Today in Surveillance:
- Amazon Ring hit with class action over facial recognition. A Virginia man is suing over Ring's "Familiar Faces" feature, which scans and stores the faces of anyone who walks by, no consent asked. Amazon already disabled the feature in Illinois, Texas, and Portland because their biometric laws make it illegal. Everywhere else? Fair game.
- WFP cyberattack exposed 600,000 Gaza households. Names, ID numbers, phone numbers, and location data for half a million families getting food aid, now in unknown hands. It's the largest known breach of humanitarian beneficiary data ever.
- X Corp wants the FTC to kill its privacy order. Musk's company says the 2022 settlement is too expensive and gets in the way of AI development. The FTC is taking public comments until July 2.
- FISA Section 702 expires in 8 days. Senate is stalled over a CBDC rider and concerns about the new intelligence director. No deal in sight.
- The SECURE Data Act hearing revealed deep divisions. Democrats call it an industry giveaway that would gut 20+ state privacy laws. Republicans say it's the consensus approach.
- FROST attack turns your SSD into a browser spy. Researchers proved websites can track your activity by measuring SSD timing: 89% accuracy, no permissions needed.
Amazon Ring Sued Over Facial Recognition That Scans Everyone Who Walks By
Charles Sigwalt, a Virginia resident, filed a class action lawsuit on June 2 against Amazon in federal court in Seattle. His claim: Ring's "Familiar Faces" feature collected and stored biometric data from his face without his knowledge or consent [1].
Familiar Faces uses AI to scan anyone who appears on a Ring doorbell camera, build a facial profile, and then recognize that person when they show up again. Ring users can create up to 50 profiles of frequent visitors. The doorbell tells you "Dad is at the door" instead of just showing motion. Amazon launched the feature in December 2025 in the US and expanded it to the UK in April 2026 [1][2].
Here's the catch: the Ring owner opts in. Nobody else does. "Millions of other Americans passed by a Ring security camera and unknowingly had their facial recognition information collected," the complaint states. Every delivery driver, neighbor, jogger, and passerby gets scanned and catalogued [1].
Amazon says face data is encrypted, never shared, and unidentified faces are automatically deleted after 30 days. But the company already knows this tech is legally toxic in some places. Familiar Faces is disabled in Illinois, Texas, and Portland, the three US jurisdictions with the strictest biometric privacy laws [2]. If it's safe enough for everywhere else, why turn it off there?
Senator Ed Markey (D-MA) demanded Amazon "abandon this plan" back in September 2025. The EFF opposed the feature. Amazon launched it anyway. Sigwalt is seeking at least $5 million in damages for the class [1][2].
Related: How Amazon Ring Turned Your Neighbors Into Surveillance Partners | Ring Killed the Flock Partnership. Public Outrage Works.
Cyberattack on World Food Programme Exposes 600,000 Gaza Households
A cyberattack targeting the World Food Programme's self-registration system exposed sensitive personal data belonging to roughly 600,000 households in Gaza, making it the largest known breach of humanitarian beneficiary data ever recorded [3].
The breach occurred on May 14, 2026. WFP notified affected people via Telegram on May 31 and publicly confirmed the incident on June 2. The exposed data includes names, national ID numbers, mobile phone numbers, and location details: information submitted by Palestinians registering to receive food and cash assistance [3][4].
No attacker has been identified. The attack vector hasn't been disclosed. What we do know: this data is extraordinarily dangerous in the wrong hands. In a conflict zone, names tied to locations and phone numbers aren't just privacy violations. They're potential targeting data. Security researchers warn the breach creates "heightened risks of social engineering and targeted physical or digital surveillance" for an already vulnerable population [4].
For context, the previous largest humanitarian data breach was the 2022 ICRC hack that exposed records of 515,000 people. This one is significantly larger, and the stakes for the people affected are arguably higher [3].
WFP says it's investigating and working to secure systems. That's cold comfort for 600,000 families whose personal data is now floating in the ether.
X Corp Asks FTC to Kill Its Privacy Order, Says It's Blocking AI
Elon Musk's X Corp filed a petition asking the FTC to either throw out or weaken the 2022 consent order that requires the company to maintain specific data security and privacy practices. The FTC announced on June 3 that it's seeking public comments on the request, with a deadline of July 2, 2026 [5][6].
X Corp's arguments are a masterclass in Silicon Valley logic. The company claims: (1) "the order was imposed on a company that no longer exists" (meaning Twitter, not X); (2) everyone responsible for the original violations has left; (3) X has built a "world-class privacy and data-protection program" since; (4) the order "no longer serves any valid regulatory purpose" and costs millions to comply with; and (5) killing the order is "critical to advancing American leadership in artificial intelligence" [5][6].
That last point is the tell. X wants to use its data for AI training, and a privacy consent order makes that messy. The company also invoked the First Amendment, arguing the order constrains its speech rights.
The original 2022 order came after the FTC found that Twitter deceptively used account security data (phone numbers and email addresses people submitted for two-factor authentication) to sell targeted ads. The settlement extended a 2011 consent order and required biennial third-party security audits. X estimates compliance has cost $17 million [5][6].
If the FTC grants this petition, it sends a clear message: buy a company, fire everyone, rebrand, then argue the old rules don't apply to the "new" company. That's a playbook every tech giant will want to copy.
8 Days Until FISA Section 702 Expires. No Deal in Sight.
Section 702 of the Foreign Intelligence Surveillance Act expires on June 12, 2026. Congress has already burned through two short-term extensions (the latest a 45-day clean extension passed in April) and there's still no agreement on a long-term deal [7][8].
The sticking points are multiplying. House Freedom Caucus members are demanding a permanent ban on central bank digital currency (CBDC) as part of any FISA package. "There is no other option," said Rep. Keith Self. Privacy hawks want a warrant requirement for searches of Americans' data that gets swept up in foreign surveillance. Senate Democrats are blocking progress over the appointment of Bill Pulte as acting Director of National Intelligence [7].
"The very nature of our collection is now going to be put in the hands of somebody who has a history of seeking out private information for political gain," Sen. Chris Murphy (D-CT) said of Pulte [7].
What actually happens on June 12? The authority to initiate new surveillance under Section 702 lapses. But certifications already issued to telecom companies remain valid for up to a year, meaning ongoing surveillance programs continue even if the statute technically expires. That's the dirty secret of the "sunset": it's more of a dim than a blackout [8].
EPIC is running a "Reform or Sunset" campaign. The Brennan Center has launched a 2026 resource page tracking every development. Neither expects Congress to do nothing, but the clock is very real.
Related: The FISA 702 Debate: What's Actually at Stake | FISA 702: The 45-Day Extension and the June Deadline
SECURE Data Act Hearing Exposes the Federal Privacy Law Fight
The House Subcommittee on Commerce, Manufacturing, and Trade held its hearing on H.R. 8413, the SECURE Data Act, on June 3. It went about as well as you'd expect for a bill that tries to replace 20+ state privacy laws with a single federal standard [9].
Ranking Member Frank Pallone (D-NJ) didn't hold back: the bill's "data minimization" provisions are a joke, he said, because they let companies collect and use data however they want as long as it's buried in the fine print. The SECURE Data Act is "assembled from industry-friendly state privacy laws that have been pushed by Big Tech," Pallone argued [9].
EPIC's Caitriona Fitzgerald testified that the bill would preempt stronger state laws (like California's CCPA, Illinois's BIPA, and the new wave of state privacy legislation) replacing them with weaker federal protections. The counter-proposal, H.R. 8014 (the Online Privacy Act of 2026), would preserve state authority and include a private right of action. It hasn't gotten a hearing [9][10].
Republicans say the SECURE Data Act mirrors the "Consensus Privacy Approach" adopted by Virginia, Kentucky, Indiana, and other states. That's technically true: those are also the weakest state privacy laws in the country.
FROST Attack: Websites Can Track Your Activity Through Your SSD
Researchers at Graz University of Technology disclosed FROST (Fingerprinting Remotely using OPFS-based SSD Timing), a browser-based side-channel attack that lets any website monitor your browsing activity by measuring how fast your SSD responds to requests [11].
The attack abuses the Origin Private File System (OPFS) API, a legitimate browser feature available in Chrome, Firefox, and Safari. A malicious site creates large files that exceed system memory, forces disk-level reads, and then measures the timing variations caused by SSD contention, essentially detecting when other programs are also reading from the drive. A neural network trained on these patterns correctly identified which websites users visited with 89% accuracy and which applications were running with 96% accuracy [11].
No permissions needed. No pop-ups. No user interaction beyond visiting the page. The attack achieved data transfer rates of 662 bits per second on Linux and 892 bits per second on macOS [11].
Browser vendors aren't exactly rushing to fix this. Google says fingerprinting attacks aren't classified as security vulnerabilities. Apple says it's "currently out of scope." Mozilla acknowledged the findings but hasn't implemented protections. The researchers suggest limiting OPFS storage size or requiring user permission, changes that haven't happened yet [11].
The DIMVA conference presentation is scheduled for July 2026. Until then, every SSD-equipped device with a modern browser is theoretically vulnerable.
Trump's New AI Executive Order: Voluntary Everything
The White House issued an executive order on June 2 titled "Promoting Advanced Artificial Intelligence Innovation and Security." The headline item: AI companies are being asked to voluntarily submit their most powerful models for government testing up to 30 days before public release [12].
The keyword is "voluntarily." The order explicitly states that nothing in it "shall be construed to authorize creation of any mandatory governmental licensing, pre-clearance, or permitting requirement for the development, publication, release or distribution of AI models." It also calls for an AI cybersecurity clearinghouse within 30 days to coordinate vulnerability scanning [12].
Privacy isn't mentioned. Surveillance capabilities of AI systems aren't addressed. Biometric use is not restricted. This is a cybersecurity-focused order that asks nicely and enforces nothing.
Related: Trump's AI Order Asks Silicon Valley to Police Itself
What to Watch
- June 12: FISA Section 702 expiration deadline. If Congress doesn't act, new surveillance authorizations stop, but existing programs keep running on prior certifications.
- July 1: Virginia's facial recognition law (Code 15.2-1723.2) takes effect, banning real-time tracking in public spaces and requiring 98% accuracy minimums. Connecticut and Arkansas privacy amendments also kick in.
- July 2: FTC comment deadline on X Corp's petition to kill its privacy order. Submit yours at ftc.gov.
- Maryland's surveillance pricing ban: HB 895 was signed by Governor Moore on April 28, the first state to restrict algorithmic pricing in food retail. Takes effect October 1. Twenty-three other states have bills pending.
- Ring lawsuit: Watch for Amazon's formal response. If the class gets certified, this becomes the first major test of facial recognition consent law outside of Illinois, Texas, and Portland.
References
- TechCrunch: Amazon faces class action lawsuit over Ring facial-recognition feature (June 2, 2026)
- The Register: Ring faces class action over facial-recognition feature (June 3, 2026)
- The New Humanitarian: Data of 600,000 Gaza households exposed in WFP cyber-attack (June 2, 2026)
- UpGuard: World Food Programme data breach exposes sensitive data of 600,000 households (June 2, 2026)
- National Law Review: FTC Seeks Comment on X Corp. Petition to Set Aside or Modify FTC Order (June 3, 2026)
- FTC: FTC Seeks Comment on X Corp. Petition (June 3, 2026)
- Daily Signal: Congress Battles Over Spy Powers (June 3, 2026)
- Brennan Center: Section 702 of FISA: 2026 Resource Page
- House Democrats Energy & Commerce: Pallone on SECURE Data Act (June 3, 2026)
- Congress.gov: H.R.8014: Online Privacy Act of 2026
- CyberInsider: New FROST attack leverages SSD side-channel to reveal browsing activity (May 29, 2026)
- White House: Promoting Advanced Artificial Intelligence Innovation and Security (June 2, 2026)