A historic courthouse facade with stone columns and engraved lettering
Photo via Unsplash

Today in Surveillance:

  • Meta NM trial, day two. Judge Bryan Biedscheid warned New Mexico's lawyers against "overreach" before yesterday's gavel. AG Torrez wants $3.7 billion and a five-year court-appointed safety monitor. Meta says the demands are unbuildable.
  • ShinyHunters' Canvas ransom hits tomorrow. "FINAL WARNING: PAY OR LEAK." 275 million users, 3.65 TB, and an extortion clock that runs out the same day Utah's VPN law turns on.
  • Aylo blocks Utah. Pornhub, Redtube, and YouPorn pulled the plug on Utah users ahead of Wednesday's SB 73 effective date. Utah residents now move to VPNs that the new law tells them they can't get instructions for.
  • RightsCon Zambia is dead. Beijing leaned on Lusaka over Taiwanese delegates. Zambia killed the conference, including its panels on Chinese digital authoritarianism. Mulungushi Centre cost China $30 million to build.
  • Fiserv hit by Everest ransomware. Major payment processor with 10,000 financial-institution clients. Listed yesterday on the Everest leak site.

Meta Day Two: Judge Tells Prosecutors Not to "Overreach"

Phase 2 of State of New Mexico v. Meta picks up its second day this morning in Santa Fe. Judge Bryan Biedscheid set the tone yesterday before opening statements: he warned New Mexico's prosecutors against asking him to invent regulations the legislature never wrote [1].

That's the central tension. Prosecutor David Ackerman walked the court through a $3.7 billion abatement package that includes mandatory algorithm redesigns to kill infinite scroll for minors, age verification on every Meta property, permanent bans on adults who target children, and a court-appointed safety monitor for at least five years. Meta's attorney Adam Mortara fired back that the state was "asking you to develop from scratch a completely new regulatory regime that far exceeds anything in Europe, in Australia, anywhere" [2].

Meta's pre-trial filing (made public last week) went further: comply with all of New Mexico's demands and the company "may have no choice but to remove access to its platforms for users in New Mexico entirely" rather than rebuild the products. AG Raúl Torrez called that a PR threat and pointed out that Meta has built bespoke versions of Instagram for authoritarian governments when the contract was right [3].

Today's expected witnesses include former Meta integrity researchers and child-development experts. Three weeks of testimony. A ruling probably this summer. Whatever Biedscheid decides becomes the template every other state AG copies.

Background: Meta Would Rather Quit New Mexico Than Stop Harming Kids

ShinyHunters' Canvas Deadline: 24 Hours and Counting

The ransom clock on Instructure runs out tomorrow. ShinyHunters posted "FINAL WARNING: PAY OR LEAK" beside its Tor leak entry for 3.65 terabytes of data covering roughly 9,000 schools and 275 million users. The deadline is May 6 [4].

Wayzata Public Schools in Minnesota became one of the first US districts to issue parent-facing warnings yesterday: their internal systems weren't breached, but Canvas-mediated student data was, and they're telling families to expect phishing emails dressed up as Canvas password resets. That advisory will get repeated by hundreds of districts this week [5].

Instructure's public posture is unchanged: contained, credentials revoked, monitoring increased. The company has not addressed the extortion claims directly. The legal class-action machine is already moving: Chimicles Schwartz Kriner & Donaldson-Smith and Class Action U opened public investigation pages within 48 hours of the breach disclosure. The legal template from the Infinite Campus suit applies almost cleanly here, except this one is roughly 25x bigger [6].

If you have a kid in a school that uses Canvas, assume student name, school email, and student ID are out by Wednesday. Talk to them about phishing.

Full coverage: Canvas Ransom Deadline Hits May 6: What 275M Students and 9,000 Schools Are Facing

Aylo Blocks Utah Before SB 73 Even Takes Effect

Utah's SB 73 (the law that holds websites liable for users behind VPNs) goes live tomorrow, May 6. Aylo, the Canadian conglomerate that owns Pornhub, Redtube, and YouPorn, didn't wait. The company has already cut off Utah IP addresses, telling users on a splash page that the state's age-verification regime is "the least effective" approach to keeping minors offline and creates "real privacy and security risks" for adults [7].

That decision matters for two reasons. One, Aylo's been quietly running this playbook for two years: block first, fight in court later, pull data from the holdouts who try to comply. Two, Utah just became a live test of what happens when the biggest sites cooperate with a state's exit and the rest are stuck under a "liability trap" they can't engineer their way out of [8].

NordVPN's response yesterday was blunt: blocking every VPN IP range in Utah is "technically impossible" because providers add new addresses faster than any blocklist can update them. The law also makes it illegal for a covered site to explain how to use a VPN to bypass age checks, the kind of speech restriction EFF flagged as a clear First Amendment problem before the bill was even signed [9].

What happens Wednesday: VPN signups in Utah go up. Sites that compete with Aylo either follow Aylo and block the state, or stay open and bet that AG Sean Reyes won't sue. Utah residents using VPNs for actual privacy reasons (domestic violence survivors, journalists, people on hostile home networks) are caught in the same liability trap the state set for the porn industry. That's the part the bill's supporters keep skipping past.

Related: Utah's VPN Law: What Changes Wednesday

Beijing Killed RightsCon. Zambia Pulled the Trigger.

RightsCon was supposed to open this morning in Lusaka. The Zambian government cancelled it instead. Around 3,000 digital rights advocates, Taiwanese civil society delegates, and journalists landed in a country that had told them at the airport their conference no longer existed [10].

Access Now, the organization that runs RightsCon, says the cancellation came after Chinese diplomats pressured Zambian officials over Taiwanese participation. The Zambian Ministry of Information dressed it up as a need for "alignment with Zambia's National values and policy priorities." The Mulungushi International Conference Centre, where RightsCon was supposed to run, was built with about $30 million in Chinese government funding [11].

RightsCon 2026's program included multiple panels specifically on Chinese digital authoritarianism: Beijing's spyware exports to Africa, the Belt-and-Road surveillance build-out, the way Chinese-built cell networks become surveillance infrastructure once they're switched on. Those panels are now postponed indefinitely. Human Rights Watch, ARTICLE 19, IFEX, and Front Line Defenders all released parallel condemnations on May 1 [12].

The bigger story: this is the first time China has gotten an entire international civil-society conference shut down on a different continent. The precedent (diplomatic pressure plus debt-financed venue plus a host government that needs the next loan) works. Expect copies.

Full coverage: Beijing Just Killed a Digital Rights Conference in Africa. The Playbook Will Repeat.

Quick Hits

  • Fiserv listed by Everest ransomware. The Everest group added Fiserv (the payment-processing giant that handles back-office systems for roughly 10,000 banks and credit unions) to its leak site Monday. Fiserv has not confirmed the intrusion. If real, the blast radius runs through small-bank online banking, debit-card networks, and merchant processing. Watch the next 72 hours [13].
  • EU CSAR trilogue #4 ended without a deal. Yesterday's Brussels session closed with Parliament and Council still split on encryption scanning. Council pushing "voluntary" scanning that escalates into mandatory detection orders. Parliament holding the line on no scanning of end-to-end encrypted communications. Next session June 29 [14].
  • UN human rights experts: surveillance tools "irreconcilable" with international law. A joint statement from special rapporteurs published last week ahead of the now-cancelled RightsCon called for member states to halt sales and deployments of intrusive surveillance tools, warning that AI-driven surveillance is "intensifying unjustified surveillance" and chilling political expression. Quoted heavily today by digital rights groups responding to Zambia [15].
  • Instructure ransom deadline collides with Utah VPN go-live. Two surveillance-policy stories both cresting Wednesday. Both will be drowned in the same news cycle.

What to Watch

  • Tomorrow, May 6: Canvas ransom deadline. ShinyHunters either drops the data or sets a new clock. Either way, school districts spend the rest of the week notifying parents.
  • Tomorrow, May 6: Utah SB 73 live. First state-level liability for VPN-tunneled users. Watch which sites block Utah, which sites stay open, and which AGs in other states copy the bill.
  • Mid-May: Congress returns from recess. FISA 702 reauthorization back on the table. Deadline June 12. Reform proposals already gutted.
  • Through May: Meta Phase 2 trial. Three weeks of testimony in Santa Fe on what Meta knew and what it should be forced to fix.
  • June 12: FISA 702 expires (again).
  • June 29: CSAR trilogue #5. Last realistic chance for a deal before EU summer recess.

Sources

  1. Source New Mexico: Judge warns New Mexico prosecutors he won't 'overreach' as bench trial against Meta begins
  2. Claims Journal: New Mexico Seeks $3.7B, Changes to Meta Platforms in Youth Harm Trial
  3. The Next Web: Meta would rather leave New Mexico than rebuild its apps for kids
  4. BleepingComputer: Instructure confirms data breach, ShinyHunters claims attack
  5. FOX 9: Canvas data breach, Wayzata Public Schools sends warning letter to parents
  6. TechCrunch: Hackers steal students' data during breach at education tech giant Instructure
  7. HNGN: Porn Sites Blocked in Utah, But VPNs Remain a Workaround
  8. Tom's Hardware: Utah first state to hold websites liable for VPN-tunneled users
  9. EFF: Utah's New Law Targeting VPNs Goes Into Effect Next Week
  10. Human Rights Watch: Zambia, Summit on Human Rights, Technology Effectively Canceled
  11. Access Now / RightsCon: A statement to our community about why RightsCon 2026 will not take place in Zambia
  12. TechPolicy.Press: RightsCon Canceled After Zambia Requires 'Full Alignment' With 'National Values'
  13. The Hacker News: Everest ransomware listings, May 2026
  14. EDRi: CSA Regulation Document Pool
  15. JURIST: UN rights experts concerned over increasing use of intrusive surveillance technologies