Today in Surveillance:
- Anthropic apologized for shipping Claude Fable 5 with invisible safety throttling. The company admitted the hidden "distillation guardrail" was "the wrong tradeoff" and said it would make the safeguard visible. The Verge, NBC News, the Wall Street Journal, Gizmodo, and TechCrunch all carried the story June 11. Simon Willison and several Hacker News threads called the move the AI safety community's first real public break with a frontier lab [1][2][3].
- AWS Bedrock will start sharing your enterprise data with Anthropic. Customers running Mythos-class models and any future Anthropic models through Bedrock will be required to route their data through Anthropic's infrastructure. The policy change hit Hacker News's front page on June 10 with 418 points. The same Fable 30-day data retention story now has a new data-residency angle [4].
- FISA Section 702 hit its statutory sunset at midnight Friday. The House rejected a three-week extension on June 11. The statute is gone. The FISA Court's March 2026 certifications keep collection running through March 2027 anyway. The Cato Institute and the Brennan Center both published explainers framing the day as political theater layered over an operational status quo [5][6][7].
- South Korea fined Coupang $409 million for a 2025 data breach. The Personal Information Protection Commission hit the e-commerce giant with 624.7 billion won for exposing roughly 33.7 million user records. The per-record fine is $12. The Equifax US settlement worked out to $2.69 per person. South Korea's privacy enforcement is structurally heavier than the US version [8][9].
- The Maine Attorney General's breach portal is now part of the attack surface. A fake data breach disclosure was filed in VRChat's name through the state AG portal. VRChat publicly denied a breach. Security Magazine, the Register, BleepingComputer, and Cybersecurity Insiders all carried the story. The portal inherits the same vulnerability in every state with a public breach notice system, and there is no federal pre-publication check [10][11][12].
- Canada's Bill C-22 petition hit 416 points on Hacker News. The petition to withdraw the lawful access bill gained traction the same week the Canadian government admitted the bill would allow "secretly ordered microphone activation." Signal, DuckDuckGo, and Apple have all warned about an exit. Our existing C-22 explainer covers the bill in detail [13].
Anthropic Apologized for Hiding Claude Fable's Safety Throttling. The Apology Is Not the Worst Part.
Anthropic published a public apology on June 11 for shipping Claude Fable 5 with a "distillation guardrail" that researchers and rival labs could not see. The hidden safeguard throttled outputs that looked like model distillation work, which is the technique competitors use to train their own systems on outputs from a frontier model. The company's own post, reproduced by The Verge and NBC News: "We went with invisible safeguards for this reason, and that was the wrong tradeoff. You should have visibility into the safeguards we have in place, and why. We're sorry for not getting the balance right" [1][2].
The episode is the first time a frontier lab has walked back a behavior modification that was deployed in secret on a flagship model. Frontier AI safety researchers, including several independent red teams, had already broken publicly with Fable's launch in a TechCrunch report on June 10. The complaint centered on the 30-day data retention requirement for Fable and Mythos-class models, which makes adversarial red teaming uncomfortable because the prompts and outputs sit on Anthropic infrastructure for a full month after the test ends. The invisible guardrail is a different problem: a safety feature with no disclosure, no documentation, and no researcher-facing way to detect when it had triggered. The same Fable prompt could be throttled for one user and pass through cleanly for another, with no signal about why [1][3].
Anthropic said it would make the distillation safeguard "as visible as other safety measures." That is a real concession, but it does not address the larger data minimization fight. A separate post from Anthropic on the same day confirmed that AWS Bedrock customers running Mythos and future Anthropic models will be required to share their inference data with Anthropic. That policy change is the bigger story for enterprise IT, privacy officers, and anyone whose customer data flows through Bedrock [1][4]. Standalone coverage is queued for the beat reporter; the materials are in today's beat brief.
AWS Bedrock Will Start Shipping Your Data to Anthropic
Hacker News's front page on June 10 carried a 418-point thread documenting a quiet change in AWS Bedrock's terms. Enterprise customers running Anthropic's Mythos-class models, and any future Anthropic models Bedrock adds, will be required to share their data with Anthropic. The change was buried in updated Bedrock terms rather than announced in a customer letter. AWS Bedrock's product page still describes the service as a multi-model gateway for foundation models; the new data flow means Anthropic gets direct read access to enterprise customers using its frontier models through the platform [4].
The pattern matters more than the individual product change. The Fable apology above and the Bedrock policy shift land in the same week. Anthropic is asking for two things at once: trust that its hidden safety behavior is appropriate, and a data pipeline that gives it a copy of what runs through one of the largest enterprise AI gateways. For companies in regulated industries, healthcare, financial services, defense, and the EU, that is a vendor lock-in story that overlaps with a data residency story. Once data leaves the AWS boundary and lands in Anthropic's infrastructure, the GDPR controls your team has built around AWS are no longer the only ones that matter [4].
The fix is not in the product yet. Customers should pull their Bedrock terms-of-service diff for the last 60 days, identify which Anthropic models are affected, and ask AWS for the data flow diagram. The Hacker News thread has examples of customers who negotiated a 30-day retention limit before signing their Bedrock contracts; that ship has now sailed for the default terms [4].
FISA 702 Expired at Midnight. The Statute Is Gone. The Surveillance Is on Autopilot.
FISA Section 702 hit its statutory sunset at 11:59 p.m. Eastern on June 12 for the first time since 2018. The House rejected a three-week extension on June 11. The Senate has not had the votes to advance any reauthorization bill since the 47-52 cloture failure on June 5. The statute is, in fact, gone [5][6].
The operational reality is much less dramatic. The Foreign Intelligence Surveillance Court reauthorized the existing Section 702 certifications in March 2026, and those certifications run through March 2027. So the wiretaps the FBI, NSA, and CIA were running yesterday are still running today. The "sunset" is a political lever, not an operational shutdown. As the Cato Institute put it on June 11, the lapse was "assured," and "thankfully" [5][7].
The Brennan Center and EPIC both published explainers on the same day walking through the legal mechanics. The FISA Court certifications are issued under Section 702(i), which is a separate authority from the sunsetting statute. An executive order cannot create new certifications, so any "fallback executive order" Cotton and Grassley are planning with Rubio would shift collection to Executive Order 12333 authorities and National Security Letters, which have looser minimization rules. The "gap" Republican leadership is preparing for is a gap in oversight, not a gap in collection [5][6][7].
Our standalone post-mortem of the lapse is now live. The longer companion piece on the FISA Court certification mechanism is in the beat materials for follow-up coverage [5][6].
Related: FISA 702 Just Lapsed. Your Phone Wires Are Still Tapped. | The March 2027 Loophole: How Collection Continues | FISA 702: The Complete Guide
South Korea Fined Coupang $409 Million. The Per-Record Math Is Worse Than the Headline.
South Korea's Personal Information Protection Commission (PIPC) fined Coupang 624.7 billion won, roughly $409 million, on June 11 for a November 2025 data breach that exposed roughly 33.7 million user records. BleepingComputer, Yahoo Finance, TechCrunch, and the Korea Times all carried the story. The fine is the largest data breach penalty South Korea has ever imposed. Coupang's stock actually rose on the news because analysts had modeled a worse outcome [8][9].
The comparison that matters is the per-record math. $409 million divided by 33.7 million records is $12.13 per person. The 2017 Equifax settlement in the US worked out to $2.69 per person, and Equifax did not even admit wrongdoing. The largest US fine on a single breach in recent memory is still the Equifax figure. South Korea's per-record penalty is more than four times the US version, and PIPC imposed it under existing law without needing new legislation [8][9].
The structural difference is regulatory willingness, not statute. The US has the Federal Trade Commission's Section 5 authority and a patchwork of state breach laws, but no federal agency has been willing to impose a single breach fine anywhere near the Coupang scale. The result is that US data breach settlements are sized for the company's legal department budget, not for the harm to the affected population. South Korea's PIPC just showed what happens when a regulator treats a 33.7 million-record breach as the structural failure it is. The US enforcement gap is now the story, not the Korean fine [8][9].
Maine's Breach Portal Was Used to File a Fake VRChat Disclosure. The Real Story Is the Portal.
A fake data breach disclosure was filed in VRChat's name through the Maine Attorney General's online breach notification portal. VRChat publicly denied any breach. Security Magazine ran a separate piece on June 12 headlined "2.4M Impacted by VRChat Breach" based on the portal filing, which is exactly the attack the perpetrator was counting on. The Register, BleepingComputer, and Cybersecurity Insiders all carried the underlying story [10][11][12].
The story is not really about VRChat. The story is that state AG breach-notification portals are now part of the attack surface. Anyone can file a notice in a company's name through Maine's portal. The notice becomes a public record the moment it is filed. Stock prices move on the headline before the company can issue a denial, and many retail investors never read the denial. The attacker does not need to break into the company. The attacker just needs to type into a state website [10][11][12].
Every state with a public breach notice system inherits the same vulnerability. There is no federal pre-publication check on the state portals. There is no inter-state sharing of "this filer has abused other states' portals before." The fix is technically trivial: a 24-hour pre-publication hold for verification, paired with a direct notification to the named company. Maine's AG office has not committed to that change. Until it does, the attack is free to repeat, and the next target will not be a VRChat that can absorb a fake headline [10][11][12].
Niantic Responds on Pokemon Go and Vantor. The Denial Is Unfalsifiable.
Kotaku reported on June 11 that Niantic Spatial issued a statement on the Pokemon Go scans feeding Vantor's military drone navigation: "Pokemon Go data wasn't shared with Vantor." Vantor told Dutch newspaper Trouw the same thing. The DroneXL scoop on June 9, which was the basis of our full investigation published the same day, is now in the Guardian, PC Gamer, and BGR. The story is not going away [14][15].
The structural problem with the denial: AI models begin with a dataset and absorb more data until the original contributions blur. Niantic Spatial had already admitted, in a separate context, that the player scans trained an "early version" of its navigation model. Vantor declined to say whether the model it plans to deploy was trained on those scans. Once a scan is folded into a model, proving it is or is not in there becomes nearly impossible. The denial is true, possibly, in the narrow sense that fresh scans are not being shared. The denial is not informative about the model itself [14][15].
Related: Full Investigation: 30 Billion Scans to Military Drones
Canada's Bill C-22 Petition Hits 416 Points on Hacker News
A House of Commons petition to withdraw Canada's Bill C-22 hit 416 points on Hacker News on June 11, the highest-scoring Canadian encryption story since the May coverage of the same bill. The bill would create a lawful access regime that, by the Canadian government's own admission, allows "secretly ordered microphone activation." Signal, DuckDuckGo, Apple, and Shopify have all weighed the cost of a Canada exit. Our existing explainer covers the bill in detail and the bill's progress [13].
Related: Canada Bill C-22: Tech Exodus and the Encryption Backdoor
What to Watch
- June 13: First day post-FISA 702 lapse. Watch for FISA Court statements, AG statements, and any executive order text. The Cotton/Grassley Rubio letter is a 72-hour story [5][6].
- June 17: EFF "LGBTQ+ Solidarity Against Surveillance" event. Watch for new tool announcements and policy asks.
- June 19: Juneteenth: surveillance-of-Black-organizations angle is a recurring story. Watch for new disclosures on retained FBI and DHS files.
- June 30: Colorado AI Act consumer rights take effect. Neural data and biological data become legally "sensitive." High-risk AI systems must have appeal processes for AI-made decisions about you.
- June 30: PayPal breach credit monitoring enrollment deadline.
- July 1: Reddit's new Privacy Policy and User Agreement. AI training opt-out gets harder.
- July 1: Connecticut, Arkansas, and Utah privacy law amendments take effect.
- August 1: California data broker registration requirements.
- August 2: EU AI Act GPAI obligations apply. High-risk rules now delayed to December 2027.
References
- The Verge: Anthropic apologizes for invisible Claude Fable guardrails (June 11, 2026)
- Simon Willison: Claude Fable is relentlessly proactive (June 11, 2026)
- Hacker News: Anthropic Fable 5 guardrails thread (June 10, 2026, 418 points)
- AWS Bedrock: Anthropic data sharing for Mythos and future models (Hacker News discussion, 418 points, June 10, 2026)
- Cato Institute: FISA Section 702 Lapse Assured, Thankfully (June 11, 2026)
- Brennan Center: Section 702 Surveillance Will Continue Until March 2027, Even if the Statute Lapses (June 2026)
- EPIC: FISA Section 702 Almost Certain to Expire After House Votes Against Extension (June 11, 2026)
- BleepingComputer: South Korea hits Coupang with record $409 million fine over data breach (June 11, 2026)
- Yahoo Finance: South Korea fines Coupang $409 million for 2025 data breach (June 11, 2026)
- Cybersecurity Insiders: Maine AG Data Breach Portal Abuse (June 2026)
- BleepingComputer: Maine breach portal abused to publish fake data breach disclosures (May 29, 2026)
- House of Commons of Canada: Petition to Withdraw Bill C-22 (June 11, 2026, 416 points on Hacker News)
- DroneXL: Pokemon Go Scans Trained the Navigation Tech Now Headed Into Military Drones (June 9, 2026)
- Government of Canada: Online Harms Act (Bill C-22) overview (June 2026)
- 5Calls: FISA Section 702 / FBI Surveillance (June 12, 2026)