Today in Surveillance:
- An Apple AirTag caught an Essex County sergeant with a press camera bag. New Jersey Attorney General Jennifer Davenport confirmed that Sergeant Darryl Brown, 43, of Sparta Township, took a press camera bag belonging to amNewYork photojournalist Angelina Katsanis home after the May 28, 2026 protest at Delaney Hall. The AG's statement, aggregated by Techdirt on June 11, 2026, said the bag contained roughly $10,000 worth of equipment. Brown is suspended without pay. The Essex County Prosecutor's Office is pursuing a felony theft case [1][2][3].
- The AirTag trail is the only case that produced a public disciplinary action. amNewYork, reporting on the night, named three other photojournalists who were targeted: Reuters' Ryan Murphy (broken finger from a baton blow), New York Times contributor Madison Swart (knocked to the ground), and Anadolu Agency's Mostafa Bassim (camera lens destroyed). The U.S. Press Freedom Tracker carries the Bassim incident as a federal record [2][3][4].
- Prime Minister Støre announced a near-ban on AI in Norwegian primary schools. The directive takes effect in August 2026 when students return. Grades 1 to 7 (ages 6 to 13) are barred from AI tools in the classroom. Lower-secondary students (grades 8 to 10) may use AI under teacher supervision. Upper-secondary students are encouraged to use AI when their teachers judge the use appropriate [5][6][7].
- Volkswagen's WeConnect app stopped letting GrapheneOS users log in. The thread opened by user aaron94 in the GrapheneOS Discussion Forum on May 30, 2026 documented the WeConnect login failure. Volkswagen support, on June 5, told one user the OS is "not an official Volkswagen offering." The same pattern now affects the Cupra app and the My SEAT app. heise.de reported on May 31 that VW's broader API change also broke EVCC, the open-source Home Assistant add-on [10][11][12][13].
- Reuters reported the U.S. has held off blacklisting DeepSeek and 100+ other firms. Karen Freifeld broke the story at 12:02 AM UTC on June 17. An interagency committee approved the firms for the Entity List last year. The list has not been updated since October 2025, the longest stretch in over a decade. The same week, JPMorgan cut off Anthropic access for its Hong Kong staff under the Fable 5 directive [15][16].
- North Korean hackers drained $285 million from Drift Protocol in 12 minutes. TRM Labs and Elliptic both attribute the April 1, 2026 heist to DPRK state actors. The attackers social-engineered multisig signers into pre-signing transactions that sat dormant, then used Solana's durable nonce feature to execute them. Chainalysis tracks $300+ million stolen across 18 confirmed DPRK operations in 2026 [19][20][22].
Also today: Norway's data-protection regulator, Datatilsynet, fined Nordic retailer Elkjop NOK 20 million (EUR 1,805,000) for four GDPR infringements affecting 6+ million members [9]. The EU AI Act's first binding obligations on general-purpose AI providers take effect on August 2, 2026, two weeks before Norwegian students return [8]. Simon Willison's analysis describes GLM-5.2 as "probably the most powerful text-only open weights LLM" [17]. The same Play Integrity API gate that hits Volkswagen hits a wave of consumer banking apps and a wave of municipal transport apps [12].
An AirTag Put a Press Camera Bag at an Essex County Sergeant's House
New Jersey Attorney General Jennifer Davenport confirmed on June 11, 2026 that Sergeant Darryl Brown, 43, an Essex County Prosecutor's Office sergeant deployed to the Delaney Hall protest on May 28, took a press camera bag home that night. The bag belonged to Angelina Katsanis, 25, an amNewYork photojournalist who was injured at the protest and tracked the bag from a hospital bed using the Apple AirTag inside it [1][2].
The AG's statement, as aggregated by Techdirt and reproduced from the New York Times, says the bag contained roughly $10,000 worth of equipment. The AirTag put the bag on a highway across northern New Jersey, then to a residence in Sparta Township where Brown lives, then to a bar near that home [1]. Body-worn camera footage from Brown's deployment, per the AG's statement, shows him "interacting with a dark-colored bag consistent with the description of the victim's belongings" [1].
Brown is suspended without pay. The Essex County Prosecutor's Office is prosecuting the felony theft case. Katsanis told amNewYork that the AirTag was eventually recovered on the side of a road, with her name and contact information still attached [2]. The full vessel covers the chain of evidence, the suspension, and the felony case [3].
The Press Was Not Just Robbed. It Was Targeted All Night.
The Brown case is the only one that produced a public disciplinary outcome from the May 28 protest. The other press-freedom violations from that night remain unresolved. Three photojournalists told amNewYork they were deliberately targeted by federal officers as vehicles left the Delaney Hall facility and ICE agents moved in with batons and military-grade pepper spray [2].
Reuters photojournalist Ryan Murphy took a baton blow to the finger next to his flash. He described the moment to amNewYork: "I had just photographed a guy on the ground getting bear-sprayed in the face, turned around to another protester getting shoved or something, and I was just hit by a baton in the finger next to my flash, and yeah, my hand just went numb. My flash flew on the ground. There is a big gash on my middle finger. It was bleeding pretty badly, I think it's broken" [2].
New York Times contributor Madison Swart was pushed to the ground. Anadolu Agency photojournalist Mostafa Bassim had his lens destroyed by a baton, and told the U.S. Press Freedom Tracker that federal officers noticed his camera and began shining high-powered lights directly at him before the protests even began [2][4]. The Trump-era border czar Tom Homan confirmed on Fox News two weeks later that federal investigators used facial recognition to match anti-ICE protesters at Delaney Hall to protests in Portland and Minnesota [5].
Norway Tells Primary Schools: No AI
Prime Minister Jonas Gahr Støre announced on June 19, 2026 that Norway will bar AI tools from primary school classrooms (grades 1 to 7, ages 6 to 13) starting in August 2026 when students return from summer break [6][7]. Lower-secondary students in grades 8 to 10 may use AI only when a teacher is present and the use is part of a defined lesson. Upper-secondary students are encouraged to use AI tools when their teachers judge the use appropriate [6].
Støre framed the policy in pedagogical terms. The direct quote, as carried by TippInsights: "The most important thing in school is that our children learn to read, write and do mathematics" [7]. Gizmodo's reporting traces the policy to Norway's 2024 smartphone ban, which a Norwegian Institute of Public Health study tied to lower bullying rates and higher grade-point averages in enforcing schools [6]. Gizmodo also notes the 2016 plan to issue tablets to every student starting at age five, a policy Norway has reversed after a decade of PISA reading-score declines [6]. Norway's data-protection regulator Datatilsynet has already used children's data as a GDPR aggravating factor in its June 2026 NOK 20 million fine against Nordic retailer Elkjop [9]. The full vessel covers the three-tier structure and the EU AI Act alignment [10].
The EU AI Act's first binding obligations on general-purpose AI providers take effect on August 2, 2026, two weeks before Norwegian students return. The obligations include publishing training-data summaries, complying with copyright opt-out mechanisms, and reporting serious incident statistics to the EU AI Office [11]. Tech Policy Press places Norway's planned under-16 social media restriction alongside similar measures adopted in Australia, France, and Spain [12].
Volkswagen Started Blocking GrapheneOS Users From Their Cars
Volkswagen's WeConnect app is the one that starts your EV, preheats the cabin, and checks the battery. It stopped letting GrapheneOS users log in on or around May 30, 2026. The thread opened by user aaron94 in the GrapheneOS Discussion Forum at 13:52 UTC that day documents the login failure: GrapheneOS ships with sandboxed Google Play, so WeConnect installs and runs, but the WeConnect login flow checks Google's Play Integrity API and refuses to advance when the verdict comes back as non-Google-certified [13].
Volkswagen support, on June 5, told one user: "The application you are using (GrapheneOS) is not an official Volkswagen offering. Therefore, we are unfortunately unable to provide technical support for questions or issues related to this third-party software" [13]. The same pattern now affects the Cupra app (also VW Group) and the My SEAT app. Forum participants on the GrapheneOS thread also named WhatsApp, a popular mobile game, and several banking apps as recent entries in the same wave [13].
The underlying API change is broader than the GrapheneOS angle. heise.de, in a piece by Günter Born dated May 31, documents VW cutting third-party access to vehicle data more broadly, with the open-source Home Assistant add-on EVCC breaking the same week WeConnect did. Born's piece carries the EU Data Act right-to-own-data framing, which has been in force since September 12, 2025 [14]. The Play Integrity API is Google's standardized device-attestation endpoint, the same gate that lets Apple gate iOS apps through App Review now letting Volkswagen gate Android apps through Play Integrity [15]. GrapheneOS publishes an Attestation Compatibility Guide that asks app developers to switch to the standard Android hardware-attestation API directly and whitelist GrapheneOS's release keys. VW has not made the switch [16]. The full vessel covers the support response, the EU Data Act framing, and the broader lockout wave [17].
The U.S. Won't Blacklist DeepSeek. The Reason Is China Policy.
Reuters, in a Karen Freifeld exclusive at 12:02 AM UTC on June 17, 2026, reported that the U.S. Commerce Department has held off adding China's AI startup DeepSeek, the country's top memory chipmaker ChangXin Memory Technologies, and more than 100 other companies flagged as national security risks to the Entity List [18]. An interagency committee approved the 100+ firms for listing last year. The list has not been updated since October 2025, the longest stretch in over a decade [18].
Reuters did not report that DeepSeek is clean. A senior State Department official told Reuters last year that DeepSeek "has supported China's military and intelligence operations" and "tried to use Southeast Asian shell companies to illegally access advanced U.S. chips" [18]. Anthropic said in March that it had identified a campaign by DeepSeek and two other Chinese AI labs to illicitly extract capabilities from Claude. OpenAI told U.S. lawmakers that DeepSeek was also targeting OpenAI's models [18]. The case for listing is on the record. The decision not to list is geopolitical [18].
The same week, JPMorgan cut off Anthropic access for its Hong Kong staff, the first major U.S. financial institution to publicly restrict Anthropic in response to the Fable 5 directive, per the Financial Times [19]. Simon Willison's analysis on June 17 describes GLM-5.2 as "probably the most powerful text-only open weights LLM," an open-weights counterweight to the Fable 5 directive that U.S. export controls cannot reach once the model is downloaded [20]. The full vessel covers the two-mechanism U.S. AI policy posture and the Microsoft 365 Copilot DeepSeek test case [21].
North Korean Hackers Took $285 Million From Drift Protocol in 12 Minutes
On April 1, 2026 at 12:47 UTC, Drift Protocol's vaults on Solana started emptying. Thirty-one withdrawal transactions fired in sequence. Within 12 minutes, $285 million in USDC and JLP tokens were gone. The largest single transfer was 41.7 million JLP tokens worth roughly $155 million [22][23].
TRM Labs and Elliptic both attribute the hack to North Korean state actors. The report from TRM Labs traces pre-attack staging in mid-March, with attackers withdrawing 10 ETH from Tornado Cash at around 9:00 AM Pyongyang time, deploying a fictitious token called CarbonVote (CVT), minting 750 million units, and seeding a few thousand dollars in liquidity to make the collateral look real to Drift's oracles [22]. The attackers then social-engineered at least two of the five multisig Security Council signers into pre-signing transactions that contained hidden authorizations, then used Solana's durable nonce feature to execute those pre-signed transactions weeks later [24]. No smart contract exploit. No code was broken. The humans were the vulnerability.
Chainalysis tracks $300+ million stolen across 18 confirmed DPRK operations in 2026, on top of $2.02 billion stolen in 2025 across DPRK-attributed service compromises that accounted for 76 percent of all crypto service compromises that year [25]. The state that surveils its own people from birth to death is also the most prolific crypto-thief on the planet. The full vessel covers the social engineering chain and the Songbun surveillance system the stolen money funds [26].
What to Watch
The other Delaney Hall press-bag cases. The Essex County sergeant case is in court. The other photojournalists targeted the same night, three already named publicly and others unaccounted for, have not produced a public disciplinary action. Watch for the next AG statement, the next body-worn-camera release, and the first Press Freedom Tracker entry that names federal officers [2][3][4].
Norway's August AI-school rollout. Norwegian schools have until early August to confirm compliance with the primary-school ban. The Education Ministry is expected to publish upper-secondary guidance before the implementation date. The first school district to publicly retire an AI tutoring tool from a primary classroom is the first data point [6][7].
The Volkswagen Play Integrity block, and what comes next. Volkswagen is one entry in a wave that now includes WhatsApp, banking apps, and municipal transit apps. Watch for the first European Data Protection Board complaint under the EU Data Act right-to-own-data framing, naming a connected-product vendor that uses Play Integrity to gate its consumer app [13][14].
The Entity List stalemate, and Microsoft 365 Copilot. Reuters reports Microsoft is evaluating whether to integrate DeepSeek into Microsoft 365 Copilot. If Microsoft does, DeepSeek frontier models land in every Microsoft 365 customer workflow, including U.S. federal agencies. The corporate test case for the Fable 5 export-control rationale is the next quarter [18][19].
The Drift Protocol aftermath. TRM Labs and Elliptic have the laundering trails. Watch for the next confirmed DPRK service-compromise attribution and the next quarterly Chainalysis total. North Korea uses the proceeds to fund the surveillance state that monitors every citizen from birth to death [22][23][25].
Sources
- Techdirt: ICE Officers Break Cameras. Cops Steal Them. Welcome To New Jersey. (June 11, 2026)
- amNewYork, Dean Moses: Broken fingers and busted cameras: Photojournalists say ICE targeted them during wild clash outside Delaney Hall (May 29, 2026)
- State of Surveillance: Essex County Sergeant Suspended for Taking a Press Camera Bag Home
- U.S. Press Freedom Tracker: Photojournalist struck with baton, lens destroyed, at New Jersey protest (June 2026)
- State of Surveillance: Homan: Feds Used Facial Recognition to Track Protesters Across States (June 10, 2026)
- Gizmodo: Norway Says AI Ain't for Education (June 19, 2026)
- TippInsights: Why is Norway restricting AI use in schools? (June 19, 2026)
- Kennedys Law: The EU AI Act implementation timeline: understanding the next deadline for compliance (2026)
- Datatilsynet: Administrative Fine Imposed on Elkjop (June 5, 2026)
- State of Surveillance: Norway Imposes Near Ban on AI in Elementary Schools
- Kennedys Law: The EU AI Act implementation timeline (2026)
- Tech Policy Press: Tracking Efforts To Restrict Or Ban Teens from Social Media Across the Globe (2026)
- GrapheneOS Discussion Forum: Volkswagen App (thread id 35949, opened May 30, 2026 at 13:52 UTC)
- heise online, Günter Born: VW cuts owners' access to their own vehicle data with API change (May 31, 2026)
- Android Developers: Play Integrity API overview
- GrapheneOS: Attestation compatibility guide
- State of Surveillance: Volkswagen Started Blocking GrapheneOS Users From Their Cars
- Reuters, Karen Freifeld: Exclusive: US holds off blacklisting China's DeepSeek, more than 100 firms deemed security risks, sources say (June 17, 2026, 12:02 AM UTC)
- Financial Times: JPMorgan Chase cuts off Anthropic access for its Hong Kong staff (June 18, 2026)
- Simon Willison: GLM-5.2 is probably the most powerful text-only open weights LLM (June 17, 2026)
- State of Surveillance: U.S. Holds Off Blacklisting DeepSeek, Adds 100+ Other Chinese Firms
- TRM Labs: North Korean Hackers Attack Drift Protocol in $285 Million Heist (April 2, 2026)
- Elliptic: Drift Protocol Exploited for $286 Million in Suspected DPRK-Linked Attack (April 2, 2026)
- CoinDesk: How a Solana Feature Designed for Convenience Let an Attacker Drain $270 Million From Drift (April 2, 2026)
- Chainalysis: 2025 Crypto Theft Reaches $3.4 Billion (January 2026)
- State of Surveillance: Drift Protocol Hack: $285M Stolen in 12 Minutes