Today in Surveillance:
- An unauthorized party pulled roughly 8.8 million records from Denmark's Central Population Register through a private-sector gateway. The Register reported the CPR administration noticed irregular activity in September and confirmed the breach scale on October 2; Denmark's population sits near 6 million, with the full register holding roughly 11 million records, so the spill is bigger than the country. Cybersecurity specialist Jan Kaastrup told The Register the CPR system is essentially broken because it treats a single identifier as proof of identity [1][2].
- Senator Ron Wyden asked ONDCP director Sara Carter to release a 2024 MITRE privacy review of the HIDTA license-plate-reader program. The MITRE review was completed but never published; Wyden's letter says 404 Media reported the HIDTA program is aggregating location data on Americans derived from Flock, Axon, and other vendors' ALPRs. The Wyden letter is the first concrete federal disclosure pressure on the program since the October 2 Flock federal-court ruling [3][4].
- EFF published a global "No ID, No Internet" brief arguing age-verification mandates exclude roughly 850 million people worldwide. The piece is by Jillian C. York with Sheila B. Lalwani, and argues the laws are "less about confirming the age of a user and more about creating barriers to online participation that many people cannot reliably scale" [5][6].
- EFF separately published "Resisting the Menace of Federal Data Consolidation," mapping two years of DOGE, DHS-ICE, and SAVE-driven data sharing. The piece, by Adam Schwartz and Mario Trujillo, catalogs multiple suits including American Federation of Government Employees v. U.S. Office of Personnel Management, California v. Trump (24 states), and EPIC v. USCIS, and reads the consolidation as a sustained threat to the 1974 Privacy Act framework [7][8].
- A 404 Media podcast covered a leaked video showing police can defeat the iPhone's automatic inactivity-reboot feature. Joseph Cox and Lorenzo Franceschi-Bicchierai discussed forensic tooling that re-enters a locked iPhone after Apple's After First Unlock reload; the underlying Franceschi-Bicchierai report was the break [9][10].
- Florida, Iowa, Montana, and Nebraska sued TP-Link Systems, alleging the router giant hid its China ties and misled US consumers. The Register and the state complaints cite TP-Link's 36.6% US unit-share figure and a Rob Joyce 2025 estimate of roughly 60% retail-market share, with the state AGs pressing deceptive-trade-practice claims [11][12].
- The FBI seized seven web domains tied to Integrity Technology Group and the Flax Typhoon botnet. The Register reports the FBI court filings name a US power company in South Carolina as a scanned target and add five CVEs to CISA's Known Exploited Vulnerabilities Catalog; the botnet was operated from 2021 until the disruption [13][14].
Also today: The Register's coverage of TP-Link cited Volt Typhoon and Flax Typhoon together as the threat-actor frame for the multi-state action [11]. EFF's consolidation piece noted 60 million voter records run through SAVE with 21,000 flagged, and 48 of 50 states were asked to hand over voter information: 16 complied and 30 sued [7]. The Register's CPR piece noted roughly 55,000 Greenland residents use CPR numbers; the Greenland number anchors how far a single national ID can carry across borders [1].
Denmark's CPR Register Spilled More Records Than Denmark Has People
An unauthorized party abused a private Danish company's legitimate access to the country's Central Population Register (CPR) and exposed names, addresses, identification numbers, and other personal information on roughly 8.8 million people, The Register reported on October 6. Denmark's population sits near 6 million; the register also holds deceased residents, people who moved abroad, and Greenland enrollees, and tops out around 11 million records. The CPR administration noticed irregular activity in September and confirmed the breach scale on October 2; the digitisation ministry issued a public statement on the weekend of October 4-5 [1].
The Danish civil-identification system runs on Section 38(1) of the Danish Civil Registration System Act, which restricts legitimate CPR access to entities with a legal task. A private-sector partner is exactly the kind of entity that holds that access in normal course, which is what makes the spill a misuse case rather than a front-door hack. Cybersecurity specialist Jan Kaastrup told The Register: "We live in a digitalized society, and therefore we should have much better identification systems" [1][2]. His structural critique matters more than his quote: a single national ID is being treated as the proof of who you are for tax, healthcare, banking, and government services, and a misuse leak on that ID is a leak on every one of those systems.
The Register's framing as a "surveillance-scale" leak is correct. The same week EFF published its global age-verification argument that national-ID-based systems structurally exclude roughly 850 million people who don't have one [5]. The Danish spill is the inverse failure mode: a system that everyone is on, and that one authorized partner had read access to, getting drained. The full State of Surveillance brief on the CPR spill tracks the misuse case, the Greenland factor, and the digitisation minister Christina Egelund's refusal to commit to new CPR numbers [2].
Wyden Presses ONDCP to Release the 2024 HIDTA Privacy Review
Senator Ron Wyden sent a letter on October 9 to Sara Carter, director of the White House Office of National Drug Control Policy (ONDCP), demanding the public release of a 2024 MITRE privacy review of the HIDTA license-plate-reader program. 404 Media's Jason Koebler reported the letter; the request follows 404 Media's earlier HIDTA investigation and the October 2 federal court ruling that a Flock search was an unconstitutional Fourth Amendment seizure [3][4].
Wyden's letter cites MITRE's review directly: "This review was conducted by MITRE and completed in 2024, but ONDCP refused to provide it to my office and has subsequently not made that report public. I urge you to make this review public." The letter also names the data sharing that the review was supposed to cover: "404 Media has reported that the HIDTA program is being used to aggregate location data on Americans derived from Flock, Axon, and other vendors' ALPRs" [3]. The structural argument is straightforward: when a federal grant program concentrates plate reads from local agencies into a federal database, the privacy bargain is moved from the city council to the White House, with no public review of the budget.
The angle builds directly on the State of Surveillance coverage of HIDTA, Flock, and the federal ALPR fight. The constitutionality ruling is the legal hook. The Wyden letter is the disclosure hook. The HIDTA + MITRE angle is the accountability hook: the privacy review of the program was already done, paid for, and is being hidden. Our ongoing ban-Flock coverage tracks the parallel federal Ban Flock Act proposals [4][15].
EFF's "No ID, No Internet" Brief Frames Age Verification as Exclusion Infrastructure
EFF's Jillian C. York and Sheila B. Lalwani, a COMPASS Fellow, published "When No ID Means No Internet: Age Verification and the Right to Access Information" on October 8. The piece frames mandatory age-verification rules as exclusion infrastructure rather than child-safety tools: roughly 850 million people globally do not have any form of state-issued ID, and the rules sort those users off the platforms the rules purport to protect [5].
The specifics anchor the global frame. The piece notes roughly 15 million US adults lack a driver's license, roughly 2.6 million lack any government photo ID, and roughly 64.4 million Nigerians have registered for the National Identification Number since 2007, only about 30% of the population. It also names the differential impact: women are 8% less likely than men to have an ID. The piece quotes EFF's framing that age-verification laws are "less about confirming the age of a user and more about creating barriers to online participation that many people cannot reliably scale," and an EDRi formulation that the laws "have serious human rights implications and ironically harm the very individuals they deem to protect" [5].
Australia's under-16 social media ban, in place since late 2025, is the running case the piece circles back to, and the US state-by-state age-verification mandates now layering on top are the immediate US context. The full State of Surveillance piece on the surveillance architecture of age verification carries the rolling state-by-state tracker [6][16].
EFF Maps Two Years of Federal Data Consolidation in Three Waves
EFF's Adam Schwartz and Mario Trujillo published "Resisting the Menace of Federal Data Consolidation" on October 9, mapping what they call three waves of federal data amalgamation: the Department of Government Efficiency (DOGE) created on January 20, 2025 and its "prompt access to all unclassified agency records" mandate, agency-to-agency sharing that routes benefits and tax data to ICE, and SAVE-Act voter-roll purges. The piece links the three waves together as a sustained attack on the 1974 Privacy Act framework [7][8].
The filing map is the heart of the piece. The lawsuits named include American Federation of Government Employees v. U.S. Office of Personnel Management, Centro de Trabajadores Unidos v. Scott Bessent, California v. HHS, League of Women Voters v. DHS, Common Cause v. DOJ, California v. Trump (with 24 states), and EPIC v. USCIS. EFF reports 25 of 30 DOJ suits in the wave have been dismissed, with Supreme Court shadow-docket stays granted 6-3 twice and a mail-in ballot injunction stay denied 7-2. The piece notes 60 million voter records run through SAVE with 21,000 flagged, and that 48 of 50 states have been asked to hand over voter information: 16 complied, and 30 sued [7].
The political argument is structural, not partisan. EFF's prescription is to strengthen the 1974 Privacy Act, pass the Fourth Amendment Is Not For Sale Act, and enact a comprehensive consumer-privacy law. The surveillance reading is that the inter-agency sharing build is the same direction as the HIDTA build: data collected for one federal mission is being routed to another federal mission without a public-record stage. Our earlier coverage of ICE's location-data buy traces the data-broker end of the same pipeline [8][17].
404 Media Reports Police Can Defeat the iPhone's Automatic Reboot
The 404 Media podcast published on October 8 covered an underlying Franceschi-Bicchierai report on a leaked video in which forensic tooling defeats the iPhone's automatic inactivity-reboot, the post-reboot relock Apple designed to keep a seized phone in "Before First Unlock" mode. The episode's headline framing came from Joseph Cox: "Cops are getting around a very important iPhone security feature" [9][10].
The technical surface is the lock-state machine. Apple ships a setting that reloads an iPhone into "Before First Unlock" after a period of inactivity, on the logic that a long-disconnected phone in "After First Unlock" mode is the more exploitable target. The leaked video, paired with reporting on commercial tools like GrayKey, shows investigators reconnecting before the timer fires and harvesting data anyway. A reader-level framing: the security feature assumed a phone would be off for days, not minutes; the forensic workflow assumes minutes, not days. The two assumptions no longer match [10].
This is the device-security story that connects to Lockdown Mode and to the West Virginia v. Apple CSAM case: the same Apple security stack that is being litigated in state court is also the stack law enforcement is now working around at the field level. The full 404 Media reporting cycle on the technical surface is the source of record [10].
Four States Sue TP-Link Over China Ties and the Router Living Room
The attorneys general of Florida, Iowa, Montana, and Nebraska sued TP-Link Systems on October 7, alleging the California-incorporated router giant hid its Chinese supply-chain ties and misled US consumers about device safety. The Register's report puts the market footprint at 36.6% of US unit share in 2024, and cites former NSA cybersecurity director Rob Joyce's 2025 testimony putting TP-Link's share of the US retail market at roughly 60% [11][12].
The legal theory is state consumer-protection law applied to a foreign-supply-chain case. Iowa AG Brenna Bird: "Iowans' sensitive data and our national security is at risk because of TP-Link and their connection to the communist Chinese government." Montana AG Austin Knudsen: "TP-Link's false statements and deceptive advertising are a violation of Montana law." TP-Link Systems corporate affairs officer Steve Kovsky rejected the allegations: "Any claims that our products present a threat to user security or grant unauthorized network access to foreign governments are baseless" [11]. The case arrives two months after Texas filed a parallel TP-Link action in February 2026.
The router is the supply-chain surveillance story that doesn't need a phone or a license plate. A compromised home router sees everything the household touches. The Register cites Volt Typhoon and Flax Typhoon together as the threat-actor frame, and the FBI's October 8 Flax Typhoon domain seizure provides the alleged mechanism: scanner tools run against exposed services, credentials walk out, and the botnet framework persists across firmware reboots. The FCC's March 2026 move on foreign-produced router models is the regulatory backdrop [11][13].
What to Watch This Week
MITRE's HIDTA review and Wyden's reply window. ONDCP's standard letter-response window runs the public pressure timeline. Watch whether the MITRE 2024 HIDTA privacy review lands on the public docket by October 16, and whether ONDCP publicly names which Hemisphere and ALPR questions the review covers [3].
The Mississippi EFF consolidation litigation docket. California v. Trump's 24-state posture, and the EPIC v. USCIS suit, are the leading cases. Watch for the next 6-3 or 7-2 SCOTUS shadow-docket ruling on a data-sharing motion, and for new SAVE-Act voter-roll purge motions in remaining states [7].
The Danish CPR misuse case. The Register reported the breach was discovered through September activity and confirmed October 2. Watch for a Digitisation Ministry statement on whether CPR numbers will be reissued, and for the first Danish Data Protection Agency enforcement notice naming the access-misuse private partner [1][2].
Flax Typhoon disruption follow-on. The FBI's October 8 domain seizure is the public-facing action. Watch for the second indictment against Integrity Technology Group personnel, and for a US-CISA advisory on consumer-routers and the MS Exchange CVE scanned by the Flax Typhoon toolkit [13][14].
Age-verification state tracker. EFF's 850-million global figure lands while a wave of US state-level age-verification bills are still moving. Watch for the next state to enact a major-platform age-verification mandate and the first court challenge under state privacy law [5][16].
Sources
- The Register, Jude Karabus: Denmark's ID register spills more people's details than the country has residents, October 6, 2026. https://www.theregister.com/a/5301307
- State of Surveillance: Age Verification as Surveillance: The ID System Behind Every Check (2026). /news/age-verification-surveillance-infrastructure-id-system-2026
- 404 Media, Jason Koebler: Following 404 Media Investigation, Senator Demands Info About White House's License Plate Surveillance Program, October 9, 2026. https://www.404media.co/following-404-media-investigation-senator-demands-info-about-white-houses-license-plate-surveillance-program/
- State of Surveillance: Federal Judge Rules Flock ALPR Search Unconstitutional (October 9, 2026). /news/flock-alpr-search-unconstitutional-federal-judge-2026
- EFF Deeplinks, Jillian C. York and Sheila B. Lalwani: When No ID Means No Internet: Age Verification and the Right to Access Information, October 8, 2026. https://www.eff.org/deeplinks/2026/10/when-no-id-means-no-internet-age-verification-and-right-access-information
- State of Surveillance: Age Verification as Surveillance: The ID System Behind Every Check (2026). /news/age-verification-surveillance-infrastructure-id-system-2026
- EFF Deeplinks, Adam Schwartz and Mario Trujillo: Resisting the Menace of Federal Data Consolidation, October 9, 2026. https://www.eff.org/deeplinks/2026/10/resisting-menace-federal-data-consolidation
- State of Surveillance: ICE Location Data IG Probe: 70 Lawmakers Demand Answers (2026). /news/ice-location-data-ig-probe-70-lawmakers-illegal-purchases-2026
- 404 Media, Joseph Cox (host): Podcast: Leak Show Cops Can Break into Locked iPhones, October 8, 2026. https://www.404media.co/podcast-leak-show-cops-can-break-into-locked-iphones/
- 404 Media, Lorenzo Franceschi-Bicchierai: Cops Can Bypass iPhone's Automatic Reboot to Get Into Locked Phones, Leaked Video Claims (October 2026). https://www.404media.co/cops-can-bypass-iphones-automatic-reboot/
- The Register, Connor Jones: US states sue popular kitmaker TP-Link over China risks, October 7, 2026. https://www.theregister.com/a/5301653
- State of Surveillance: Ban Flock Act: Sanders, Ocasio-Cortez, Merkley Introduce Federal ALPR Ban (October 7, 2026). /news/ban-flock-act-sanders-ocasio-cortez-merkley-alpr-federal-2026
- The Register, Jessica Lyons: US disrupts Chinese hacking tools as 7 govts warn of PRC spies stealing sensitive data worldwide, October 8, 2026. https://www.theregister.com/a/5302107
- State of Surveillance: Flock ALPR Search Unconstitutional Federal Judge (October 9, 2026). /news/flock-alpr-search-unconstitutional-federal-judge-2026
- State of Surveillance: Ban Flock Act Sanders Ocasio-Cortez Merkley ALPR Federal (October 7, 2026). /news/ban-flock-act-sanders-ocasio-cortez-merkley-alpr-federal-2026
- State of Surveillance: Doctorow Age Verification Is Mass Surveillance (June 25, 2026). /news/cory-doctorow-age-verification-is-mass-surveillance-2026
- State of Surveillance: ICE Location Data IG Probe 70 Lawmakers Illegal Purchases (March 4, 2026). /news/ice-location-data-ig-probe-70-lawmakers-illegal-purchases-2026