Today in Surveillance:
- The SEC bought airline data that reached beyond US borders. Documents obtained by 404 Media show the regulator purchased access to more than a billion ticketing records, including flights between foreign countries. The records were searchable without the ordinary court process used when agencies request data directly from an airline [1].
- INTERPOL says AI is now tied to more than half of reported cybercrime in Africa. Its 2026 assessment describes synthetic identities made with stolen data and deepfaked biometric faces that passed checks used by banks and mobile-money providers [2].
The SEC Bought a Map of Who Flew Where
The Securities and Exchange Commission is supposed to police securities markets. Its own documents show it also bought access to more than a billion airline ticketing records, Joseph Cox reported for 404 Media on August 4. The dataset covered not only US domestic flights and flights landing in the country, but also flights between foreign countries and flights entirely within foreign countries [1].
The source was the Airlines Reporting Corporation, an airline-owned intermediary. Its ticket records can include a passenger's name, credit card number, departure and arrival cities, flight dates, flight numbers, and the travel agency involved. The product, called the Travel Intelligence Program, offered searchable records, daily name alerts, and automatic recurring searches [1][3][4].
That is the privacy problem in plain English: a record that would normally be requested from an airline through a subpoena or court order could instead be purchased from a commercial intermediary. A November 2025 letter from Senator Ron Wyden, Representative Andy Biggs, Representative Adriano Espaillat, and Senator Cynthia Lummis said the arrangement let agencies search a database containing half of all tickets booked without asking a judge [3].
ARC has since stopped selling the records. That does not answer what agencies retained, what searches were run, or whether another broker can sell a similar product. The SEC has not explained why it needed worldwide flight data. For travelers, the lesson is uncomfortable: booking through a travel agency can place trip details in a separate commercial pipeline that the government may buy without notifying you.
Read the day's full vessel, SEC Bought Airline Data to Track Global Flights Without a Warrant, for the documents and the congressional response.
Deepfaked Faces Are Getting Through Biometric KYC
INTERPOL's African Cyberthreat Assessment Report 2026 says AI was tied to 55% of reported cybercrime across the African countries surveyed. The report says reported financial losses rose from $192 million in 2024 to $484 million in 2025. It also says 92% of African law-enforcement agencies lack staff with technical AI know-how [2][5].
The most important finding for privacy is not the headline percentage. It is the failure of identity systems that are sold as a defense against fraud. In Tanzania and Kenya, criminals combined stolen personal data with deepfaked biometric faces to create synthetic identities that passed verification at banks and mobile-money providers. The identities were then used to open accounts, obtain mobile loans, and register SIM cards [2][5].
Biometric onboarding is often presented as the safer alternative to passwords and documents. This report shows its weakness. A face scan can confirm that a face matches a stored image while missing the more basic question of whether the person, identity, or underlying records are real. Once a synthetic identity enters a bank or telecom system, it is not just a fraud attempt. It becomes an account, a number, and a durable trail connected to someone else's stolen information.
The report also describes voice and video cloning used to impersonate South African Reserve Bank Governor Lesetja Kganyago and steer victims toward fake investment platforms. AI is reducing the cost of making a lie look official. More verification data can create more material for the next impersonation unless the systems also limit collection and improve independent checks.
Our other daily story, INTERPOL: AI Cybercrime in Africa Beats Biometric KYC, follows the report's regional findings and its recommendations for law-enforcement training and digital forensics.
Two Systems, One Permission Problem
The SEC story and the INTERPOL report look unrelated. One concerns airline bookings. The other concerns synthetic identities. Both show what happens when institutions treat data collection as a substitute for judgment.
ARC turned travel records into a product that agencies could query. Biometric providers turn faces and identity documents into a gate that is supposed to decide who gets access. In both cases, the system expands the reach of the institution using it while leaving the person being watched with little visibility into the search, the match, or the error.
There is a practical difference between the two threats. Travelers can ask airlines and booking services how records are shared, and can avoid unnecessary third-party booking channels when that choice is available. People facing biometric onboarding should ask what is retained, who operates the verification service, how long the data is kept, and what appeal exists when the match fails. Neither checklist fixes the underlying market. Both make the hidden handoffs harder to ignore.
What to Watch
What happened to the SEC's data. ARC's program is winding down, but the next disclosure should address historical copies, search logs, retention, and the investigations that used the records [1][3].
The next airline data broker. A program can close without changing the legal rule that made a commercial purchase possible. Watch for a renamed product or another intermediary offering the same records.
Biometric verification failures. The INTERPOL findings make synthetic identity fraud a test of the verification industry, not merely a warning about individual scammers. Watch for banks and mobile-money providers to explain how they detect deepfaked faces and what happens to people whose identities are wrongly flagged [2][5].
AI crime capacity. INTERPOL's recommendation is more training and standardized forensic capability. The question is whether those safeguards grow as quickly as the tools used to automate phishing, impersonation, and identity fraud [2].
Sources
- 404 Media, Joseph Cox - The SEC Bought Airline Data to Monitor Flights Worldwide (August 4, 2026). https://www.404media.co/the-sec-bought-airline-data-to-monitor-flights-worldwide/
- INTERPOL - INTERPOL report finds AI linked to more than half of cybercrime in Africa (August 3, 2026). https://www.interpol.int/en/News-and-Events/News/2026/INTERPOL-report-finds-AI-linked-to-more-than-half-of-cybercrime-in-Africa
- Senator Ron Wyden, Rep. Andy Biggs, Rep. Adriano Espaillat, Sen. Cynthia Lummis - Letter to Airline Executives on ARC Sale of Americans' Travel Records (November 17, 2025). https://papersplease.org/wp/wp-content/uploads/2025/11/letter-to-arc.pdf
- 404 Media, Joseph Cox - Airlines Sell 5 Billion Plane Ticket Records to the Government for Warrantless Searching (September 15, 2025). https://www.404media.co/airlines-sell-5-billion-plane-ticket-records-to-the-government-for-warrantless-searching/
- Infosecurity Magazine, Phil Muncaster - AI Accounts for Over Half of Cybercrime in Africa, Says INTERPOL (August 4, 2026). https://www.infosecurity-magazine.com/news/ai-accounts-over-half-cybercrime/