Today in Surveillance:
- DHS used a 1930 customs law to unmask a Canadian who criticized ICE online. The man hasn't set foot in the US in over a decade. ACLU-DC filed suit to block Google from handing over his data.
- Canvas ransom deadline is Monday. ShinyHunters told 9,000 schools they have until May 12 before "everything is leaked." Time, NPR, and Wikipedia are all covering it now. Class action attorneys circling.
- AP won the Pulitzer for surveillance reporting. The prize recognized a three-year investigation into Chinese surveillance infrastructure, and the American companies that built it.
- DHS Inspector General: 76% of intelligence office apps are security risks. The agency building the largest surveillance apparatus in US history can't keep high-risk apps off its own phones.
- SECURE Data Act opposition is building. EFF and EPIC both published takedowns. The bill would kill 20+ state privacy laws and replace them with an opt-out-only federal framework.
- Medtronic facing at least six federal class actions. 9 million patient records stolen. ShinyHunters was removed from their leak site, suggesting a ransom was paid.
DHS Used a 1930 Customs Law to Hunt Down a Canadian Who Criticized ICE
A Canadian man who posted anti-ICE comments on X after federal agents killed Renee Good and Alex Pretti in Minneapolis is now suing DHS Secretary Markwayne Mullin to stop the government from obtaining his Google data. The reason he's in court: DHS issued a "customs summons" (a tool from the Tariff Act of 1930) demanding Google hand over his location records, account activity, and identifying information tied to his Gmail-linked X account [1].
The man, identified as "John Doe" in ACLU-DC's filing, hasn't entered the United States in more than a decade. The summons doesn't specify why he's under investigation beyond citing the 96-year-old tariff statute. His lawyers argue the law covers customs entries, duties, and penalties, not speech-linked Gmail data from a foreign national who criticized a government agency [2].
This isn't an isolated use of the tactic. The New York Times reported in February that Google, Reddit, Discord, and Meta received hundreds of administrative subpoenas during the previous six months, all aimed at people who publicly criticized ICE or attempted to track its agents' activities. The Tariff Act summons is the most creative stretch yet: a trade law being weaponized to reach across international borders for speech data.
Background: EFF Sues DHS Over Administrative Subpoenas · Reddit Grand Jury Subpoena for ICE Critic · DHS Instagram Subpoenas
Canvas: 3 Days to the Ransom Deadline. 275 Million Records in the Balance.
ShinyHunters' final-final deadline for Instructure is Monday, May 12. The group told 9,000 schools directly via Canvas messages that "everything is leaked" if payment isn't made by end of day. Instructure disputes the scope (says no financial data, government IDs, or passwords were compromised) but hasn't denied the 275 million record count or the 4TB exfiltration claim [3].
The story has crossed from cybersecurity press into mainstream media. Time published a "What to Know" explainer on May 8. NPR reported Canvas is back online but "questions, and final exam disruptions, linger." The 2026 Canvas security incident now has its own Wikipedia page. CBS8 in San Diego covered campus impact during finals week. WRAL reported the breach may have affected every school in North Carolina [4].
Class action attorneys are moving. ClassAction.org has an active investigation page. Fisher Phillips published guidance for institutions. The Daily Pennsylvanian reports 300,000+ Penn users affected. Cornell's Daily Sun confirmed Canvas went down after the breach was announced. Harvard's Crimson reported the same [5].
If your school uses Canvas: assume your name, email, and student ID are in the wild. Watch for phishing emails disguised as Canvas password resets: that's the attack vector Times Higher Education flagged this week.
Background: 275M Students, 3.65TB Stolen · How School Districts Are Responding · May 12 Deadline and Finals Week
AP Wins Pulitzer for Three-Year Surveillance Investigation
The Associated Press won the 2026 Pulitzer Prize for International Reporting on May 4 for what the Pulitzer board called "an astonishing global investigation into state-of-the-art tools of mass surveillance." Journalists Dake Kang, Garance Burke, Byron Tau, Aniruddha Ghosal, and contributor Yael Grauer were recognized for a three-year project that spanned thousands of documents and dozens of interviews [6].
The investigation found that the Chinese government's surveillance infrastructure was built with direct help from American companies, and that across multiple administrations, the US government allowed tech firms and China to skirt regulations barring access to advanced chips and surveillance components. The reporting also covered the expansion of license plate surveillance within the United States.
It's a signal. When the Pulitzer board calls surveillance reporting "astonishing," it means the scale of what's being uncovered has outrun what most people think is happening.
DHS Can't Secure Its Own Phones. It Wants to Surveil Yours.
The DHS Inspector General published a report this week finding that the department's Office of Intelligence and Analysis (the unit responsible for domestic threat assessment) failed to properly secure the smartphones used by its roughly 800 employees [7].
The numbers: 76% of apps installed on OI&A devices were flagged as security risks, prohibited, or allowed prohibited activities. 19% of devices ran outdated operating systems. The office didn't enforce security settings, didn't screen for high-risk app downloads, and didn't require proper authorization for international travel with government devices. Apps developed by OI&A and shared publicly with first responders (downloaded 375,000 times) contained their own security vulnerabilities [8].
DHS concurred with all 11 recommendations. The irony writes itself: the department operating Webloc, Penlink, facial recognition databases, and the largest immigration surveillance system in history can't keep TikTok-tier security risks off the phones in its own intelligence office.
Privacy Groups Are Sounding the Alarm on the SECURE Data Act
The EFF published "The SECURE Data Act is Not a Serious Piece of Privacy Legislation" on May 5, and EPIC followed with its own broadside: "America needs a strong privacy law. The SECURE Data Act isn't it." The California Privacy Protection Agency sent a formal letter opposing the bill. FPF, IAPP, and multiple law firms have published analysis. The opposition is coordinated and growing [9].
At issue: HR 8413, introduced by House Republicans on April 22, would create a single federal privacy standard that preempts all 20+ state privacy laws. That means Illinois' BIPA, California's Delete Act, Washington's My Health My Data Act, and every other state-level protection gets overwritten. The replacement? An opt-out-only framework with no private right of action, meaning you can't sue companies that violate it. You'd have to ask the FTC to enforce it for you [10].
The EFF put it plainly: the bill "puts the burden on you to opt out of invasive company practices, like targeted third-party advertising, the sale of your personal data, and profiling." The bill makes federal law a ceiling, not a floor. States can't do better.
Background: Federal Privacy Preemption: What's at Stake · SECURE Data Act Breakdown
Medtronic: Six Class Actions Filed, Ransom Likely Paid
Medical device maker Medtronic is now facing at least a half-dozen federal class action lawsuits, filed within days of the company confirming that ShinyHunters breached its corporate IT systems. Plaintiffs include cardiac device patients whose medical records (SSNs, treatment data, device information) were among the 9 million records compromised [11].
One detail that hasn't gotten enough attention: Medtronic was removed from ShinyHunters' leak site. In ransomware dynamics, that almost always means payment was made. Neither Medtronic nor ShinyHunters has confirmed, but the pattern is consistent with paid-and-delisted behavior seen across dozens of ShinyHunters' 2026 targets.
The class action filings allege Medtronic failed "basic security procedures" and that patients now "face a substantial increased risk of identity theft, both currently and for the indefinite future." Multiple law firms (Schubert Jonckheer & Kolbe, Shamis & Gentile, and others) are actively recruiting plaintiffs.
Background: Medtronic: 9M Records Stolen · ShinyHunters Campaign Tracker
Quick Hits
- FISA 702: 34 days to the June 12 deadline. Congress returns from recess Monday. The 45-day extension is ticking. The Senate killed the House's three-year reauthorization over a CBDC provision. Reform advocates (EPIC, EFF, Brennan Center) are pushing for a warrant requirement before the window closes. Full explainer.
- Flock Safety cancel wave hits 30+ cities. Mountain View shut down its cameras after discovering the ATF, Air Force, and GSA Inspector General accessed data without authorization. Security researchers found 67 cameras streaming to the internet without passwords. Boston, Flagstaff, Santa Clara, Cambridge, Eugene, and Santa Cruz have all suspended or terminated contracts. The Flock Rebellion.
- New York Senate passes Facial Recognition Study Act. S3699 creates a task force to recommend a regulatory framework for biometric technology. No immediate restrictions: it's a study-first approach. Moves to the Assembly next. State FR Legislation Roundup.
- Meta NM trial continues in Santa Fe. Phase 2 enters week 2. New Mexico seeking $3.7B and court-mandated algorithm changes. Judge Biedscheid still skeptical about becoming a "one-person legislator." Day One Coverage.
What to Watch
- Monday, May 12: Canvas ransom deadline. ShinyHunters either leaks, extends, or goes quiet. School districts will be sending parent notifications either way.
- Monday, May 12: Congress returns from recess. FISA 702 reform advocates have a 34-day window before the June 12 deadline. The Senate needs to move.
- Through May 22: Meta NM Phase 2 testimony. Watch for Biedscheid signaling how far he'll go on platform-design injunctions.
- May 18-20: IEEE Symposium on Security and Privacy (San Francisco). Watch for surveillance-relevant papers on ad-tech tracking, facial recognition accuracy, and LLM-assisted surveillance.
- June 12: FISA Section 702 extension expires. The real deadline. If Congress can't negotiate, the program either lapses or gets another short-term punt.
Sources
- ACLU-DC: Canadian Trump Critic Sues to Stop Google from Sharing Personal Information with DHS
- WinBuzzer: DHS Demanded Google Surrender Data on Canadian's Anti-ICE Posts
- Time: What to Know About the Canvas Cyberattack
- NPR: Canvas is back online, but questions, and final exam disruptions, linger
- Daily Pennsylvanian: Cybercrime group crashes Penn's Canvas system, demands ransom
- US News: Associated Press Global Investigation Into Government Surveillance Wins Pulitzer
- NOTUS: Inspector General Says DHS Staff Risked Cyberattacks With Government Smartphones
- FedScoop: DHS watchdog flags lagging mobile device security
- EFF: The SECURE Data Act is Not a Serious Piece of Privacy Legislation
- Venable LLP: SECURE Data Act: Congress Introduces New Federal Privacy Framework
- Bank Info Security: Medtronic Already Facing Federal Lawsuits in Recent Hack