Today in Surveillance:
- The Department of Commerce has ordered the Census Bureau and the Bureau of Economic Analysis to stop using "noise infusion" in any statistical product. Noise infusion is the math differential privacy uses to keep individual records safe when the Bureau publishes tables. The 2020 Census adopted it after researchers proved 2010-era swapping leaked individual records. Damien Desfontaines, ex-Google differential-privacy researcher, published the analysis on June 11. The Hacker News thread crossed 800 points and 500 comments by Saturday. Our full explainer on the Commerce order and what it does to your data is already up [1][2].
- A UK police officer is under criminal investigation for using AI to fabricate evidence in multiple cases. Derbyshire Constabulary launched the probe after a Sky News report. The officer is alleged to have perverted the course of justice and has been removed from frontline duties. The story lands the same week the UK Home Office stood up a new national "PoliceAI" centre. Sky News carried the original report (304 HN points); BBC confirmed the byline. The collision is the political economy of the week: the state is pushing AI into policing while its own officers get caught fabricating evidence with the same technology [3][4][5].
- Amazon CEO Andy Jassy's conversations with US officials were the trigger for the Anthropic Fable 5 crackdown, WSJ reports. The Wall Street Journal published late June 13 (640+ HN points, 469 comments) that Jassy's talks with the White House were the originating pressure point for the export-control directive that suspended Fable 5 and Mythos 5 access for every customer. Axios, The Verge, and Reuters all confirmed the Amazon angle June 13 to 14. Anthropic's response: "we believe this is a misunderstanding." This is the political economy angle on yesterday's top story: a competitor (Amazon, Anthropic's biggest cloud partner) lobbying the White House against Anthropic specifically [6][7][8][9].
- FISA 702 has now been lapsed for 48 hours. The House rejected the short-term extension June 11. The FISA Court's March 2026 certifications keep collection infrastructure running through March 2027, so the wiretaps are not blinking. Sens. Cotton and Grassley are pushing an executive order fallback. Sen. Capito is reportedly using World Cup funding to squeeze Democrats. EFF's "Victory! 702 has Expired" post continues to circulate [10][11][12].
- Meta is taking fresh legal action against NSO Group, and WhatsApp just caught fresh Pegasus attacks against journalists and human-rights defenders in 2026. The two announcements together confirm NSO is still actively deploying Pegasus against WhatsApp targets despite prior court injunctions. Memeburn and BornCity both carry the WhatsApp disclosure. The 2019 WhatsApp v. NSO litigation is now in a third round [13][14].
- EU privacy regulators are escalating warnings over smart glasses, framing it as the next big privacy fight. The European Data Protection Board has commissioned a report due this summer. Sweden's DPA is publicly raising concerns. The story ties to the Meta Ray-Ban Kenya data-labeling scandal and our recent EFF victory on the FR code [15][16].
- Quick hits. Congress "rushed through" H.R. 6028, restructuring the Copyright Office; the downstream effect is on every pending AI-training-data scraping lawsuit. Maui County approved $1.7M in AI surveillance for police, branded "Eyes in the Sky." openDemocracy reports that NHS patients cannot opt out of Palantir's Federated Data Platform, but their hospitals can. Canada privacy watchdog: Grok generates explicit deepfakes without valid consent. ICE officers broke Ring-style cameras in New Jersey, and local police then took the broken cameras. A Shai-Hulud variant compromised Microsoft GitHub repos and 1,500+ Arch Linux AUR packages. Reclaim The Net: France's own secure-messaging app TCHAP got hacked. SJV Water and NY Post: Iranian hackers claim to have breached three California water utilities (CISA and FBI have not attributed) [17][18][19][20][21][22][23][24].
Commerce Banned the Math That Kept Census Data Anonymous. The Bureau Has No Replacement.
The lead story of the day is a Department of Commerce order to the Census Bureau and the Bureau of Economic Analysis: stop using "noise infusion" in any statistical product you publish [1]. The order was issued the week of June 8 and surfaced publicly on June 11, when Damien Desfontaines (ex-Google differential-privacy researcher, now independent) published a detailed analysis on his personal blog. By Saturday morning the Hacker News thread had crossed 800 points and 500 comments [2].
What is noise infusion? It is the technique differential privacy uses to keep individual records safe when a statistical agency publishes tables. You add a small amount of calibrated random noise to each published number. The published numbers are still accurate at the population level, but no individual record can be reconstructed from them, even by an attacker with the agency's own published data and unlimited auxiliary data. The 2020 Census adopted differential privacy specifically because the 2010-era "swapping" method had been mathematically broken: a 2019 Census Bureau scientific advisory committee report concluded that an attacker with the 2010 Census tables and commercial data could re-identify a meaningful fraction of individual respondents [1].
Read the order carefully. It says it "shall not be interpreted to conflict with any constitutional, statutory, regulatory, or other legal provision." That phrasing is not a fig leaf. The Census Bureau is still legally required by Title 13 to keep individual records confidential. The order bans the only safe tool the Bureau has for doing that, while leaving the legal obligation intact. Desfontaines is blunt about the result: "Future statistical releases will either be useless compared to past ones, or they will be incredibly unsafe" [1].
Two things matter for the surveillance beat. First, the precedent. This is the first time the US government has used a Commerce Department order to roll back a federal statistical agency's differential privacy implementation. The 2020 Census was a six-year, multi-billion-dollar rebuild of disclosure avoidance; the current order undoes it from the top. Second, the pattern. The same Commerce Department that issued the 5:21pm ET Friday letter to Anthropic telling the company to suspend Fable 5 and Mythos 5 for every customer (see Section 3 below) is the same Commerce Department that issued this order. The through-line is a Commerce Department willing to use its regulatory reach to roll back both the technical and the statistical privacy practices that the previous decade built [1].
Related: The Census Bureau Just Banned the Math That Kept Your Data Anonymous
A UK Police Officer Is Under Criminal Investigation for Using AI to Fabricate Evidence
Derbyshire Constabulary, in the East Midlands, has launched a criminal investigation into one of its own officers accused of using AI systems to "create evidential material in a number of cases" [3][4]. The officer is alleged to have perverted the course of justice and has been removed from frontline duties. Sky News broke the story on June 13; the Hacker News thread on the Sky piece crossed 304 points and 142 comments within 24 hours, and the BBC confirmed the byline with 30+ HN points and follow-up coverage on its own article [5].
This is the first documented case of a serving UK police officer under criminal investigation for using AI to fabricate case evidence. The story lands the same week the UK Home Office stood up a new national "PoliceAI" centre to coordinate AI deployment across UK policing. The collision is the political economy of the week. The state is pushing AI into frontline policing as the next infrastructure layer, and one of the first public integrity failures is an officer using that technology to manufacture evidence [3][4].
The "evidence fabrication" framing matters. The Crown Prosecution Service and the Forensic Science Regulator rely on chain-of-custody rules designed for paper files, body-worn video, and forensic samples. AI-generated exhibits, especially AI-generated witness statements and AI-generated scene reconstructions, do not fit any of those rules. The Derbyshire case will land in court as the first test of whether existing perversion-of-justice and perverting the course of justice statutes cover AI-fabricated material. If they do not, the legislative gap is going to be the most-cited policy ask in the 2026 UK policing review [3][4].
For the US reader: the same evidentiary-integrity question is alive in this country. Axon AI police report generators, Truleo body-cam analysis, and the dozens of state and local "police AI" pilots all raise the same chain-of-custody question. Our existing Heber City / Axon AI police report piece is the standing reference on the US side [3][4].
Amazon CEO Jassy Pressed the White House to Suspend Anthropic. Anthropic Says It Is a Misunderstanding.
The Wall Street Journal reported late June 13 that the originating pressure for the export-control directive against Anthropic's Fable 5 and Mythos 5 came from conversations between Amazon CEO Andy Jassy and US officials [6]. The Hacker News thread on the WSJ piece crossed 640 points and 469 comments within 12 hours. Axios, The Verge, and Reuters all confirmed the Amazon angle in the next 18 hours [7][8][9].
Read the story carefully. This is not just an export-control order. It is a competitor (Amazon, through AWS, is Anthropic's biggest cloud partner) lobbying the White House against Anthropic specifically. The Verge ran its own follow-up June 13, headlined "Amazon security research reportedly led to the White House's Anthropic Fable ban" [8]. Anthropic's response has been consistent since the 5:21pm ET Friday letter: the company is complying, restoring access, and calls the action a "misunderstanding."
The story is now the political economy of the Anthropic story, not the technical merits of the export-control directive. The "jailbreak" the directive cites is, on Anthropic's reading, a code-review capability that GPT-5.5 and other frontier models can also do. The unanswered question is what the next pressure campaign will look like. If a competitor's CEO can trigger an export-control order with a phone call, every other frontier-AI competitor has a new tool in its belt. The story is in its "second-day" phase and is going to drive the AI policy conversation for the rest of the month [6][7][8][9].
Related: Anthropic Fable 5 and Mythos 5 Suspended by US Government: Anthropic Pushes Back | Anthropic's Hidden Guardrails Apology + AWS Bedrock 30-Day Data Retention
FISA 702, Day 2: The Wiretaps Did Not Blink. The Senate Is Now Fighting Over World Cup Funding.
FISA Section 702 hit its statutory sunset at 11:59 p.m. Eastern on Friday, June 12. As of this briefing going up, the statute has now been lapsed for 48 hours [10][11]. EFF called it "Victory! 702 has Expired" within an hour of midnight. The Cotton-Grassley fallback executive order letter to Secretary of State Marco Rubio (sent June 8, asking State to "begin planning for a fallback executive order" to address what the letter calls a "potential significant gap in foreign intelligence collection") is the second-order fight [10].
The dirty secret from the start has been that the FISA Court's March 2026 annual certifications keep ongoing 702 collection running through March 2027, so the wiretaps do not blink. NPR, the Guardian, AP, Reuters, Politico, and the Cato Institute all ran "what happens now" explainers by Saturday morning. Senator Shelley Moore Capito is reportedly using World Cup funding as the pressure point to pull Democrats toward a short-term extension [11][12].
The 72-hour outlook: any executive order text out of State or the White House, the first statement from AG Bondi or acting DNI Pulte on the lapse, and the next move from Senate Majority Leader Thune. The 47 to 52 cloture math from June 5 has not changed. If the executive order actually materializes, the policy fight moves to a different venue: an EO cannot create new FISA Court certifications, but it can direct the intelligence community to continue collection under EO 12333 and NSL authority and to share the data with FBI and DHS under looser minimization. That is a Section 702 substitute the FISA Court does not get to review [10][11][12].
Related: FISA 702 Lapsed June 12. The Wiretaps Kept Running. | The FISA Court Certification Loophole: Why the Sunset Deadline Is a Headline, Not a Change
Meta Is Suing NSO Group Again. WhatsApp Just Caught Fresh Pegasus Attacks in 2026.
Two related stories landed June 13 to 14. First, Meta announced fresh legal action against NSO Group, the Israeli spyware vendor, in what observers are calling a third round of the WhatsApp v. NSO litigation that has been running since 2019 [13]. Second, WhatsApp published a separate disclosure that it had caught fresh NSO Pegasus exploitation attempts against journalists and human-rights defenders in 2026 [14].
Read the two announcements together. NSO is still actively deploying Pegasus against WhatsApp targets despite the 2019 court injunction and the 2024 SCOTUS-adjacent fallout. Memeburn and BornCity both carried the WhatsApp disclosure. The 2019 case was the first time a major platform sued a commercial spyware vendor and won an injunction; the 2026 case is the first time the same platform is back in court for the third time. The litigation is no longer a precedent. It is a recurring incident [13][14].
The supply-chain angle is what connects this story to the rest of the surveillance beat. Citizen Lab's Webloc RTB surveillance-tool coverage and the 2024 to 2026 commercial-spyware vendor stories (Intellexa, Cytrox, NSO, Paragon) all run through the same handful of brokerage, hosting, and infrastructure providers. If the WhatsApp disclosure names infrastructure providers (as the 2019 disclosure did), the next round of supply-chain reform hits at the cloud and domain layer, not the model layer [13][14].
EU Privacy Regulators Are Coming for Smart Glasses. The EDPB Report Is Due This Summer.
Politico Europe reported on June 8 that European privacy regulators are escalating their warnings over smart glasses, framing it as the next big privacy fight. The European Data Protection Board has commissioned a report on smart glasses due this summer. Sweden's data protection authority has gone public with concerns. Renew Europe MEP Veronika Cifrová Ostrihoňová has written to the Commission asking what EU-level action is possible [15]. The story picked up 94 HN points on June 12 [16].
The story is the EU counterpart to the US-side ACLU coalition push (64 groups) and our recent EFF victory on the Meta Ray-Ban FR code. The two combined are a strong narrative for the EU-vs-Meta smart-glasses beat. The underlying data-labeling scandal (Meta contractors in Kenya recording bathroom and intimate activity to train the on-device AI) is the proof-of-harm that the EU regulators are using to anchor their precautionary framing [15][16].
For US readers: smart glasses are not regulated as a category in the United States. The closest analog is the Illinois Biometric Information Privacy Act (BIPA), which has been used to litigate facial recognition at retail and at airports. The first BIPA suit against Meta over smart glasses would land in Illinois state court, and the same "biometric identifier" definition that has been doing the work in retail and airport cases would do the work here. The litigation vehicle is ready; the defendant is identified; the regulatory gap is the product [15][16].
Quick Hits: Eight Smaller Stories Worth Knowing
H.R. 6028, Copyright Office overhaul. EFF published a deeplinks piece on June 10 saying Congress "rushed through" H.R. 6028, a bill that fundamentally restructures the US Copyright Office [17]. Hacker News picked it up: 198 points, 63 comments. The reason this lands on a surveillance beat: H.R. 6028 changes the Copyright Office's role in the AI-training-data scraping lawsuits that are pending against OpenAI, Anthropic, Meta, and Microsoft. Our standing piece on the AI scraping suits is the right reference for the downstream effect [17].
Maui County, $1.7M, "Eyes in the Sky." The Maui County Council approved $1.7 million in AI surveillance tools for the Maui Police Department, branded "Eyes in the Sky" [18]. This is a fresh local-surveillance expansion on a county that previously had limited public AI surveillance programs. TIE BACK to our Flock Safety cancellation piece for the opposite local-government angle: cities are canceling Flock, this county is buying in.
NHS patients cannot opt out of Palantir. Their hospitals can. openDemocracy has been documenting the NHS-Palantir Federated Data Platform story since at least the June 5 piece on the platform's mass-surveillance posture, and the same opt-out asymmetry is now public: under the new contract, individual patients cannot opt out of having their health data processed by Palantir's platform, but individual NHS hospitals can opt out as institutions [19]. The opt-out asymmetry is the public-facing privacy angle. TIE BACK to the broader Palantir-surveillance network coverage.
Canada privacy watchdog: Grok generated explicit deepfakes without valid consent. Jurist reported June 13 that Canada's privacy commissioner has formally found that xAI's Grok generates explicit deepfakes of real people without valid consent, in violation of Canadian privacy law [20]. This is the first major non-consensual-imagery finding by a G7 privacy regulator against a frontier AI image generator. The finding will land as a precedent other regulators (UK ICO, EU DPAs) can use.
ICE officers broke Ring-style cameras. Local police took them. TechDirt reported June 11 that ICE officers broke Ring-style home security cameras during a New Jersey operation, and local police then took the broken cameras [21]. The surveillance-state angle: federal agents physically destroying civilian surveillance of their operations, then removing the destroyed evidence. Story is part of a larger pattern of friction between federal immigration enforcement and local surveillance infrastructure.
Shai-Hulud variant hits Microsoft GitHub repos. Arch Linux AUR, 1,500+ packages. Memeburn and Phoronix reported June 13 to 14 that a Shai-Hulud variant compromised dozens of open-source Microsoft packages hosted on GitHub, with attackers specifically targeting AI developer credentials. Microsoft disabled 70+ repos in response. The Phoronix story on the related Arch Linux AUR incident (1,500+ packages) is the broader supply-chain signal [22][23]. TIE BACK to the June 12 steganography coverage and the "Mini Shai-Hulud, Miasma, Hades" worm family we already track.
France's own TCHAP got hacked. The encryption-backdoor push just got harder. Reclaim The Net reported June 13 that France's secure-messaging app TCHAP (the official French government chat, mandatory for cabinet ministers) was successfully hacked in 2024, with attack details surfacing in the security research community [24]. The breach is now being deployed as evidence in the debate over France's 2024 to 2026 push to require backdoors in encrypted services. TIE BACK to our existing France Identity Agency breach story from May 31 (different incident, same jurisdiction).
Iran-linked hackers claim three California water utilities (unverified). SJV Water and the New York Post reported June 13 that an Iranian-linked hacker group has allegedly breached the water systems serving Bakersfield, Visalia, and Chico, California, claiming access to SCADA-adjacent control systems [25]. CISA and FBI have not attributed. We are holding this for official attribution before any standalone piece. CITE as "alleged" until confirmed.
What to Watch This Week
- Monday, June 15: Watch for any FISA 702 executive order text out of State or the White House. Watch for the first statement from AG Bondi or acting DNI Pulte on the lapse. The Derbyshire criminal investigation will be the day's lead on the UK side; look for a College of Policing statement. On the Census side, watch for any comment from Census Bureau leadership or from the Government Accountability Office [10][11][3][4][1].
- Tuesday, June 16: EU GDPR 8-year anniversary. Expect a wave of "is GDPR working" retrospectives. Expect the first concrete UK ICO follow-up to the Canada Grok finding. The first 24 hours of any Anthropic response to the Amazon-originated pressure campaign will land here [6][7][20].
- Wednesday, June 17: Watch for Senator Capito's World Cup funding play. The 2026 FIFA men's World Cup matches begin in eight days, and the funding vehicle is the pressure point. If a short-term FISA extension is going to materialize, it materializes here, and the data-broker loophole is the amendment worth watching [11][12].
- Thursday, June 18: Watch for the Anthropic "restore access" plan to take shape. Anthropic said it is complying and working to restore access. The first concrete public signal on whether "restore access" means a fix to the model, a workaround on nationality identification, or a formal legal challenge is going to land in the next 96 hours [6][7][8].
- Friday, June 19: Juneteenth. The site is closed; the publishing calendar pauses for the federal holiday. Weekly roundup drops the following Monday.
- The June 30 cluster. Colorado AI Act (repealed, replaced with the CO ADMT Law; correction on the original tracker entry). T-Mobile March 2026 breach monitoring enrollment deadline. State privacy law amendments in CT, AR, and UT all take effect on July 1, two weeks after that.
References
- Damien Desfontaines: Banning noise will be a disaster for statistical data products (June 11 to 13, 2026)
- Hacker News: Census Bureau noise-infusion ban (800+ points, 500+ comments)
- Sky News: Derbyshire police officer investigated for using AI to create evidence in multiple cases (June 13, 2026)
- BBC: Derbyshire police officer under criminal investigation over AI evidence (June 13, 2026)
- Hacker News: Derbyshire police AI evidence (304 points, 142 comments)
- Wall Street Journal: Amazon CEO's talks with US officials triggered crackdown on Anthropic models (June 13, 2026, paywalled)
- Axios: Anthropic, Amazon, and the White House (June 13, 2026)
- The Verge: Amazon security research reportedly led to the White House's Anthropic Fable ban (June 13, 2026)
- Hacker News: WSJ Amazon CEO triggered Anthropic crackdown (640+ points, 469 comments)
- EFF: Victory! 702 has Expired (India McKinney, June 12, 2026)
- Legis1: FISA Section 702 Authority Expires Amid Intelligence Nominee Fight (June 12, 2026)
- Hacker News: FISA 702 lapsed Day 2 / Capito World Cup funding (carried as part of the rolling 702 thread)
- Reuters: Meta takes legal action against Israeli spyware firm NSO Group (June 8, 2026, paywalled)
- Memeburn: WhatsApp catches fresh NSO spyware attacks in 2026 (June 13, 2026)
- Politico Europe: New privacy frontier: Europe eyes crackdown on smart glasses (June 8, 2026)
- Hacker News: EU smart glasses crackdown (94 points)
- EFF: Congress Just Rushed Through Disastrous Copyright Office Overhaul (June 10, 2026)
- Hawaii News Now: Maui Council approves $1.7M in AI surveillance tools for police (June 13, 2026)
- openDemocracy: Palantir is turning the NHS into a tool for mass surveillance (June 5, 2026, opt-out asymmetry public since)
- Jurist: Canada privacy watchdog says Grok generates explicit deepfakes without users' valid consent (June 13, 2026)
- TechDirt: ICE Officers Break Cameras. Cops Steal Them. Welcome to New Jersey (June 11, 2026)
- Memeburn: Microsoft's GitHub repos were hacked to steal AI developer passwords (June 14, 2026)
- Phoronix: Arch Linux AUR compromised, more than 1,500 packages affected (June 13, 2026)
- Reclaim The Net: France's own hacked chat app is now an argument against its encryption backdoor push (June 13, 2026)
- New York Post: California water systems hit by Iranian hackers in terrifying threat to drinking supply (June 13, 2026, alleged, unverified by CISA/FBI)