Today in Surveillance:

  • A federal court killed FinCEN's real estate surveillance rule 18 days after it took effect. Judge in the Eastern District of Texas ruled in Flowers Title Companies, LLC v. Bessent on March 19, 2026 that FinCEN cannot treat every cash purchase through an LLC or trust as inherently suspicious under the Bank Secrecy Act. The nationwide vacatur ended a rule that had forced title companies to collect full legal name, date of birth, residential address, Social Security number, and citizenship for every non-financed residential buyer using an entity [1][2][3].
  • Signal president Meredith Whittaker said the company will leave the UK and Sweden before it breaks encryption. In remarks at RightsCon 25 and follow-on coverage, Whittaker said Signal would "rather leave the Swedish market completely" than store user communications, and would "leave the U.K. or any jurisdiction" if forced to backdoor its encryption. The UK Ofcom report on Section 121 of the Online Safety Act is due in April 2026, and Sweden's data retention bill could take effect as early as March 1, 2026 [4][5][6].
  • Apple already pulled Advanced Data Protection from the UK in February 2025 after a government demand for backdoor access. The original demand was broader than a backdoor, asking Apple to provide access to the unencrypted data of any Apple user worldwide. Apple refused that part and instead disabled ADP for UK users [7][8].
  • Monroe County, New York passed a 21-8 vote on April 15, 2026 forcing its sheriff to disclose surveillance tech purchases over $100,000. The trigger was a 10-year, $15 million surveillance contract that legislators learned about after the fact. The county has received $24 million in state law enforcement technology grants, operates 157 blue-light cameras, runs a growing drone program, and has used KingFish cellular intercept devices [9][10][11].
  • MongoDB's MongoBleed memory-leak vulnerability (CVE-2025-14847) left 87,000 publicly exposed servers leaking credentials pre-authentication. A public proof-of-concept exploit dropped December 26, 2025. CISA added the flaw to the Known Exploited Vulnerabilities catalog on December 29, 2025. Wiz found 42% of cloud environments have at least one vulnerable MongoDB instance [12][13][14].
  • eScan antivirus update servers pushed malware to users in South Asia on January 20, 2026. Attackers replaced the legitimate reload.exe with a fake-signed malicious version, then disabled Windows security features, killed future updates, and established persistent remote access through scheduled tasks disguised as "CorelDefrag." MicroWorld Technologies shut down the global update service for 8+ hours [15][16][17].

Also today: The Swedish Armed Forces (Försvarsmakten) told Sweden's government in an official consultation response that the proposed encryption backdoor "cannot be fulfilled without introducing vulnerabilities and backdoors that third parties could exploit" [18]. The Global Encryption Coalition, a network of more than 400 organizations, sent a joint letter to Sweden's Riksdag in April 2025 warning the same thing [19]. MongoDB released patched versions 8.2.3, 8.0.17, 7.0.28, 6.0.27, 5.0.32, and 4.4.30 on December 19, 2025 [20]. The UK National Security Technology Centre suggested in January 2026 that creating apps like Signal or WhatsApp could constitute "hostile activity" [21].

A Federal Court Killed FinCEN's Real Estate Surveillance Rule in 18 Days

The U.S. District Court for the Eastern District of Texas vacated FinCEN's Anti-Money Laundering Regulations for Residential Real Estate Transfers on March 19, 2026. The rule had taken effect on March 1. Eighteen days [1][2][3].

The rule forced title companies, settlement agents, and closing attorneys to collect and report to the federal government the full legal name, date of birth, residential address, Social Security number, and citizenship of every beneficial owner of any entity used to buy a residential property with cash, with beneficial owners defined as anyone owning 25% or exercising substantial control [22]. Get any data point wrong, and the reporting person faced penalties. Miss a filing, and the reporting person faced penalties. The mechanism was mandatory reporting of every cash transaction through an entity, treated as a category rather than a case-by-case determination.

The court in Flowers Title Companies, LLC v. Bessent ruled that the Bank Secrecy Act allows FinCEN to require reports of "suspicious" transactions, and that the agency's framing of every cash purchase through an entity as inherently suspicious exceeded that authority. The court found the rule unlawful because "cash real estate transfers to entities and trusts are not categorically 'suspicious' under the Bank Secrecy Act" [3]. The Pacific Legal Foundation, which represented the plaintiffs, framed the win in plain terms: "FinCEN claimed sweeping power to require reporting anytime someone pays cash for a house. But Congress limited FinCEN to regulating only objectively 'suspicious' transactions" [2]. The full vessel walks through the briefing timeline, from August 2024 finalization to December 2025 original effective date to March 1 effective date to March 19 vacatur [1].

The ruling applies nationwide. Every title company in America is off the hook under this specific rule. Treasury will almost certainly appeal. The Suspicious Activity Report regime still applies to actually suspicious transactions. The Corporate Transparency Act still requires new LLCs to file beneficial ownership information with FinCEN separately. But the precedent is on the books: the government cannot treat an entire category of legal transactions as suspicious because criminals sometimes use them.

Signal Will Leave the UK and Sweden Before It Breaks Encryption

Two governments. Same demand. Give us access to encrypted messages or face the consequences. Signal's president has drawn the line on both fronts [4][5][6].

In the UK, Ofcom has been tasked with investigating how to break encryption under Section 121 of the Online Safety Act. Lord Hanson of Flint confirmed the timeline in the House of Lords: "We have set a date of April 2026, and we expect to act extremely speedily once we have had the report back" [4]. The proposal under consideration is a client-side scanning mechanism that security researchers from Cambridge, Johns Hopkins, MIT, and Stanford examined in a 2021 study and concluded "by its nature creates serious security and privacy risks for all society" [23]. Security expert Alec Muffett described Ofcom's proposals as displaying "a horrifying lack of safety by design" [24].

In Sweden, the government is pushing legislation that would require messaging apps to store user communications and hand them over to law enforcement. The bill could take effect as early as March 1, 2026 [5]. The Swedish Armed Forces told the government as much in an official consultation response: "access requirements in end-to-end encrypted communications cannot be fulfilled without introducing vulnerabilities and backdoors that third parties could exploit" [18]. Justice Minister Gunnar Strömmer argues the measures are "necessary for authorities to carry out investigations effectively," but his own military disagrees.

Signal's Meredith Whittaker, speaking at RightsCon 25 in January 2026 and in follow-on coverage, was direct. On the UK: "We would leave the U.K. or any jurisdiction if it came down to the choice between backdooring our encryption and betraying the people who count on us for privacy, or leaving" [6]. On Sweden: "In practice, the law would mean that we are being asked to break the encryption that is the basis of our entire business. Asking us to store data would undermine our entire architecture and we would never do that. We would rather leave the Swedish market completely" [6].

Apple made the opposite call. In February 2025, Apple disabled its Advanced Data Protection feature for UK users after the government demanded backdoor access under the 2016 Investigatory Powers Act [7]. The original demand was even broader: a secret order asking Apple to provide access to the unencrypted data of any Apple user worldwide. Apple refused that. Instead of fighting the demand, Apple withdrew ADP from the UK entirely, so current UK users "will eventually need to disable this security feature," per spokesperson Fred Sainz [8]. UK iPhone users still have end-to-end encryption on iCloud Keychain and Health data. Backups, photos, notes, voice memos, and nine other categories are now protected only by "Standard Data Protection," which Apple can access, which means a UK warrant can reach. Technically the Apple statement that it "never built a backdoor or master key" is still true. Apple just turned off the lock.

The UK National Security Technology Centre suggested in January 2026 that creating apps like Signal or WhatsApp could constitute "hostile activity" [21]. That is the framing battle. Governments say encryption helps terrorists and child abusers, and anyone who builds unbreakable encryption is enabling them. The same arguments were used in the 1990s Clipper chip fight, and they have not stopped since. The full vessel covers the UK and Sweden timelines and the technical reality of client-side scanning [25].

Monroe County Forced Its Sheriff to Disclose Surveillance Tech Purchases

On April 15, 2026, the Monroe County Legislature passed a surveillance disclosure ordinance by a 21-8 vote. The rule requires the county sheriff to file quarterly reports with the legislature on any surveillance technology purchase over $100,000, including a description of the technology, its intended use, the vendor, and the funding source [9][10].

The ordinance came after County Legislator Rachel Barnhart discovered the county had signed a 10-year, $15 million contract for surveillance software and equipment for the sheriff's office. No legislative vote. No public hearing. No disclosure of what the technology does, who it tracks, or how long it stores data [9]. "It's hard for me to believe that anyone would think we as a legislative body don't have the right to automatically know about a 10-year, $15 million contract, particularly when it involves surveillance technology," Barnhart said [10].

The ordinance defines surveillance technology broadly: "equipment, software, or systems capable of, or used or designed for, collecting, retaining, processing, or sharing audio, video, location, thermal, biometric, or similar information" [9]. That covers ALPR cameras, drones, facial recognition, cell-site simulators, predictive policing, and body cameras with AI features. The eight legislators who voted against the disclosure argued the information is already available through existing county purchasing processes [10]. That argument would carry more weight if the $15 million contract had not blindsided the rest of the legislature.

Monroe County is already deep into surveillance technology. The county received $24 million in state law enforcement technology grants, the largest amount any single county in New York received. The money split between the Rochester Police Department ($10 million) and the Monroe County Sheriff's Office ($11.7 million) [11]. The county operates 157 blue-light surveillance cameras with 24/7 monitoring, upgraded with an $8 million grant to 360-degree coverage, with footage stored for 180 days [11]. UAV missions jumped from 13 in 2019 to 73 in 2024, and a "Drones as First Responders" pilot launched in 2025 that sends drones to 911 calls [11]. KingFish cellular intercept devices, stingrays that mimic cell towers to vacuum up phone data, were reportedly discontinued as of February 2025, though "reportedly" does a lot of heavy lifting [11]. The Rochester Police Accountability Board found that blue-light camera concentration is "almost three times greater in census tracts with predominantly Black or Hispanic populations than in predominantly white census tracts" [11].

What the ordinance does not do matters as much as what it does. There is no pre-approval requirement, so the sheriff buys first and reports later. The $100,000 threshold means a Flock Safety ALPR camera at around $2,500 per camera per year could be deployed dozens of times over without ever triggering a report. There is no public hearing mandate, no use restrictions, and no data-retention limits. Compare that to San Francisco's CCOPS law, which requires public process, impact assessments, annual audits, and revocation power [26]. Monroe County's ordinance is a first step. Twenty-six jurisdictions across the U.S. have CCOPS laws, covering nearly 18 million people, but almost all target municipal police [26]. County-level sheriff disclosure is the blind spot, and Monroe County just started to close it. The full vessel covers the gap between disclosure and approval [27].

MongoBleed Left 87,000 Servers Leaking Credentials Pre-Authentication

CVE-2025-14847, codenamed MongoBleed, is a buffer over-read in MongoDB's zlib compression handling that returns whatever is sitting in server memory when an attacker sends malformed packets. No password required. No authentication needed. The decompression happens before any credential check, so an attacker can declare a large buffer size, send minimal actual data, and read back fragments of whatever the database was recently processing: usernames, passwords, API keys, cloud access tokens, OAuth tokens, session identifiers, encryption keys, signing secrets [12][13].

Censys scanned the internet on December 27, 2025 and found over 87,000 publicly accessible MongoDB servers running vulnerable versions, with the largest concentrations in the U.S., China, Germany, India, and France [12]. Wiz looked at customer data and found 42% of cloud environments have at least one MongoDB instance vulnerable to CVE-2025-14847 [12]. A public proof-of-concept exploit dropped December 26, 2025. CISA added the flaw to its Known Exploited Vulnerabilities catalog on December 29, 2025, requiring federal agencies to patch by January 19, 2026 [14]. CISA does not add vulnerabilities to the KEV catalog speculatively. They require evidence of active exploitation targeting real systems. MongoBleed made the list three days after the public exploit appeared, which is fast and signals either widespread or high-impact attacks [13].

MongoDB released patches December 19, 2025: versions 8.2.3, 8.0.17, 7.0.28, 6.0.27, 5.0.32, and 4.4.30 [20]. Versions 3.6 through 4.2 reached end-of-life years ago and have no patches. As a temporary workaround, operators can disable zlib compression via the networkMessageCompressors option and use snappy or zstd instead. Existing connections using zlib will break, which is the right trade. The flaw affects MongoDB 3.6 through 8.2.2 with zlib compression enabled, which is the default configuration. If you are running MongoDB and have not patched in the last two weeks, you are vulnerable [12][13].

The seven-day window between patch (December 19) and public exploit (December 26) is not enough time for most organizations to test, schedule, and deploy. Attackers scripted the exploit, scanned for vulnerable servers, and started harvesting credentials within days. Managed Atlas users got automatic patches; self-hosted operators on AWS, Azure, Google Cloud, or their own servers need to patch manually. Rotate every credential that touched MongoDB since November 2025, including database passwords, API keys, cloud access tokens, and application secrets. The full vessel covers the technical breakdown and what users can do [28].

Your Antivirus Just Delivered Malware: The eScan Update Channel Compromise

On January 20, 2026, attackers compromised an eScan regional update server and pushed a fake-signed malicious version of reload.exe to users running automatic updates. The file carried a forged digital signature. When users ran their normal automatic updates, they downloaded malware instead of a security patch [15][16].

Kaspersky telemetry shows infections concentrated in India, Bangladesh, Sri Lanka, and the Philippines, hitting hundreds of machines across both individuals and organizations [16]. MicroWorld Technologies, eScan's maker, detected the intrusion within an hour and isolated affected infrastructure, shut down the global update service for 8+ hours, and released patches to restore functionality [17]. The catch: if the malware ran on a machine, automatic updates no longer work. The malware broke that mechanism. Manual intervention is required to clean up and then manually download the patch from eScan.

The payload ran three base64-encoded PowerShell scripts in sequence, with fallback mechanisms if one failed and multiple command-and-control servers for redundancy. It killed future updates by modifying registry settings and the hosts file. It disabled the Windows Antivirus Scan Interface (AMSI), the component that lets security tools inspect scripts before they run. It specifically hunted for Kaspersky products on the system to detect competing security tools. It established persistence through scheduled tasks disguised as "CorelDefrag" in Windows\Defrag\ directories, and modified CONSCTLX.exe for backup access [15]. Morphisec was first to investigate. Kaspersky confirmed detections the same day. MicroWorld claims only a "small subset" of customers received the malicious update; Morphisec says all their eScan-running customers were targeted. The truth probably sits somewhere between, and the full scope may never be known.

The security software paradox is the structural point. Antivirus requires the highest privileges on a system: full file access, the ability to monitor everything, the ability to terminate processes. That is exactly what an attacker wants. When the antivirus vendor's update server is compromised, the attacker gets a trusted delivery channel, elevated system privileges, and the ability to disable the very security tool meant to stop them. In 2024, attackers exploited a vulnerability in the same company to sideload the GuptiMiner backdoor and crypto miners [29]. Two supply chain attacks in two years is a pattern. If you use eScan, look for "CorelDefrag" scheduled tasks and unexpected files in Windows\Defrag\, check the hosts file for unexpected entries blocking eScan domains, and review registry for modified eScan exception rules. The full vessel covers the cleanup steps [30].

What to Watch

The FinCEN appeal. Treasury will almost certainly appeal the Eastern District of Texas ruling to the Fifth Circuit. Watch whether the appellate court takes the appeal en banc, whether it stays the vacatur during the appeal, and whether FinCEN attempts to reissue a tailored version of the rule. The Bank Secrecy Act framework has not changed, so the appellate fight is over how much authority "suspicious" gives an agency to define a category [1][3].

The UK Ofcom report and Sweden's Riksdag vote. The Ofcom report on Section 121 of the Online Safety Act is due in April 2026. Sweden's data retention bill could take effect as early as March 1, 2026. If Signal pulls out of either market, the political backlash will be the next data point on whether a major tech company can hold the line on encryption by threatening to leave [4][5].

Monroe County's first quarterly report. The ordinance took effect after the April 15 vote. The first quarterly disclosure from the sheriff's office will tell legislators what surveillance tech they are actually buying, and at what scale. Watch whether the $100,000 threshold hides smaller purchases, whether the sheriff's office treats KingFish-style intercept devices as in-scope, and whether other county legislatures start writing similar ordinances [9][26].

MongoBleed exposure in cloud environments. Wiz's 42% figure is from their customer base. The 87,000 publicly exposed server count is from Censys. Watch for the first major data breach attributed to CVE-2025-14847 and the first cloud provider to publish customer-side telemetry on unpatched MongoDB instances [12][13].

Sources

  1. State of Surveillance: Court Kills FinCEN Rule That Would Have Tracked Cash Home Buyers, the vessel on Flowers Title Companies v. Bessent and the 18-day rule window. /news/fincen-real-estate-surveillance-rule-struck-down-court-2026
  2. Pacific Legal Foundation: Court Strikes Down Federal Real Estate Surveillance Rule (March 2026). https://pacificlegal.org/press-release/court-strikes-down-federal-real-estate-surveillance-rule/
  3. Choate Hall: Federal Court Vacates FinCEN Residential Real Estate Reporting Rule (March 2026). https://www.choate.com/insights/federal-court-vacates-fincen-residential-real-estate-reporting-rule/
  4. Computer Weekly: Privacy Will Be Under Unprecedented Attack in 2026. https://www.computerweekly.com/news/366636751/Privacy-will-be-under-unprecedented-attack-in-2026
  5. The Record: Swedish Authorities Seek Backdoor to Encrypted Messaging Apps. https://therecord.media/sweden-seeks-backdoor-access-to-messaging-apps
  6. Infosecurity Magazine: Signal May Exit Sweden If Government Imposes Encryption Backdoor. https://www.infosecurity-magazine.com/news/signal-exit-sweden-government/
  7. TechCrunch: Apple Pulls iCloud End-to-End Encryption for UK Users (February 2025). https://techcrunch.com/2025/02/21/apple-pulls-icloud-end-to-end-encryption-feature-for-uk-users-after-government-demanded-backdoor/
  8. Computer Weekly: Apple Withdraws Encrypted iCloud Storage from UK. https://www.computerweekly.com/news/366619614/Apple-withdraws-encrypted-iCloud-storage-from-UK-after-government-demands-back-door-access
  9. Spectrum News 1: Monroe County to Require Disclosure of Sheriff's Surveillance Technology Purchases (April 15, 2026). https://spectrumlocalnews.com/nys/rochester/news/2026/04/15/monroe-county-to-require-disclosure-of-sheriff-s-surveillance-technology-purchases-
  10. 13WHAM: Monroe County Legislature Orders Sheriff's Office to Disclose Surveillance Technology Purchases (April 2026). https://13wham.com/news/local/monroe-county-legislature-orders-monroe-county-sheriffs-office-to-disclose-surveillance-technology-purchases-mcso
  11. Rochester Beacon: Police Surveillance and Privacy (March 26, 2026). https://rochesterbeacon.com/2026/03/26/police-surveillance-and-privacy/
  12. Wiz: MongoBleed, Critical MongoDB Vulnerability CVE-2025-14847. https://www.wiz.io/blog/mongobleed-cve-2025-14847-exploited-in-the-wild-mongodb
  13. BleepingComputer: Exploited MongoBleed flaw leaks MongoDB secrets, 87K servers exposed. https://www.bleepingcomputer.com/news/security/exploited-mongobleed-flaw-leaks-mongodb-secrets-87k-servers-exposed/
  14. CISA: CISA Adds One Known Exploited Vulnerability to Catalog (December 29, 2025). https://www.cisa.gov/news-events/alerts/2025/12/29/cisa-adds-one-known-exploited-vulnerability-catalog
  15. Securelist: eScan Supply Chain Attack Technical Analysis. https://securelist.com/escan-supply-chain-attack/118688/
  16. Help Net Security: eScan AV Supply Chain Compromise (January 29, 2026). https://www.helpnetsecurity.com/2026/01/29/escan-antivirus-update-supply-chain-compromised/
  17. Check Point Research: Threat Intelligence Report (February 2, 2026). https://research.checkpoint.com/2026/2nd-february-threat-intelligence-report/
  18. Digital Watch: Sweden Considers Law Requiring Encrypted Messaging Backdoors. https://dig.watch/updates/sweden-considers-law-requiring-encrypted-messaging-backdoors-signal-threatens-to-exit
  19. Cyber Insider: Global Coalition Warns Sweden Against Encryption Backdoor Legislation. https://cyberinsider.com/global-coalition-warns-sweden-against-encryption-backdoor-legislation/
  20. BitSight: CVE-2025-14847 MongoDB MongoBleed, Details, Next Steps. https://www.bitsight.com/blog/critical-vulnerability-alert-cve-2025-14847-mongodb-mongobleed
  21. TechRadar: Creating Apps Like Signal Could Be 'Hostile Activity' Claims UK Watchdog. https://www.techradar.com/vpn/vpn-privacy-security/creating-apps-like-signal-or-whatsapp-could-be-hostile-activity-claims-uk-watchdog
  22. Fennemore Law: New FinCEN Rule Requires Reporting of Certain Residential Real Estate Transactions as of March 1, 2026. https://www.fennemorelaw.com/new-fincen-rule-requires-reporting-of-certain-residential-real-estate-transactions-as-of-march-1-2026/
  23. Proton: The Online Safety Act Doesn't Protect Encryption. https://proton.me/blog/online-safety-act
  24. Reclaim The Net: UK Orders Ofcom to Explore Encryption Backdoors. https://reclaimthenet.org/uk-orders-ofcom-to-explore-encryption-backdoors
  25. State of Surveillance: Signal Would Rather Leave the UK and Sweden Than Break Encryption, the vessel on Whittaker's exit threats and the UK/Sweden deadlines. /news/uk-sweden-encryption-backdoor-signal-2026
  26. Electronic Frontier Foundation: Community Control of Police Surveillance (CCOPS). https://www.eff.org/issues/community-control-police-surveillance-ccops
  27. State of Surveillance: Monroe County Just Forced Its Sheriff to Show Receipts, the vessel on the 21-8 vote and the $15 million contract. /news/monroe-county-sheriff-surveillance-disclosure-ordinance-rochester-2026
  28. State of Surveillance: MongoDB MongoBleed Flaw Leaks Passwords, 87K Servers Exposed, the vessel on the pre-authentication credential leak. /news/mongodb-mongobleed-vulnerability
  29. SecurityWeek: eScan Antivirus Delivers Malware. https://www.securityweek.com/escan-antivirus-delivers-malware-in-supply-chain-attack/
  30. State of Surveillance: Your Antivirus Just Delivered Malware, the vessel on the eScan supply chain attack and the South Asia targeting. /news/escan-antivirus-supply-chain-attack-2026