulk exports ("they allowed you to export all tickets in one request from an agent"), a stunning access control failure [4].
Adobe hasn't confirmed or denied the breach. The silence is its own statement. Cybersecurity News, CyberPress, and Security Online have all published analyses based on the leaked samples.
This is a supply chain attack. Adobe's own infrastructure may be fine, but its outsourcers were a wide-open back door. Millions of people who submitted support requests trusted Adobe with their data. Adobe trusted a BPO firm. The BPO firm fell for a phishing email.
Related: Adobe's Bug Bounty Secrets Leaked: Full Analysis | Supply Chain Attacks 2026: Your Vendors Are the Weak Link
ATF Facial Recognition Hearing: 549 Searches, Zero Guardrails
The House Judiciary Subcommittee on Crime and Federal Government Surveillance is holding a hearing today on ATF's use of Clearview AI to search for gun owners, and the cross-partisan outrage is real [5].
What the GAO found:
- ATF conducted 549+ Clearview AI facial recognition searches over 2.5 years
- No dedicated policy governing facial recognition use
- No risk assessment ever conducted
- No staff training on limitations or proper use
- ATF also accessed Vigilant Solutions' database
ATF claimed it stopped using Clearview AI in April 2023. But ATF requested facial recognition photos in July 2024 during the Trump assassination investigation. When asked about current use, ATF says it now "leverages" state and local partners for facial recognition: effectively the same tool, one degree removed [6].
Chairman Andy Biggs and Rep. Warren Davidson pointed out the obvious: routing facial recognition through state police doesn't absolve ATF of its Fourth Amendment obligations.
Gun Owners of America and the ACLU are both condemning the practice. When the NRA crowd and the ACLU crowd agree something has gone too far, it usually has.
Related: ATF Clearview AI: 549 Searches, Zero Oversight | GAO Audit Report
FISA 702: 12 Days. Congress Is Back. The Votes Aren't There.
Congress returned from its two-week recess yesterday. FISA Section 702 expires April 20. Speaker Johnson punted the vote before recess because he didn't have the numbers, and the numbers haven't changed [7].
The math problem:
- 98 Congressional Progressive Caucus Democrats formally oppose any reauthorization without "dramatic reforms"
- A dozen GOP holdouts demand privacy protections, especially a warrant requirement for querying Americans' data
- Trump won't sign without the SAVE Act (requiring proof of citizenship to vote) attached, a poison pill for Democrats [8]
- The Government Surveillance Reform Act (Wyden-Lee-Davidson-Lofgren) is the most comprehensive reform proposal in decades. It would require warrants for accessing Americans' data
Johnson plans to bring it to the floor the week of April 13, leaving four business days before sunset. The Senate would then need to act immediately. This is as tight as it gets.
Meanwhile, the PCLOB (Privacy and Civil Liberties Oversight Board) released a report backing Section 702, but it was authored by a single remaining board member after the Trump administration gutted the board. Critics call it a rubber stamp from a captured watchdog.
Related: 19-Day Countdown | SAVE Act Complication | 98 Democrats Oppose
EU Chat Control: The Scanning Died. Then Parliament Voted to Extend It.
The EU's voluntary message scanning framework officially expired on April 3-4. For a brief, glorious moment, tech companies like Google, Meta, Microsoft, and TikTok lost their legal basis to scan your private messages [9].
Then the European Parliament voted 458-103 to extend a limited version through August 2027. But this isn't the same framework that expired:
- Scanning must be proportional and targeted, not mass surveillance
- End-to-end encrypted communications are explicitly excluded
- Judicial authorization requirements were added
EU member states through the Council wanted broader powers: mass scanning, not targeted scanning. They said no to Parliament's compromise. The original framework just... expired.
The permanent CSAR regulation ("Chat Control 2.0") is still alive. The next trilogue negotiation is April 16. The EFF praised Parliament for blocking mass scanning but warned the permanent proposal could still gut encryption [10].
Related: Chat Control Expires April 3 | What's Next After Expiry
ICE's Quiet Pivot: From Raids to Surveillance-Driven Enforcement
After the Minnesota surge (where two U.S. citizens were shot and killed in Minneapolis, tear gas was deployed in neighborhoods, and public backlash exploded) ICE is shifting to a less visible approach [11].
New DHS Secretary Mullin said he'd "love to see ICE become a transport more than the front line." Translation: fewer dramatic raids, more tech-driven targeting through the 287(g) program, which has exploded to over 13,000 local police officers now deputized for immigration enforcement.
Washington Post data shows two-thirds of the nearly 400,000 ICE arrests since January 2025 involved people with no criminal convictions. Thirty-eight percent had neither convictions nor pending charges [12]. The surveillance infrastructure (Flock cameras, ALPRs, Palantir, facial recognition, social media monitoring) is feeding a system that primarily catches non-criminals.
Related: 287(g) Program Explosion | ImmigrationOS Mission Creep
Quick Hits
- Government social media data requests surged 770%. A Proton report found Google, Apple, and Meta shared data from 3.5 million user accounts with U.S. authorities in a decade. Apple requests up 927%. Including FISA requests, the total hits 6.9 million accounts [13]. Our Coverage
- DocketWise immigration breach hit 116,666 people. The cloud-based immigration case management platform lost SSNs, passports, financial data, and medical records of immigration clients. An attacker used valid credentials to copy files. Class action lawsuits launched [14]. Our Coverage
- CareCloud patient records accessed. Healthcare IT firm CareCloud disclosed that hackers accessed one of its electronic health record environments for 8+ hours on March 16. The company serves 45,000+ providers covering millions of patients. Still unclear how many people were affected [15].
- Charles River Insurance breached by Akira ransomware. The group claims 63GB of data including SSNs, driver's licenses, passports, and financial details. Class action investigation underway [16].
- Illinois facial recognition ban gains momentum. House Bill 5521 would ban police from using facial recognition databases. Two new co-sponsors joined, but 227 opponents registered against just 1 proponent. Law enforcement pushback is heavy [17].
What to Watch
This week:
- April 13-17: Congress expected to bring FISA 702 reauthorization to the floor. Four business days before sunset. This is the week.
- April 16: EU CSAR political trilogue #2: the permanent chat control regulation lives or dies here.
Coming up:
- April 20: FISA Section 702 sunset. 12 days.
- April 22: COPPA revised regulations compliance deadline.
- April 30: Conduent breach credit monitoring signup deadline.
- May 4: Meta New Mexico $375M verdict Phase 2 trial.
References
- TechCrunch - ICE Says It Bought Paragon's Spyware
- NPR - ICE Acknowledges It Is Using Powerful Spyware
- Cybersecurity News - Adobe Breach: 13 Million Support Tickets
- Security Online - The BPO Backdoor: Mr. Raccoon and Adobe
- Biometric Update - Congressional Hearing on Federal Surveillance
- House Judiciary Committee - ATF Hearing
- The Hill - House GOP Pushes FISA Vote to April
- American Prospect - SAVE Act and FISA Reform
- EFF - EU Parliament Blocks Mass-Scanning of Chats
- Patrick Breyer - Historic Chat Control Vote
- NPR - After Minnesota Surge, ICE Shifts to Quieter Enforcement
- Washington Post - ICE Still Arrests Many Without Criminal Record
- The Hill - Government Social Media Data Requests Up 770 Percent
- ClassAction.org - DocketWise Data Breach
- TechCrunch - CareCloud Breach: Hackers Accessed Patient Records
- ClassAction.org - Charles River Insurance Breach
- Biometric Update - Illinois Facial Recognition Ban Bill
Last updated: April 8, 2026