Today in Surveillance:
- The Pentagon put Grok on classified military networks and dropped AI ethics. Defense Secretary Pete Hegseth announced on January 13 that Grok and Google Gemini will be deployed across Pentagon systems including IL-5 classified networks. The strategy document states "Diversity, Equity, and Inclusion and social ideology have no place" in military AI. Saudi Arabia and Qatar are xAI investors [1][2][3].
- 676 million U.S. identity records sat exposed on an unsecured Elasticsearch database. Threat intelligence firm SOCRadar found the 91.7 GB database running on port 9200 with no authentication. Full names, full Social Security numbers, dates of birth, addresses, and phone numbers were all searchable. Around 250 million related entries had already appeared on criminal forums before the discovery. The database owner remains unknown [4][5][6].
- The Institute for Justice filed a federal class action over San Jose's 474 license plate cameras. Three San Jose residents sued on April 15, 2026 in the Northern District of California, asking a federal court to order police to delete plate data within 24 hours unless they first obtain a warrant. The case is designed to drive ALPR law to the Supreme Court [7][8][9].
- Chat & Ask AI left 300 million private messages open on a misconfigured Firebase backend. The Turkish developer Codeway's app, with 50 million downloads across the App Store and Google Play, exposed chat histories from 25 million users. The exposed messages included users asking how to kill themselves, how to make methamphetamine, and how to hack applications. Codeway fixed the bug within hours of disclosure but never publicly acknowledged the incident [10][11][12].
- Maine's Senate exempted political parties from its own privacy bill. LD 1822 passed 20-14, but Senator Anne Carney's amendment carving out political organizations passed 18-16. Political parties, PACs, and campaign committees can still collect and combine voter data with commercial broker information while businesses face new restrictions [13][14][15].
The Pentagon Put Grok on Classified Networks and Dropped AI Ethics
Defense Secretary Pete Hegseth made the announcement on January 13, 2026. Grok and Google Gemini will both be deployed across Pentagon networks, including classified systems at IL-5 and above [1][2]. IL-5 is where the serious national security data lives, the kind of material foreign governments would love to access.
The Pentagon's third AI strategy in four years establishes seven "pace-setting projects" to embed AI deeper into military operations. One of them is "Agentic AI": autonomous decision-making from campaign planning to "kill chain execution." Pentagon-speak for the sequence from identifying a target to destroying it. The strategy asks AI to make decisions inside that process.
The strategy also explicitly rejects AI ethics. "Diversity, Equity, and Inclusion and social ideology have no place" in military AI, the document states [1]. That's a philosophical position. It's a claim that previous guardrails were ideological obstacles.
The Pentagon's new strategy does not explicitly retain its prior "meaningful human control" preference for autonomous weapons [1]. That phrase was the international compromise language to keep humans in the loop when AI recommends lethal action. The omission creates room for interpretation conflicts among commanders. The new standard: contracts must include "any lawful use" language within 180 days [1].
Then there's the money. xAI counts Saudi Arabia and Qatar among its investors [1]. Saudi Arabia's Kingdom Holding bought a $400 million stake; Qatar's QIA participated in a major funding round. That's foreign government money backing an AI system now touching classified U.S. military networks. The lines between commercial interests, foreign intelligence, and national security aren't blurry. They're absent.
Senator Elizabeth Warren sent a letter to Pentagon leadership on September 10, 2025 raising concerns that Musk's Department of Government Efficiency role may have given him "an unfair competitive advantage," including access to "valuable nonpublic federal contracting data" to help train Grok [3].
The full vessel is at Pentagon Deploys Grok AI to Classified Military Networks.
676 Million U.S. Identity Records Sat Open on an Unsecured Database
Threat intelligence firm SOCRadar discovered an Elasticsearch server sitting on the open internet, no authentication required. Inside: 676 million indexed records of U.S. identity data [4]. Not just names. Not just emails. The full package: full legal names, complete Social Security numbers, dates of birth, street addresses, and phone numbers. All of it searchable.
The database was 91.7 gigabytes across nearly 677 million records, running on Elasticsearch version 8.15.2 with port 9200 exposed [4]. Anyone who found it could query it like a search engine for identity theft.
Approximately 250 million related data entries had already appeared on criminal forums before SOCRadar found the database [4]. Automated scanners run 24/7 looking for exactly this kind of exposed database. When they find one, they grab everything within minutes. Even if the database gets secured today, the damage is done.
The data owner is unknown. SOCRadar attempted to identify the operator and coordinate remediation, but at the time of the report, no owner had come forward. Without a responsible party, no breach notification letter, no credit monitoring offer, no class action. Just 676 million records searchable until someone secures an instance nobody will claim.
SOCRadar's CISO Ensar Seker explained why this exposure is critical: "The operational risk is driven less by uniqueness and more by the presence of structured, searchable SSN-linked identity profiles." [5] SSNs and dates of birth are "non-rotatable identifiers": you can't change them after they're exposed.
The full vessel is at 676 Million U.S. Identity Records Found Exposed Online.
The Institute for Justice Wants the Supreme Court to Kill Mass ALPR Surveillance
The complaint landed April 15 at the Robert F. Peckham Federal Building in downtown San Jose [7]. Three plaintiffs (Tony Tan, Scott West, and Colin Wolfson), one defendant (the City of San Jose), and one specific ask: declare San Jose's ALPR program unconstitutional under the Fourth Amendment and require police to delete captured plate data within 24 hours unless they first obtain a warrant [7][8].
Tony Tan is a privacy engineer and a legal observer who shows up when reports come in of federal immigration enforcement activity. His concern in the complaint is direct: ICE could pull San Jose's ALPR data to identify the car he drives to observations and retaliate.
IJ attorney Michael Soyfer told San Jose Spotlight: "(Plaintiffs) haven't done anything wrong, and their movements are being compiled in this massive government database where officers can search them without a warrant or probable cause." [7][8]
The numbers IJ is putting in front of a federal judge: 474 cameras made by Flock Safety, 30-day retention of every capture, and approximately 15,000 database searches per day on average in the second half of 2025 [7]. The 30-day retention is already down from a full year. San Jose cut it in February 2026 after a separate state-court lawsuit. IJ says 30 days is still too long.
Flock's PR manager Paris Lewbel responded with the line the company always uses: "Using Flock devices is constitutional" and "more than 30 courts have already definitively answered" that question. A city spokesperson said San Jose has strict policies against misuse and the cameras are essential for solving kidnappings and homicides [7].
This is the second federal ALPR class action IJ has filed. The first, against Norfolk, Virginia's 170-camera system, was filed in 2024 [7]. San Jose is bigger, louder, and in a more plaintiff-friendly circuit. If IJ wins at the Ninth Circuit and the Supreme Court follows, every city running a Flock network has to rebuild its program. Retention shrinks. Search rules tighten. The business model that's put cameras in 5,000+ communities cracks.
The full vessel is at Institute for Justice Takes San Jose ALPR Case Toward the Supreme.
Chat & Ask AI Left 300 Million Private Messages Wide Open
A security researcher who goes by "Harry" discovered that Chat & Ask AI's Google Firebase backend was misconfigured so anyone could access the database [10][11]. The app, built by Turkish developer Codeway, wraps around OpenAI, Anthropic, and Google models. It racked up 50 million downloads across the App Store and Google Play [10]. Inside the database: 300 million private messages from 25 million users.
To confirm the scope, Harry analyzed a sample of 60,000 users and over one million messages. The data was real, the access was complete, and the vulnerability affected Codeway's other apps too [10][12].
The exposed messages included users asking how to painlessly kill themselves, how to write suicide notes, how to manufacture methamphetamine, and how to hack other applications [10]. The database also exposed full chat histories with timestamps, custom names users assigned to their chatbots, AI model selections, and configuration settings for each user's session.
Codeway's marketing claimed "SSL certification, GDPR compliance, and ISO standards" with "enterprise-grade security" [12]. SSL encrypts the connection in transit. It says nothing about what happens to data after it arrives. In this case, the data sat in an open Firebase database that anyone could read.
Harry disclosed the vulnerability to Codeway on January 20, 2026. Codeway fixed the Firebase misconfiguration across all of its apps within hours. But the company never responded to 404 Media's requests for comment. No public acknowledgment. No disclosure to users. No explanation of how long the database was exposed or whether anyone else accessed it before Harry [11].
The full vessel is at Chat & Ask AI Left 300 Million Private Messages Wide Open.
Maine Politicians Exempted Themselves From Their Own Privacy Law
Maine was about to pass one of the strictest data privacy laws in the country. LD 1822, the Maine Online Data Privacy Act, would have limited data brokers from collecting and selling sensitive personal information: religion, sexual orientation, health status, and more.
Then Senator Anne Carney, a Democrat from Cumberland, introduced a floor amendment on March 5, 2026 [14]. It carved out a massive exception: political organizations wouldn't have to follow the rules.
The Senate passed the overall bill 20-14, mostly along party lines [14]. But the political exemption amendment was a different story. It squeaked through 18-16, with two Democrats joining Republicans to oppose it [14]. Senator Joe Baldacci of Penobscot was one of them [13]. His response to Carney's First Amendment argument: "If this is a First Amendment issue, I say let the political parties sue us." [13]
The amendment defines political organizations as any "party, committee, association, fund or other group that operates primarily to influence or attempt to influence the election." That includes the Democratic and Republican parties of Maine, PACs and Super PACs, campaign committees, and issue advocacy groups that engage in elections. These groups can continue collecting and combining your data with commercial data broker information to target you, while businesses face new restrictions for doing the same thing.
The bill now returns to the Maine House for reconsideration. The House originally passed an earlier version without the political exemption. If they reject the Senate amendment, the bill goes to a conference committee. If they accept, it heads to Governor Janet Mills.
The full vessel is at Maine Politicians Exempted Themselves From Their Own Privacy Law.
What to Watch
The San Jose ALPR case. San Jose has 21 days to respond to the Institute for Justice's federal class action. Expect a motion to dismiss. If the case survives (Norfolk's similar motion failed), discovery begins. That's where the interesting numbers come out: how many ICE queries, how many officers searched their ex-partners, how many times the database was used for reasons that have nothing to do with solving violent crime [7][8].
Maine LD 1822 in the House. The House originally passed a version without the political exemption. The Senate's amendments now face a floor vote. If the House rejects them, the bill goes to conference. If the House accepts, Governor Janet Mills decides whether to sign a law that exempts political parties from the privacy rules everyone else follows [13][14].
Who owns the Elasticsearch database. SOCRadar continues to coordinate remediation. Without a named owner, the 676 million records stay in a legal void: no breach notification, no credit monitoring, no class action. The longer the owner stays unnamed, the longer victims have no way to know if they're affected [4][5].
Codeway's other apps. The Firebase misconfiguration was fixed across Codeway's portfolio within hours. The full scope of exposure remains undisclosed. Codeway publishes 60+ apps, including Wonder AI Art Generator, Nerd AI, FaceDance, and TypeAI. The same configuration mistake could have exposed users across the catalog [10][12].
Sources
- Defense One: Grok is in, ethics are out in Pentagon's new AI-acceleration strategy. https://www.defenseone.com/policy/2026/01/grok-ethics-are-out-pentagons-new-ai-acceleration-strategy/410649/
- Federal News Network: Pentagon is embracing Musk's Grok AI chatbot as it draws global outcry. https://federalnewsnetwork.com/artificial-intelligence/2026/01/pentagon-is-embracing-musks-grok-ai-chatbot-as-it-draws-global-outcry/
- Senator Warren: Letter to Pentagon Regarding Integration of Grok. https://www.warren.senate.gov/imo/media/doc/letter_to_pentagon_regarding_integration_of_grok_91025.pdf
- Biometric Update: Open Elasticsearch Server Exposes 676 Million US Identity Records. https://www.biometricupdate.com/202603/open-elasticsearch-server-exposes-676-million-us-identity-records
- Security Info Watch: Publicly Exposed Database Contains 676M U.S. Identity Records Including SSNs. https://www.securityinfowatch.com/cybersecurity/article/55361287/publicly-exposed-database-contains-676m-us-identity-records-including-ssns
- ID Tech: SOCRadar Discovers Open Elasticsearch Server Exposing 676 Million US Identity Records. https://idtechwire.com/socradar-discovers-open-elasticsearch-server-exposing-676-million-us-identity-records/
- Institute for Justice: Three San Jose Residents File Federal Class Action Lawsuit Over City's Mass Surveillance of Drivers. https://ij.org/press-release/three-san-jose-residents-file-federal-class-action-lawsuit-over-citys-mass-surveillance-of-drivers/
- San Jose Spotlight: Another lawsuit targets San Jose's license plate cameras. https://sanjosespotlight.com/another-lawsuit-targets-san-joses-license-plate-cameras/
- NBC News: Drivers sue San Jose over nearly 500 Flock police cameras. https://www.nbcnews.com/tech/tech-news/san-jose-drivers-sue-city-police-flock-cameras-rcna331750
- Fox News: Chat & Ask AI app exposed 300 million messages due to misconfiguration. https://www.foxnews.com/tech/millions-ai-chat-messages-exposed-app-data-leak
- 404 Media: Massive AI Chat App Leaked Millions of Users' Private Conversations. https://www.404media.co/massive-ai-chat-app-leaked-millions-of-users-private-conversations/
- Business and Human Rights Centre: Millions of People's Privacy Rights Compromised in AI Apps Data Breach. https://www.business-humanrights.org/en/latest-news/millions-of-peoples-privacy-rights-reportedly-compromised-in-ai-apps-data-breach/
- Bangor Daily News: Maine Democrats move to exempt political groups from sweeping data privacy bill. https://www.bangordailynews.com/2026/03/05/politics/state-politics/maine-data-privacy-bill-anne-carney-amendment-political-groups/
- IAPP: State of the states - Maine comprehensive privacy, Oregon AI chatbot bills on the move. https://iapp.org/news/a/state-of-the-states-maine-comprehensive-privacy-oregon-ai-chatbot-bills-on-the-move
- Maine Morning Star: New political group exemption in data privacy proposal narrows support. https://mainemorningstar.com/2026/03/05/new-political-group-exemption-in-data-privacy-proposal-narrows-support/