Today in Surveillance:
- ICE is paying local police up to $2 billion in 2026. A 287(g) bonus program quietly turning sheriffs and city departments into federal immigration enforcement. NPR/GPB investigation just put numbers to it.
- ShinyHunters' Canvas leak deadline is today. The group already extended once. Duke, Penn, North Carolina school systems all in the blast radius. 275 million students and teachers waiting to see if the file dump lands.
- Meta v. New Mexico: week 2 of the bench trial. Judge Biedscheid already told prosecutors he won't be a "one-person legislator." Three weeks of testimony to go.
- UK Met Police scanned 1.7 million faces in 2026. An 87% jump on 2025. Two Biometrics Commissioners just told the government the legal patchwork can't keep up.
- Healthcare breach wave keeps building. Western Orthopaedics, Tri-Cities Gastroenterology, Community Health Systems, Integrated Pain: four announcements in a week.
- Cushman & Wakefield confirms ShinyHunters vishing hit. 500,000 Salesforce records claimed. Two ransomware groups now naming the company.
ICE Is Paying Your Local Police $2 Billion to Enforce Immigration Law
NPR and Georgia Public Broadcasting published an investigation this week that quantifies what civil-liberties groups have been warning about for months: ICE is dangling unprecedented cash at local police departments to sign 287(g) agreements, and the total bill could hit $2 billion in 2026 alone [1].
That number comes from FWD.us. It assumes every police agency that signs gets the funding ICE has reportedly promised. The current federal grant programs that fund local policing (COPS and JAG-Byrne) would be dwarfed by it.
Where the money goes: vehicles, fingerprint scanners, real-time Spanish-translation AirPods. ICE announced last September it had sent Florida police agencies nearly $40 million for vehicles and equipment alone. Naureen Shah at the ACLU told NPR that "Congress never intended for ICE to be swooping in to these local jurisdictions and offering them money in exchange to participate." The Justice Department's own past audits have flagged 287(g) departments for what investigators called racial profiling. Adding cash on top of that is the part that scares advocates [1].
This story does not sit alone. It plugs into the surveillance budget arc we've been tracking: ICE's $28 billion surveillance budget, the 100,000-officer Mobile Fortify rollout, the 287(g) explosion we covered earlier this year. The new piece is the explicit cash-for-cooperation pipeline. Sanctuary jurisdictions are already feeling the pressure, and state legislatures from Illinois to Washington are looking at 287(g) bans this session.
This story is getting full-article coverage from one of our beat reporters today.
Canvas Leak Day: ShinyHunters' Clock Runs Out Again
May 8 was the latest "final" deadline ShinyHunters set for Instructure to pay or watch 3.65 TB of student data spill onto the open web. The group already moved the deadline once (from May 6 to May 8) and a separate ransom note seen by reporters now mentions May 12 as another possible cutoff. Either way, the clock is no longer credible. The data dump is when it's when [2].
The Duke Chronicle reported May 7 that Duke is among the 9,000 schools in the dataset, joining Penn (300,000+ users affected per The Daily Pennsylvanian), Wayzata Public Schools in Minnesota, and North Carolina K-12 districts where Canvas outages are now disrupting end-of-year testing [3]. Times Higher Education warned Wednesday that personalized phishing aimed at students is the most likely fallout: names, school emails, and student IDs are exactly what a convincing "Canvas password reset" email needs.
If you have a kid using Canvas, or you teach on it: assume the email/student-ID tuple is in the wild. Talk through the phishing risk before any "urgent" Canvas message hits their inbox.
Background: Instructure/Canvas: 275M Students, 3.65TB Stolen · How School Districts Are Responding
Meta NM Trial: Week 2, Judge Still Skeptical
The Phase 2 bench trial in State of New Mexico v. Meta entered its second week this morning in Santa Fe. Judge Bryan Biedscheid set the tone on May 4 when he told prosecutors he held "some concerns" about the state's request for court-mandated platform changes and added that he was "probably not the easiest sell on the idea where I would become a one-person legislator, judge and executive branch enforcer" [4].
What New Mexico is asking for is enormous: $3.7 billion in restitution over 15 years, a court order banning infinite scroll for minors, age verification across all Meta properties, permanent bans on adults targeting children, and an outside safety monitor reporting to the court for at least five years. Phase 1 already produced a $375 million civil-penalty verdict, the largest of its kind. This phase is about whether the judge will write algorithm policy from the bench.
Meta's lawyer Adam Mortara has called it "a completely new regulatory regime that far exceeds anything in Europe, in Australia, anywhere." Whatever Biedscheid decides (expected late May) gets used by every other state AG running a similar case.
Background: Phase 2 Day One: Biedscheid Warns He Won't Overreach · Phase 1: $375M Verdict
UK Met Police: 1.7 Million Faces Scanned, Watchdogs Say "Enough"
The Metropolitan Police has run live facial recognition against more than 1.7 million faces in London during the first months of 2026, an 87% jump from the same period last year. The number landed alongside a sharply worded report from Britain's two Biometrics Commissioners: Tony Eastaugh in England and Wales, and Brian Plastow in Scotland [5].
Their joint message: the law is a patchwork, the oversight is years behind the rollout, and the Information Commissioner's Office audit of the Met has been postponed indefinitely. Retrospective facial recognition (comparing custody mugshot databases against CCTV, doorbell, and dashcam footage) is now running at 25,000+ searches per month at the Met alone.
The accuracy data is ugly. Researchers at Queen Mary University of London found that across six Met live-FR deployments, only 8 of 42 matches were correct, an 81% error rate. Alvi Choudhury, a 26-year-old in Southampton, was arrested at home for a Milton Keynes burglary after Thames Valley Police's software confused him with someone else of South Asian heritage. A Face Int poll found 57% of Britons see live FR as "another step towards turning the UK into a surveillance society."
The High Court approved Met LFR deployment in late April, ruling against a legal challenge. The Crime and Policing Bill is supposed to add governance, but observers expect the meaningful biometric provisions to be watered down before passage.
Background: UK Biometrics Commissioners: Patchwork Policy · Met Police FR Expansion Tracker
Healthcare Breach Wave: Four Providers in a Week
HIPAA Journal logged four healthcare breach notifications in the past few days. Each one is its own story; together they show the same pattern: a months-long gap between intrusion and disclosure, then a notification letter that lands when the data has already been monetized [6].
- Western Orthopaedics (Englewood, Colorado): Network access between September 17–25, 2025, identified October 2. Notifications going out now. Exposed: SSNs, financial account numbers, health insurance info, dates of service.
- Tri-Cities Gastroenterology (Tennessee, 5 locations): 67,115 patients. Intrusion December 11, 2025; investigation closed April 22, 2026. The Insomnia ransomware group already leaked the stolen data on its dark-web site, meaning the ransom wasn't paid and the records are public.
- Community Health Systems: Suspicious activity February 28, 2026; April 28 notification. SSNs, driver's licenses, treatment information, Medicare/Medicaid IDs all in scope.
- Integrated Pain Associates (Killeen, Texas): Network compromised February 24; April 30 notification. SSNs, driver's licenses, diagnosis and medication data.
The throughline is the disclosure delay. By the time you get the letter, the data has been on a leak site for months. Credit-monitoring offers from the breached provider are largely cosmetic at that point. The real defense is a credit freeze you set up yourself, before the next letter arrives.
Cushman & Wakefield Confirms ShinyHunters Hit; Salesforce Campaign Continues
Commercial real estate giant Cushman & Wakefield confirmed this week it suffered a vishing-driven breach. Both ShinyHunters and Qilin have listed the company on their leak sites. ShinyHunters claims more than 500,000 Salesforce records containing PII and internal corporate data, with a May 6 deadline that has now expired [7].
The company's spokesperson called the incident "limited" but didn't confirm or deny the 500,000-record number. The pattern is identical to the rest of the 2026 ShinyHunters campaign: voice phishing of an employee, IT-support impersonation, Salesforce Experience Cloud session hijack, exfiltration, ransom note. Salesforce Ben is now tracking 400+ companies hit since the campaign began.
Cushman is the latest in a chain that includes ADT, Kemper, Ameriprise, Canada Life, Carnival Cruise Line, and dozens more. Same playbook each time.
Background: ShinyHunters Salesforce Campaign Tracker · Cushman & Wakefield Vishing Breach
Quick Hits
- Canada/OpenAI ruling reverberating internationally. The May 6 finding that OpenAI violated PIPEDA in training ChatGPT is now being cited by EU and US regulators as a possible template. OpenAI must add a clear training notice within three months and limit sensitive data ingestion. Our full piece: Canada's Privacy Commissioners Found OpenAI Broke the Law [8].
- NSO Group/WhatsApp case still grinding through appeals. The headline-grabbing $167 million punitive damages award against NSO from May 2025 was reduced by Judge Phyllis Hamilton to roughly $4 million in October 2025, with a permanent injunction barring NSO from targeting WhatsApp users. Both sides are now in front of the Ninth Circuit. NSO is still arguing the damages are unconstitutional; Meta is appealing the reduction. Background on NSO/Pegasus.
- NSO appeal explainer coming. One of our beat reporters is taking the NSO appeal as a standalone piece today, walking through what's actually pending at the Ninth Circuit and what the precedent would mean for the next spyware case.
- Connecticut SB4 still on Lamont's desk. Passed House 141-6 on May 4. The bill creates a data-broker registry, a one-click central deletion tool, a geolocation-sale ban, FR signage requirements, and a surveillance-pricing ban. Lamont has signaled he'll sign. Full breakdown.
- Home Depot ALPR class action keeps growing. Five California residents filed in Sacramento Superior Court April 2 over Flock Safety cameras at 233 California stores. ATF, ICE, and the Air Force can pull from that data. WSB-TV reports an investor group is now pushing for an internal audit. Our piece.
What to Watch
- Today/tomorrow: Canvas data dump. ShinyHunters either leaks, extends again, or goes dark. Either way, school districts are sending parent notifications all week.
- Through May 22: Meta NM Phase 2. Two more weeks of testimony. Watch for any narrowing of remedies as Biedscheid signals where he'll cap an injunction.
- May 11/12: Congress returns. The FISA Section 702 45-day extension expires June 12. The Senate has 36 days to negotiate a reauthorization that doesn't blow up over an attached digital-currency ban.
- This week: Lamont signs SB4 (expected). Connecticut joins the data-broker-deletion club; the state-run central deletion tool is the part the rest of the country will be watching.
- May 18: UK DWP covert-surveillance tender closes. Bidding deadline for the £2 million van-camera contract aimed at benefit claimants.
- June 12: FISA Section 702 expires (again). Reform coalition is mobilizing during the recess window.
- June 29: EU CSAR trilogue #5. Last realistic shot at a deal before summer recess.
Sources
- NPR: ICE is paying incentives to local police to help reach Trump's deportation goals
- Wikipedia: 2026 Canvas security incident (timeline of ransom deadlines)
- Duke Chronicle: Duke among 9,000 schools affected by Canvas cyberattack
- Source New Mexico: Judge warns New Mexico prosecutors he won't 'overreach'
- Biometric Update: UK regulators pan patchwork policy for law enforcement facial recognition
- HIPAA Journal: Data breaches announced by four healthcare providers
- The Register: Cushman & Wakefield confirms vishing cyberattack
- Office of the Privacy Commissioner of Canada: Joint investigation finds OpenAI ChatGPT
- Georgia Public Broadcasting: ICE is giving local police big money
- Daily Pennsylvanian: Over 300,000 Penn users affected in Canvas hack
- Cybernews: Two ransomware gangs now claim Cushman & Wakefield
- ClassAction.org: Tri-Cities Gastroenterology data breach impacts 67K
- ClaimDepot: Integrated Pain Associates data breach
- CT Mirror: Consumer data privacy bill gets final passage in CT House
- Boston Globe: New Mexico seeks child safety restrictions on Meta in trial's 2nd phase
- SecurityWeek: NSO ordered to stop hacking WhatsApp, damages cut to $4 million