Today in Surveillance:
- Five Eyes issues rare joint spy warning. FBI, MI5, and intelligence agencies from Australia, Canada, and New Zealand are warning that Chinese military intelligence is using LinkedIn, Indeed, Upwork, and Craigslist to recruit government insiders. Fake job ads for "foreign policy analysts" are the bait.
- EFF confirms Meta deployed facial recognition code to glasses. Static analysis of the Ray-Ban Meta app reveals a working "Name Tag" system that converts faces into 2,048-number arrays. Internal docs show Meta planned to launch "during a dynamic political environment" to dodge civil society pushback.
- Russia turns schools into surveillance networks. Amnesty International found teachers are ordered to monitor students' online activity, collect dossiers on their opinions, and report dissent to authorities.
- FISA Section 702 expires in 7 days. Senate remains stalled. No deal in sight. The clock is very real.
- FTC fines Cox Media $930K for fake "Active Listening" claims. Their AI ad service claimed to eavesdrop on conversations through your phone. It didn't. It was just reselling email lists.
- GM pays $12.75M in largest CCPA settlement ever. California caught General Motors selling driver location data and driving behavior to data brokers without proper consent.
- EFF tells Congress: rein in agencies, not just AI. Testimony to the House Homeland Security Subcommittee warned that government AI deployment without safeguards "supercharges unconstitutional violations of civil liberties."
Five Eyes Issues Rare Joint Warning: Chinese Spies Are Recruiting on LinkedIn
The FBI, MI5, and intelligence agencies from Australia, Canada, and New Zealand issued what they called an "unprecedented" joint bulletin on June 3-4: Chinese military intelligence services are using professional networking sites to recruit assets with access to classified information [1][2].
The playbook is straightforward and effective. Chinese operatives (posing as employees of private consultancies, think tanks, or HR firms) post job ads on LinkedIn, Indeed, Upwork, and Craigslist for positions like "foreign policy analyst" or "defense researcher." When resumes come in, they're ranked by how likely the applicant is to have access to sensitive government information [1][2].
Then come the interviews. Candidates face probing questions about government contacts, military base locations, and responsibilities. Those who pass get offered "trial tasks": write a report on China-related matters. Conversations shift to encrypted platforms. Payment arrives via PayPal, Zelle, Wise, Western Union, or cryptocurrency. By the time the target realizes what's happening, they're already compromised [2][3].
MI5 warned that "individuals engaged in the unauthorized disclosure of sensitive or classified information could face prosecution under national laws such as those relating to espionage" [2]. Translation: if you take the bait, your own government prosecutes you, not the Chinese operatives who set the trap.
The target list is broad: security clearance holders, defense workers, military personnel, academics, journalists, and think tank employees with government connections. Bloomberg, The Register, NBC News, and the Washington Post all confirmed the bulletin's details [1][3].
What makes this significant isn't the tactic: intelligence agencies have used job platforms for recruitment for decades. It's the Five Eyes publicly agreeing to warn about it together. These agencies don't do joint public statements unless the scale of the problem demands it.
EFF Confirms: Meta Already Deployed Facial Recognition Code to Millions of Ray-Ban Glasses
EFF's Threat Lab published "Move Fast, Surveil Things" on June 4, confirming through static code analysis what privacy advocates feared: Meta has shipped facial recognition functionality to millions of Ray-Ban smart glasses. The code is present, active, and waiting to be switched on [4].
The system (internally called "Name Tag") converts every face the glasses detect into a 2,048-number array representing the positioning of facial features. When activated, it compares each new face against stored faceprints in the user's database. A separate researcher manually activated the feature by adding a face through a connected computer in debug mode, confirming the glasses could then detect that face [4].
Internal Meta documents make the strategy explicit. The company planned to launch facial recognition "during a dynamic political environment where many civil society groups that we would expect to attack us would have their resources focused on other concerns" [4]. They know it's controversial. They timed it to minimize resistance.
This is the same company that paid $650 million to settle a BIPA lawsuit over mass facial recognition on Facebook, then shut down that feature entirely. Now they're putting it on your face. Texas Attorney General Ken Paxton is investigating. The ACLU and 75 organizations have formally opposed the feature [4][5].
Related: Meta Killed Facial Recognition on Facebook. Now It's Putting It on Your Face.
Russia Turns Schools Into "Factories of Compliance" Through Student Surveillance
Amnesty International released a briefing on June 1 titled "Only Official Sources," documenting how Russian schools have become instruments of state surveillance and indoctrination. Teachers are instructed to monitor students' online activity, compile dossiers on their political and social opinions, and report dissenting views to authorities [6].
The system is called "profilaktika": prevention measures that involve constant clandestine monitoring of students both inside and outside schools, including their internet activity. Officially, it's meant to prevent "extremism" and "terrorism." In practice, it screens children's political, religious, and personal views for anything that deviates from state doctrine [6][7].
Since 2023, the Russian Ministry of Education has imposed a single mandatory set of history textbooks portraying Russia as a "besieged fortress." Ukrainian identity and statehood are denied or diminished. Children across Russia and Russian-occupied Ukraine are being subjected to centrally controlled curriculum designed to produce compliance, not education [6].
Amnesty says the approach violates Russia's obligations under the Convention on the Rights of the Child, which requires education to develop respect for human rights. The Moscow Times described the findings as confirming "mounting pressure on children in Russia" [6][7].
7 Days Until FISA Section 702 Expires. The Senate Is Still Stuck.
Section 702 of the Foreign Intelligence Surveillance Act expires on June 12, 2026. Congress has already used two short-term extensions (the latest a 45-day clean extension passed April 30) and there's still no agreement on a long-term deal [8][9].
The House passed a 3-year extension, but the Senate is stalled over a CBDC rider that House Freedom Caucus members insist on attaching. Privacy hawks from both parties want a warrant requirement for searches of Americans' communications. Senate Democrats are blocking over concerns about the new intelligence director. The Brennan Center launched a dedicated 2026 resource page to track the countdown [8][9].
The reform coalition (Senators Wyden and Lee, plus the bipartisan Problem Solvers Caucus) is pushing for warrant requirements. EPIC is running a "Reform or Sunset" campaign. The EFF has called the House extension bill "insufficient" [8].
What actually happens on June 12? New surveillance authorizations stop. But FISC annual certifications may keep ongoing collection running until as late as April 2027. The "expiration" is more theatrical than operational, but it's the only bargaining power reformers have.
Related: FISA 702 Gets Another 45-Day Extension: And Reform Is Dead on Arrival
FTC Fines Cox Media $930K: Their "Active Listening" Ad Service Was a Scam
The FTC announced on May 21 that Cox Media Group, MindSift, and 1010 Digital Works must pay a combined $930,000 for deceptively marketing an "Active Listening" AI-powered advertising service. The service claimed to listen to consumers' conversations through their smart devices to target ads in real time [10].
It didn't listen to anything. The companies were reselling email lists from other data brokers (at a significant markup) and calling it AI-powered eavesdropping. They also told small business customers the service could place hyperlocal ads in specific locations. That didn't work either [10].
The deception ran deeper. All three companies told potential customers that consumers had "opted in" to being listened to by agreeing to terms of service when downloading apps. That's not consent. That's a buried clause nobody reads being used to justify surveillance theater [10].
CMG pays $880,000; MindSift and 1010 Digital Works pay $25,000 each. The irony is thick: the company that promised to spy on you through your phone was just running a plain old data broker hustle. The surveillance was fake. The privacy violation was real: they still collected and sold data without meaningful consent [10].
General Motors Hit With Largest CCPA Fine Ever: $12.75 Million
California Attorney General Rob Bonta announced on May 8 a $12.75 million settlement with General Motors and its connected vehicle service OnStar, the largest fine ever issued under the California Consumer Privacy Act [11].
GM was selling vehicle-generated data from hundreds of thousands of California drivers to data brokers, including precise geolocation and driving behavior data. The settlement alleges GM violated the CCPA's data-minimization principle: collecting and sharing far more data than necessary for the services people signed up for [11].
The penalty includes a five-year ban on selling driving data to consumer reporting agencies, including data brokers. It's California's first enforcement action centered on data minimization, signaling that "collect everything, sell everything" is no longer an acceptable default, at least in California [11].
Your car was already ratting you out to insurance companies. Now we know the state AG agrees that's illegal.
EFF Tells Congress: "Rein In the Agencies, Not Just the AI"
EFF Senior Policy Analyst Dr. Matthew Guariglia testified on June 4 before the House Homeland Security Subcommittee on Cybersecurity and Infrastructure Protection. The hearing ("The AI Security Landscape") focused on how frontier models and agentic AI are reshaping cybersecurity [12].
Guariglia's key point cut through the usual AI governance noise: "The question is not how do we rein in AI: it's how do we rein in the agencies that would unleash AI on the American public." He warned that using generative AI for mass government surveillance would "supercharge unconstitutional violations of civil liberties" [12].
He cited specific failures: AI producing false citations in legal briefs, and a DHS incident where AI errors sent recruits to field offices without proper training. Government secrecy combined with proprietary black-box systems means nobody (not the public, not lawmakers) knows when these systems fail [12].
Quick Hit: FTC Begins Enforcing the TAKE IT DOWN Act
As of May 19, the FTC is enforcing Section 3 of the TAKE IT DOWN Act. Covered platforms must now provide a way for people to request removal of nonconsensual intimate images (including AI-generated deepfakes) and remove them within 48 hours of a valid request [13]. The law is the first federal enforcement mechanism targeting AI-generated sexual imagery without consent.
What to Watch
- June 12: FISA Section 702 expiration deadline. Seven days. If Congress doesn't act, new surveillance authorizations stop, but existing programs keep running on prior FISC certifications.
- Five Eyes follow-up: Watch for specific case disclosures or arrests related to the LinkedIn recruitment campaign. Intelligence agencies don't issue joint warnings this public without expecting follow-through.
- Meta facial recognition: Texas AG Paxton's investigation into Meta's Ray-Ban glasses could produce a CID (civil investigative demand) any day. The EFF code confirmation strengthens his hand.
- July 1: Virginia's facial recognition law takes effect. Connecticut and Arkansas privacy amendments also kick in. Reddit's updated privacy policy goes live.
- July 2: FTC comment deadline on X Corp's petition to kill its privacy order. Yesterday's briefing covered the details.
References
- Bloomberg: US, Five Eyes Warn of Chinese Spies Using LinkedIn for Recruitment (June 3, 2026)
- The Register: Five Eyes: Watch out for odd LinkedIn connection requests (June 4, 2026)
- Washington Post: U.S. and intelligence allies issue rare joint warning about China (June 3, 2026)
- EFF: Move Fast, Surveil Things (June 4, 2026)
- ACLU: 75 Organizations Sound Alarm on Meta Facial Recognition (2026)
- Amnesty International: Russia: Schools have turned into "factories of compliance" (June 1, 2026)
- The Moscow Times: Rights Groups Warn of Mounting Pressure on Children in Russia (June 1, 2026)
- Brennan Center: Section 702 of FISA: 2026 Resource Page
- CNBC: FISA Section 702: Congress passes short-term extension (April 30, 2026)
- FTC: Cox Media Group Settlement Over "Active Listening" Claims (May 21, 2026)
- The Record: GM to pay over $12 million in California privacy settlement (May 2026)
- EFF: EFF Testifies to Congress on Protecting Americans' Rights from Government AI (June 4, 2026)
- National Law Review: The Privacy Filter: June 2026