Today in Surveillance:

  • Senator Ron Wyden asked ONDCP director Sara Carter to release a 2024 MITRE privacy review of the HIDTA license-plate-reader program. Wyden's October 9 letter cites MITRE's completed-but-not-public review and 404 Media's reporting that the HIDTA program aggregates location data on Americans derived from Flock, Axon, and other vendors' ALPRs. The letter lands three weeks after the October 1 ruling in United States v. Kyle, in which U.S. District Judge Sara Hill of the Northern District of Oklahoma called a single Flock search "a type of indiscriminate mass surveillance" and suppressed the evidence [1][2].
  • EFF published "Resisting the Menace of Federal Data Consolidation," mapping two years of federal data sharing in three waves. Adam Schwartz and F. Mario Trujillo's October 9 piece names DOGE's "prompt access to all unclassified agency records" mandate, agency-to-agency sharing that routes benefits and tax data to ICE, and SAVE-Act voter-roll purges as a sustained attack on the 1974 Privacy Act framework. The lawsuits named include California v. Trump (24 states) and EPIC v. USCIS [3][4].
  • EFF separately published "When No ID Means No Internet," arguing ID-mandated age-verification gates exclude roughly 850 million people globally. Jillian C. York and Sheila B. Lalwani's October 8 piece anchors the global frame with the US figure: roughly 15 million adult US citizens lack a driver's license, and a further 2.6 million lack any government photo ID [5][6].
  • The FBI seized seven web domains tied to Integrity Technology Group and the Flax Typhoon botnet. Jessica Lyons reported in The Register that FBI special agent Adam James's filings name a US power company in South Carolina as a scanned target, add five CVEs to CISA's Known Exploited Vulnerabilities Catalog, and document a 260,000-device botnet "infecting devices from 2021 until the FBI stepped in." CISA published advisory AA26-281A on the same day [7][8].
  • Florida, Iowa, Montana, and Nebraska sued TP-Link Systems, alleging the router giant hid its Chinese supply-chain ties. The Register's report puts TP-Link's market footprint at 36.6% of US unit share in 2024 and 31% by dollar share, and cites former NSA cybersecurity director Rob Joyce's 2025 House testimony estimating TP-Link's share of the US retail Wi-Fi/SoHo router market at roughly 60% [9][10].
  • Denmark's Central Population Register spilled roughly 8.8 million records through a private firm's authorized access. The Register reported the CPR administration noticed irregular activity in September and confirmed the breach scale on October 2. Denmark's population sits near 6 million; the full register holds roughly 11 million records, so the spill is bigger than the country [11][12].
  • A 404 Media podcast covered a leaked video showing police can defeat the iPhone's automatic inactivity reboot. Joseph Cox and Lorenzo Franceschi-Bicchierai discussed forensic tooling that re-enters a locked iPhone after Apple's After First Unlock reload, the security feature Apple shipped to keep seized phones in a hardened state [13][14].

Continuing threads: EFF's federal data consolidation brief reported more than 60 million voter records run through SAVE with 21,000 flagged as potential noncitizens, that at least 48 states have been asked to hand over voter information, that at least 16 states complied, and that the federal government has sued 30 states over voter data, with courts dismissing 25 of those suits [3]. The Register's Denmark CPR piece noted roughly 55,000 Greenland residents also use CPR numbers for healthcare, tax services, and banking, which is how far a single national ID can carry across borders [11]. The site's weekly surveillance roundup for October 5 to 11, 2026 carries the full thread index.

Wyden Presses ONDCP to Release the 2024 HIDTA Privacy Review

Jason Koebler reported on October 9 in 404 Media that Senator Ron Wyden sent a letter to Sara Carter, director of the White House Office of National Drug Control Policy (ONDCP), demanding the public release of a 2024 MITRE privacy review of the HIDTA license-plate-reader program. Wyden's letter cites MITRE's completed-but-not-public review and 404 Media's reporting that the HIDTA program aggregates location data on Americans derived from Flock, Axon, and other vendors' ALPRs [1].

The letter puts three statements in the public record. First, the MITRE review was commissioned by ONDCP and "should be released to the public." Second, the review was "conducted by MITRE and completed in 2024, but ONDCP refused to provide it to my office and has subsequently not made that report public. I urge you to make this review public." Third, "there is currently limited transparency into these HIDTA-funded surveillance programs, but ONDCP has commissioned an assessment into the privacy practices of these programs that should be released to the public." Wyden also requests a separate "analysis of automated license plate reader systems and practices" [1].

The letter lands three weeks after the October 1 ruling in United States v. Kyle, in which U.S. District Judge Sara Hill of the Northern District of Oklahoma called a single Flock search "a type of indiscriminate mass surveillance" and suppressed the evidence [2]. The structural argument is straightforward: when a federal grant program concentrates plate reads from local agencies into a federal database, the privacy bargain is moved from the city council to the White House, with no public review of the budget. Our coverage of the federal Flock ruling and the Ban Flock Act filing track the parallel federal response [15].

EFF Maps Two Years of Federal Data Consolidation in Three Waves

EFF's Adam Schwartz and F. Mario Trujillo published "Resisting the Menace of Federal Data Consolidation" on October 9, mapping three waves of federal data amalgamation: the Department of Government Efficiency (DOGE) created on January 20, 2025 and its "prompt access to all unclassified agency records" mandate, agency-to-agency sharing that routes benefits and tax data to ICE, and SAVE-Act voter-roll purges. The piece links the three waves together as a sustained attack on the 1974 Privacy Act framework [3][4].

The filing map is the heart of the piece. The lawsuits named include American Federation of Government Employees v. U.S. Office of Personnel Management, Centro de Trabajadores Unidos v. Scott Bessent, California v. HHS, League of Women Voters v. DHS, Common Cause v. U.S. Department of Justice, California v. Trump (with 24 states as plaintiffs), U.S. Postal Service v. California, and EPIC v. USCIS. EFF reports more than 60 million voter records run through SAVE with 21,000 flagged as potential noncitizens, that at least 48 states have been asked to hand over voter information, that at least 16 states have complied, and that the federal government has sued 30 states over voter data, with courts dismissing 25 of those suits [3].

The structural reading is the identifier layer. Federal departments route benefits (OPM, SSA, Treasury), tax (IRS), immigration (DHS-ICE), and voter data (DOJ, AAMVA, USCIS) through shared identifiers. EFF's prescription: strengthen the 1974 Privacy Act, pass the Fourth Amendment Is Not For Sale Act, and enact a federal consumer-privacy law. The site's ICE location-data IG probe coverage and the free-surveillance-tech pipeline piece are the data-broker end of the same build [4][16].

EFF's "No ID, No Internet" Brief Frames Age Verification as Exclusion Infrastructure

Jillian C. York and Sheila B. Lalwani published "When No ID Means No Internet: Age Verification and the Right to Access Information" on October 8. The piece argues mandatory age-verification rules are exclusion infrastructure rather than child-safety tools: roughly 850 million people globally do not have ID, "most of these individuals exist in primarily low and middle income countries in Sub-Saharan Africa and South Asia," and "women are particularly vulnerable and are 8% less likely than men to have an ID" [5].

The US-side numbers anchor the global frame. Roughly 15 million adult US citizens lack a driver's license, and a further 2.6 million lack any government photo ID. Australia's under-16 social media ban, in place since late 2025, is the running case the piece circles back to, and the UK Online Safety Act is the European parallel. EFF's framing: "Age verification laws provide quick tech solutions but overlook longstanding structural challenges and undermine the universality of the internet." The piece lands the same week as Denmark's CPR spill, the inverse failure mode: in Denmark the problem is that everyone is on a single national ID system; in the global age-verification frame, the problem is that the global internet is being gated on whether they are on one [5][11]. The site's age-verification as surveillance piece and the Doctorow frame carry the broader pattern [6][17].

FBI Seizes Seven Integrity Technology Group Domains Tied to Flax Typhoon

Jessica Lyons reported on October 8 in The Register that the FBI seized seven web domains tied to Integrity Technology Group and the Flax Typhoon botnet, in a joint action with the United States, UK, Australia, Canada, Japan, New Zealand, and Spain. FBI special agent Adam James's filings name a US power company in South Carolina as a scanned target, list five CVEs added to CISA's Known Exploited Vulnerabilities Catalog, and document a 260,000-device botnet "infecting devices from 2021 until the FBI stepped in." CISA published an advisory, AA26-281A, on the same day as the seizures [7][8].

The tradecraft is documented in the FBI filings. The actors "exploit vulnerabilities by using scanning tools, cross-site scripting attacks, and password spraying on Microsoft Exchange servers, while establishing persistence through VPN software and exfiltrating emails and credentials using scripts." The FBI identified a specific scanner the group used, named Microscan, and a phishing helper named FishHub: "based on my training and experience I believe the tool was named FishHub because it facilitated phishing activity." The filings add specific targets: a US power company in South Carolina, a multi-national Non-Governmental Organization, Japanese and Polish airports, and at least two Taiwanese critical-infrastructure companies in the natural gas and power sectors [7].

The five CVEs added to the catalog were CVE-2015-3306, CVE-2015-5477, CVE-2016-3081, CVE-2021-3199, and CVE-2023-22894. The Register notes this is the first time seven governments have jointly attributed the activity to a single threat actor, and the joint action follows a previous takedown of the "Raptor Train" botnet infrastructure run by Flax Typhoon. The site covers the parallel PRC hacking infrastructure in the FBI China FISMA coverage and the Volt Typhoon tracker [8][18].

Denmark's CPR Register Spilled More Records Than Denmark Has People

Jude Karabus reported on October 6 in The Register that an unauthorized party pulled roughly 8.8 million records from Denmark's Central Population Register (CPR) by abusing a private Danish firm's legitimate access. Denmark's population sits near 6 million; the register also holds deceased residents, people who moved abroad, and Greenland enrollees, and tops out around 11 million records. The CPR administration became aware of irregular activity in September and confirmed the breach scale on October 2, with the digitisation ministry issuing a public statement on the weekend of October 4 to 5 [11][12].

Denmark's civil-identification system runs on Section 38(1) of the Danish Civil Registration System Act, which restricts legitimate CPR access to companies, foundations, other legal entities, and individuals conducting business, and requires that "access concerns a defined group of people identified individually in advance." A private-sector partner is exactly the kind of entity that holds that access in normal course, which makes the spill a misuse case rather than a front-door hack. Cybersecurity specialist Jan Kaastrup told The Register: "We live in a digitalized society, and therefore we should have much better identification systems." Digitisation minister Christina Egelund said it was too soon to say whether the country would issue all-new CPR numbers [11].

Read the spill as the inverse failure mode of the EFF age-verification argument. EFF's brief argues the internet is being gated on whether users have a state ID; Denmark's spill shows what happens when everyone has a state ID and one authorized partner has read access to it. Roughly 55,000 Greenland residents also use CPR numbers for healthcare, tax services, and banking, which is how far a single national ID can carry across borders. The site covered the spill earlier this week, and the age-verification as surveillance piece is the parallel US-side piece on the same architectural problem [11][6].

404 Media Reports Police Can Defeat the iPhone's Automatic Reboot

Joseph Cox and Lorenzo Franceschi-Bicchierai covered on the 404 Media podcast published October 8 an underlying Franceschi-Bicchierai report on a leaked video in which forensic tooling defeats the iPhone's automatic inactivity-reboot, the post-reboot relock Apple designed to keep a seized phone in Apple's Before First Unlock (BFU) state. Cox framed the episode around police "getting around a very important iPhone security feature" [13][14].

The technical surface is the lock-state machine. Apple ships a setting that reloads an iPhone into Apple's Before First Unlock (BFU) state after a period of inactivity, on the logic that a long-disconnected phone in the After First Unlock (AFU) state is the more exploitable target. The leaked video, paired with reporting on commercial tools like GrayKey, shows investigators reconnecting before the timer fires and harvesting data anyway. A reader-level framing: the security feature assumed a phone would be off for days, not minutes; the forensic workflow assumes minutes, not days. The two assumptions no longer match [14].

This is the device-security story that connects to Lockdown Mode and to the West Virginia v. Apple CSAM case: the same Apple security stack that is being litigated in state court is also the stack law enforcement is now working around at the field level. The site's ICE Cellebrite and GrayKey contracts coverage and the Apple Signal-deleted-messages CVE coverage track the parallel device-security angles [19][20].

What to Watch This Week

MITRE's HIDTA review and Wyden's reply window. ONDCP's standard letter-response window runs the public pressure timeline. Watch whether the MITRE 2024 HIDTA privacy review lands on the public docket by October 16, and whether ONDCP publicly names which Hemisphere and ALPR questions the review covers [1].

The federal data consolidation docket. California v. Trump's 24-state posture, and the EPIC v. USCIS suit, are the leading cases. Watch for the next SCOTUS shadow-docket ruling on a data-sharing motion, and for new SAVE-Act voter-roll purge motions in remaining states [3].

The Danish CPR misuse case. The Register reported the breach was discovered through September activity and confirmed October 2. Watch for a Digitisation Ministry statement on whether CPR numbers will be reissued, and for the first Danish Data Protection Agency enforcement notice naming the access-misuse private partner [11].

Flax Typhoon disruption follow-on. The FBI's October 8 domain seizure is the public-facing action. Watch for the second indictment against Integrity Technology Group personnel, and for a US-CISA advisory on consumer-routers and the MS Exchange CVEs scanned by the Flax Typhoon toolkit [7][8].

The TP-Link multi-state case. Watch for any preliminary injunction motion, and for the first state-court ruling on whether consumer-protection law reaches a foreign-supply-chain deception claim. The Nebraska complaint is the public docket to watch [9].

Age-verification state tracker. EFF's 850-million global figure lands while a wave of US state-level age-verification bills are still moving. Watch for the next state to enact a major-platform age-verification mandate and the first court challenge under state privacy law [5][17].

Sources

  1. 404 Media, Jason Koebler: Following 404 Media Investigation, Senator Demands Info About White House's License Plate Surveillance Program (October 9, 2026). https://www.404media.co/following-404-media-investigation-senator-demands-info-about-white-houses-license-plate-surveillance-program/
  2. State of Surveillance: Federal Judge Rules Flock ALPR Search Unconstitutional (October 9, 2026). /news/flock-alpr-search-unconstitutional-federal-judge-2026
  3. EFF Deeplinks, Adam Schwartz and F. Mario Trujillo: Resisting the Menace of Federal Data Consolidation (October 9, 2026). https://www.eff.org/deeplinks/2026/10/resisting-menace-federal-data-consolidation
  4. State of Surveillance: ICE Location Data IG Probe: 70 Lawmakers Demand Answers (2026). /news/ice-location-data-ig-probe-70-lawmakers-illegal-purchases-2026
  5. EFF Deeplinks, Jillian C. York and Sheila B. Lalwani: When No ID Means No Internet: Age Verification and the Right to Access Information (October 8, 2026). https://www.eff.org/deeplinks/2026/10/when-no-id-means-no-internet-age-verification-and-right-access-information
  6. State of Surveillance: Age Verification as Surveillance: The ID System Behind Every Check (2026). /news/age-verification-surveillance-infrastructure-id-system-2026
  7. The Register, Jessica Lyons: US disrupts Chinese hacking tools as 7 govts warn of PRC spies stealing sensitive data worldwide (October 8, 2026). https://www.theregister.com/security/2026/10/08/us-disrupts-chinese-hacking-tools-as-7-govts-warn-of-prc-spies-stealing-sensitive-data-worldwide/5302107
  8. State of Surveillance: FBI China Hack Major Incident FISMA (2026). /news/fbi-china-hack-major-incident-fisma-surveillance-2026
  9. The Register, Connor Jones: US states sue popular kitmaker TP-Link over China risks (October 7, 2026). https://www.theregister.com/security/2026/10/07/us-states-sue-popular-kitmaker-tp-link-over-china-risks/5301653
  10. State of Surveillance: Texas AG Sues TP-Link Over CCP Ties (February 2026). /news/texas-ag-paxton-ccp-lawsuits-temu-shein-tp-link-surveillance-2026
  11. The Register, Jude Karabus: Denmark's ID register spills more people's details than the country has residents (October 6, 2026). https://www.theregister.com/security/2026/10/06/denmarks-id-register-spills-more-peoples-details-than-the-country-has-residents/5301307
  12. State of Surveillance: Weekly Surveillance Roundup, October 5 to 11, 2026 (October 11, 2026). /news/2026-10-11-weekly-surveillance-roundup
  13. 404 Media, Joseph Cox (host): Podcast: Leak Show Cops Can Break into Locked iPhones (October 8, 2026). https://www.404media.co/podcast-leak-show-cops-can-break-into-locked-iphones/
  14. 404 Media, Lorenzo Franceschi-Bicchierai: Cops Can Bypass iPhone's Automatic Reboot to Get Into Locked Phones, Leaked Video Claims (October 2026). https://www.404media.co/cops-can-bypass-iphones-automatic-reboot/
  15. State of Surveillance: Ban Flock Act: Sanders, Ocasio-Cortez, Merkley Introduce Federal ALPR Ban (October 7, 2026). /news/ban-flock-act-sanders-ocasio-cortez-merkley-alpr-federal-2026
  16. State of Surveillance: Free Surveillance Tech Pipeline: How Police Hand Data to ICE (2026). /news/free-surveillance-tech-pipeline-police-ice-data-2026
  17. State of Surveillance: Cory Doctorow on Age Verification as Mass Surveillance (June 25, 2026). /news/cory-doctorow-age-verification-is-mass-surveillance-2026
  18. State of Surveillance: Volt Typhoon 2026 Tracker. /articles/government/volt-typhoon-2026-tracker
  19. State of Surveillance: ICE Cellebrite and GrayKey Phone Hacking Contracts. /news/ice-cellebrite-graykey-phone-hacking-contracts
  20. State of Surveillance: Apple iPhone Signal Deleted Messages FBI Notification Bug CVE-2026-28950 (2026). /news/apple-iphone-signal-deleted-messages-fbi-notification-bug-cve-2026-28950