A red padlock resting on a black computer keyboard
Photo via Unsplash

Today in Surveillance:

  • Canvas ransom deadline: today. ShinyHunters' "FINAL WARNING" clock runs out on 3.65 TB of student data from 9,000 schools. Instructure is still refusing to comment on the extortion. Some reports say the deadline has been nudged to May 7. Either way, 275 million users are in limbo.
  • Utah SB 73 is now live. The first US state to hold websites liable for VPN-tunneled visitors. Technically impossible to enforce. Constitutionally suspect. In effect as of today.
  • UK wants spy cameras in vans to watch benefit claimants. The DWP just dropped a £2 million tender for covert vehicle-mounted surveillance cameras. The contract runs through 2029, possibly 2031.
  • Meta NM trial, day three. Witness testimony continues in Santa Fe. State wants $3.7 billion and a court-appointed safety monitor. Meta says the demands are impossible.
  • SpaceBears hits Johnson & Johnson. The ransomware group claims to have breached J&J Innovative Medicine, targeting CAR-T research data.

Canvas Ransom Deadline: The Clock Runs Out

Today is the day. ShinyHunters set May 6 as the "FINAL WARNING: PAY OR LEAK" deadline for Instructure, the company that runs Canvas LMS. The threat: dump 3.65 terabytes of data covering roughly 275 million users across 9,000 schools if Instructure doesn't pay up [1]. We covered the full scope of the Canvas breach when it first surfaced.

Some threat intelligence trackers now show the deadline pushed to May 7, giving Instructure one more day of silence. That's the pattern: ShinyHunters extends, ratchets the pressure, extends again. But the stolen data is real. TechCrunch confirmed the breach includes student names, personal email addresses, student IDs, phone numbers, and messages between teachers and students. Instructure spokesperson Kate Holmes declined to answer questions and pointed reporters to the company's status page [2].

The class-action pipeline is already running. Chimicles Schwartz Kriner & Donaldson-Smith and at least two other firms opened investigation pages within 48 hours of disclosure. The legal template from the Infinite Campus suit fits: same threat actor, same industry, 25 times the scale [3].

What makes this breach different from the standard enterprise hack: the victims are children. Student IDs, school emails, private messages between kids and teachers, all sitting on a Tor leak site. ShinyHunters also claims "several billion" private messages from within the platform. Whether that number is inflated or not, the phishing risk is immediate [4].

If you're a parent of a kid who uses Canvas, assume student name, school email, and student ID are compromised. Talk to them about phishing emails dressed up as Canvas password resets. Wayzata Public Schools in Minnesota already sent that warning to parents yesterday [5].

Background: Canvas Breach: How School Districts Are Responding

Utah SB 73 Goes Live: VPNs Are Now a Liability

As of today, Utah is the first US state to hold websites legally responsible for users who tunnel through VPNs to dodge age verification. Senate Bill 73, signed by Governor Spencer Cox on March 19, says a user is considered to be in Utah if they are physically located there, regardless of what their IP address says [6].

The problem: websites can't reliably detect VPN traffic. Commercial VPN providers rotate IP addresses constantly. NordVPN said as much yesterday: blocking every VPN range is "technically impossible" because new addresses appear faster than any blocklist can update [7].

Aylo, the Canadian company behind Pornhub, Redtube, and YouPorn, already pulled the plug on Utah users yesterday. But the law doesn't just affect adult sites. It also makes it illegal for a covered website to explain how to use a VPN to bypass age checks, a speech restriction that EFF flagged as a First Amendment problem before the bill was signed [8].

Here's the collateral damage nobody in the Utah legislature mentioned: VPN users with legitimate privacy needs (domestic violence survivors, journalists, people on hostile home networks) are caught in the same liability trap. The law doesn't distinguish between someone dodging age checks and someone protecting their location from a stalker.

Related: Utah's VPN Law: What Changes Today

Britain Wants Spy Cameras in Vans to Watch Benefit Claimants

The UK Department for Work and Pensions published a £2 million tender last week for covert surveillance equipment, including vehicle-mounted cameras that can record video without the subject knowing. The contract runs from September 2026 to September 2029, with a possible extension to 2031. Bids are due May 18 [9].

The shopping list: in-vehicle cameras for covert recording, live-streaming video systems, encryption technology for footage, evidence management systems, and apps for remote monitoring and control. This is the surveillance infrastructure of a spy agency, deployed against people whose crime is claiming disability benefits.

The legal basis is the Public Authorities (Fraud, Error and Recovery) Act, passed last year. That law gave the DWP power to compel banks to hand over account information, recover money directly from people's accounts without a court order, and strip suspected fraudsters of their driving licences. Minister Andrew Western said the powers would "better identify, prevent and deter fraud and error" and save £1.5 billion by 2029-2030 [10].

Mariano delli Santi from the Open Rights Group put it differently: "Welfare surveillance further stigmatizes people who receive benefits, many of whom already face discrimination and negative stereotyping" [11].

The Big Issue reported this week that the DWP is also hiring "covert surveillance officers," people whose job title literally describes spying on benefit claimants. Between the van cameras, the bank-account surveillance powers, and the dedicated spying staff, the UK is building a parallel surveillance state aimed specifically at its poorest citizens.

Meta Trial Day Three: Three Weeks of Testimony Ahead

Day three of the State of New Mexico v. Meta Phase 2 bench trial continues this morning in Santa Fe. Judge Bryan Biedscheid set the ground rules on day one: he won't "overreach" beyond what existing law permits, and he's watching for the state to ask him to create regulations the legislature never wrote [12].

The state's demands remain staggering. AG Raúl Torrez wants $3.7 billion in restitution over 15 years, mandatory algorithm changes to kill infinite scroll for minors, age verification on every Meta property, permanent bans on adults who target children, and a court-appointed safety monitor for at least five years. Meta's lawyer Adam Mortara called it "a completely new regulatory regime that far exceeds anything in Europe, in Australia, anywhere" [13].

Today's expected witnesses include former Meta integrity researchers and child-development experts. The trial runs through May 22. Whatever Biedscheid decides will become the template every other state AG uses.

Background: Meta Would Rather Quit New Mexico Than Stop Harming Kids

Quick Hits

  • SpaceBears ransomware hits Johnson & Johnson Innovative Medicine. The group listed J&J's pharmaceutical division on its leak site, claiming access to CAR-T research data. The attack was estimated around April 26, discovered May 4. The breach compromised credentials for 209 employees and 14,640 users. J&J has not issued a public statement [14].
  • Fiserv still silent on Everest ransomware listing. The payment-processing giant that handles back-office systems for roughly 10,000 banks was listed on the Everest leak site May 3. Everest threatened to publish stolen data within 3-4 days, putting the leak window right around today. Fiserv has not confirmed or denied the breach. If real, the blast radius runs through small-bank online banking, debit-card networks, and merchant processing [15].
  • UK facial recognition regulators raise alarm. The UK's two Biometrics Commissioners published a report warning that police facial recognition is "nowhere near as effective as the police claim it is" and the law behind it is "patchwork." Commissioner for Scotland Dr. Brian Plastow called for binding standards before more forces deploy the tech [16]. The warning lands as the Met Police plans up to 10 facial recognition deployments a week.
  • Disneyland facial recognition now at nearly every gate. Only four entrance lanes at both Disneyland parks don't scan your face. Disney says it's optional. Critics say the opt-out lanes are easy to miss, and signs explaining the system only appeared four months after face scanning started [17].

What to Watch

  • Today/tomorrow, Canvas data dump. ShinyHunters either leaks, extends, or goes quiet. School districts spend the rest of the week sending parent notifications either way.
  • Today: Fiserv leak window opens. Everest's 3-4 day countdown from May 3 hits today. Watch for data publication or ransom negotiation signals.
  • Mid-May: Congress returns from recess. FISA 702's 45-day extension expires June 12. The Senate needs to negotiate with the House on a three-year reauthorization. Reform proposals are already gutted.
  • Through May 22: Meta Phase 2 trial. Three weeks of testimony in Santa Fe on algorithm harm and what Meta should be forced to fix.
  • May 18: UK DWP surveillance tender closes. Bidding deadline for covert van cameras targeting benefit claimants.
  • June 12: FISA 702 expires (again).
  • June 29: CSAR trilogue #5. Last realistic shot at an EU deal on chat-scanning before summer recess.

Sources

  1. BleepingComputer: Instructure confirms data breach, ShinyHunters claims attack
  2. TechCrunch: Hackers steal students' data during breach at education tech giant Instructure
  3. ClassAction.org: Instructure Data Breach Confirmed, Attorneys Investigating
  4. Cybernews: Canvas breach: Hackers threaten to leak messages of 275M users
  5. FOX 9: Canvas data breach: Wayzata Public Schools sends warning letter to parents
  6. EFF: Utah's New Law Targeting VPNs Goes Into Effect Next Week
  7. Tom's Hardware: Utah first state to hold websites liable for VPN-tunneled users
  8. TechRadar: Utah to become the first US state to target VPN users with controversial age verification law
  9. Biometric Update: UK gov't seeks covert surveillance tech in benefit fraud crackdown
  10. The Big Issue: DWP recruiting 'covert surveillance officers' to snoop on benefit claimants
  11. Computer Weekly: UK Fraud Bill targets benefit claimants for mass surveillance
  12. Source New Mexico: Judge warns New Mexico prosecutors he won't 'overreach'
  13. CNBC: Meta's public nuisance case in New Mexico has billion-dollar consequences
  14. RedPacket Security: SpaceBears ransomware victim: Johnson & Johnson Innovative Medicine
  15. RedPacket Security: Everest ransomware victim: Fiserv
  16. Biometric Update: UK regulators pan patchwork policy for law enforcement facial recognition
  17. Fortune: Disneyland implements facial recognition, guests say they didn't know it was optional