United States Capitol building illuminated at night with streetlights and silhouetted pedestrians
Photo via Unsplash

Today in Surveillance:

  • FISA 702 gets another stay of execution. Congress passed a 45-day extension on April 30: no reforms, no warrant requirement, no accountability. The House voted 261-111. The Senate passed it unanimously. New deadline: mid-June. Same fight, later date.
  • Disneyland is scanning your face. Nearly every entrance gate at Disneyland and Disney California Adventure now uses facial recognition. Only four lanes don't. Many guests had no idea it was optional.
  • Eyemart Express hit by ransomware. PayoutsKing gang claims 435 GB of data including Social Security numbers and medical records from the optical retailer's 250+ stores.
  • Citizens Bank breach spawns lawsuits. Two class action suits filed after Everest ransomware gang claimed 3.4 million records. Citizens says most was "masked test data." Courts will decide.
  • EU chat control decision in two days. The CSAR trilogue is scheduled for May 4. Your encrypted messages are on the agenda.

FISA 702: Congress Punts for the Second Time This Month

Section 702 of the Foreign Intelligence Surveillance Act (the law that lets US intelligence agencies hoover up foreigners' communications without warrants, and "incidentally" collect massive amounts of American data in the process) was hours from expiring on April 30. Congress responded the way Congress always responds: with a Band-Aid [1].

The Senate passed a clean 45-day extension by unanimous consent. The House followed with a 261-111 vote: 167 Republicans and 94 Democrats voting yes. President Trump is expected to sign it. Section 702 now expires in mid-June.

Here's how we got here. Speaker Johnson spent weeks trying to pass a three-year reauthorization. The Freedom Caucus wanted warrant requirements for searching Americans' data. Johnson's solution was to tack on a ban on a central bank digital currency (CBDC) to buy their votes. It worked in the House. Senate Majority Leader Thune called the CBDC provision a "poison pill" and killed the bill on arrival [2].

So every proposed reform (warrant requirements, attorney approval for searches, criminal penalties for misuse) got shelved. Again. The FISA Court found just months ago that compliance problems the DOJ claimed to have fixed are ongoing across the intelligence community [3]. None of that mattered enough to force actual change.

"We have done our job. The Senate needs to do theirs," Speaker Johnson said, washing his hands of it on what he called the House's "last legislative day" before recess.

The 45-day window is supposed to give lawmakers time to negotiate a real deal. The last time they had extra time (a 10-day extension in mid-April) they accomplished nothing. There's no reason to think this time will be different.

Related: FISA 702 Bill Implodes Two Days Before Deadline | Three Scenarios for Section 702

Disneyland Scans Your Face at Nearly Every Gate Now

Disney expanded facial recognition technology to most entrance lanes at both Disneyland Park and Disney California Adventure as of late April. Of the dozens of gates at both parks, only four did not use the technology on launch day [4].

The system matches your face against images captured when your ticket or annual pass was first activated. Disney says it converts faces into "unique numerical values" (not stored photographs) and deletes them within 30 days "unless they must be retained for legal or fraud-prevention purposes." That last clause is doing a lot of heavy lifting.

The system had been running since December 2025. New signs explaining which lanes used facial recognition didn't appear until April 21, four months after face scanning began. Many visitors had no idea they could opt out [5].

"The normalization of facial surveillance is really problematic," said Ari Waldman, a professor of law at UC Irvine. "We can't go around life hiding our faces, so this isn't just the next step in surveillance; it's qualitatively different."

Parents flagged concerns about children's biometric data. And in Los Angeles and Orange counties (where 8 to 10 percent of residents are undocumented) the collection of biometric data at a tourist attraction creates conditions for profiling and targeted enforcement. California's Consumer Privacy Act classifies biometric information as sensitive personal data, but Disney seems to be testing the limits of what "optional" means when four out of dozens of gates are the alternative.

Related: Full Analysis: Disneyland's Facial Recognition System

Eyemart Express Ransomware Breach: SSNs, Medical Records Exposed

Eyemart Express, the optical retailer with over 250 stores across 40+ states, has been hit by ransomware. The PayoutsKing gang claimed responsibility on March 10, 2026, saying it grabbed 435 GB of internal data [6].

The compromised data includes names, addresses, Social Security numbers, driver's license numbers, medical information, health insurance details, and dates of birth: basically everything you'd need to steal someone's identity.

Eyemart disclosed the breach to the Texas Attorney General on April 17. As of that date, the company still hadn't notified the people whose data was stolen. Multiple law firms have launched class action investigations [7].

This is the problem with storing sensitive data in bulk: when the breach comes (and it always comes) everything goes at once. Your eye prescription, your Social Security number, your medical history, all packaged together for whoever wants it.

Citizens Bank Breach: Two Class Actions Filed

Two class action lawsuits landed in U.S. District Court in Providence on April 23, both seeking over $5 million in damages after the Everest ransomware gang claimed 3.4 million records from Citizens Bank [8].

Citizens Bank disclosed the breach to the Massachusetts Attorney General on April 28. The compromised data includes names, addresses, and financial account numbers: the kind of information that appears on written checks. Citizens says most of the exposed data was "masked test data" with only a "very limited set" of real customer information involved. The lawsuits suggest affected customers disagree with that characterization.

Both Citizens and Frost Bank (also targeted) blame a third-party vendor. No SSNs or tax IDs were found in the breach, which limits the damage to fraud and social engineering rather than full identity theft. Cold comfort when your bank account numbers are floating around the dark web.

Related: Citizens Bank Breach Full Coverage

TransGlobal Insurance Breach: SSNs and Driver's Licenses Exposed

TransGlobal Insurance Agency, which operates over 30 offices across 15 states, reported a data breach to the California Attorney General on April 29. Unauthorized access occurred on February 18, discovered six days later on February 24 [9].

The stolen data potentially includes names, addresses, Social Security numbers, driver's license numbers, and dates of birth. TransGlobal is offering affected individuals 12 months of credit monitoring: the standard "sorry we lost your data" package that does approximately nothing to undo the damage.

The two-month gap between discovery and disclosure tells you everything about the current state of breach notification. Your data was compromised in February. You're finding out in May.

Ad-Based Surveillance: Webloc Story Keeps Getting Bigger

The NPR investigation into Citizen Lab's Webloc report (revealing how advertising real-time bidding data lets police track 500 million devices without warrants) has now been syndicated across 15+ NPR affiliate stations [10]. The story has legs.

Confirmed Webloc customers include ICE, which uses Webloc to track phones without a warrant, the US military, Texas DPS, DHS, NYC district attorneys, and police departments in Los Angeles, Dallas, Baltimore, Tucson, and Durham. Every time you load a webpage, your data is broadcast to thousands of advertisers in milliseconds. Tools like Webloc just catch the signal and sell it to cops.

This is the story that connects ad tech to mass surveillance in a way anyone can understand. If you missed our deep dive, now's the time.

Related: How Ad Bidding Became a Government Surveillance Pipeline | How Ads Track Your Phone: RTB Explainer

What to Watch

  • May 4, EU CSAR trilogue. The first formal negotiation between the European Parliament, Council, and Commission on the Child Sexual Abuse Regulation. Translation: they're deciding whether to mandate scanning of every private message. The Parliament blocked voluntary scanning, but the Council wants mandatory detection orders. This is the fight for end-to-end encryption in Europe, and Signal has said it will leave the continent rather than break it. Our preview.
  • Mid-June, FISA 702 deadline (again). The 45-day extension runs out. Expect the same circus: reform demands, poison pills, last-minute stopgaps. Set a reminder. We'll be here.
  • Walmart digital price tags. The rollout continues: 2,300 stores and counting, all US locations targeted by year end. Walmart swears they won't use them for surveillance pricing. Maryland already banned it.
  • California CPPA enforcement. The California Privacy Protection Agency held its board meeting April 30–May 1. The agency is transitioning from rulemaking to enforcement. If you do business in California and play loose with consumer data, the regulatory hammer is warming up.

Sources

  1. NPR: Congress extends FISA 702 surveillance program for 45 days
  2. CBS News: Congress passes another short-term FISA extension, hours before deadline
  3. Axios: House passes FISA reauthorization, Senate roadblock awaits
  4. Fortune: Disneyland implements facial recognition to keep the lines moving
  5. Washington Times: Disneyland deploys facial recognition at park gates, raising privacy alarms
  6. DeXpose: PayoutsKing Strikes Optical Retailer Eyemart Express
  7. Migliaccio & Rathod LLP: Eyemart Express Data Breach Investigation
  8. American Banker: Customers sue Citizens, Frost over third-party data breach
  9. ClassAction.org: TransGlobal Insurance Agency Data Breach Reported
  10. NPR: A new study shows how ad-based technology is used for surveillance