Today in Surveillance:
- A 96 GB infostealer database sat unprotected for nearly a month. Cybersecurity researcher Jeremiah Fowler found 149,404,754 stolen usernames and passwords in a public database that included 48 million Gmail accounts, 17 million Facebook logins, 6.5 million Instagram credentials, 4 million Yahoo Mail accounts, and 3.4 million Netflix logins [1][2]. The hosting provider took nearly a month to pull it offline, and the database was still growing while Fowler watched it.
- ShinyHunters ran the same Okta voice-phishing playbook against two US companies. The group dumped a 6.1 GB archive of more than 12 million CarGurus records after the auto marketplace refused to pay, then published 2.5 GB of data on 967,000 Figure customers after the non-bank HELOC lender did the same [3][4][5]. Silent Push traced both attacks to a broader campaign against more than 100 Okta-using companies.
- A 42-state bipartisan AG coalition watched its AI chatbot deadline pass with most companies silent. On December 10, 2025, 42 attorneys general sent a 13-page letter to 13 AI companies giving them 37 days to fix chatbot safety. The January 16 deadline passed with most of the recipients declining to respond publicly. The Trump administration's Executive Order 14365 preempts state AI rules but carves out child safety, the exact area the AG letter targets [6][7][8].
- LastPass disclosed a master-password phishing campaign timed to the MLK weekend. Attackers sent emails warning of "24-hour" vault backups; the link led through an AWS redirect to mail-lastpass[.]com. LastPass warned that it never asks for a master password by email [9][10][11].
- Mullvad VPN published a 4,000-word State Mass Surveillance primer. The June 25, 2026 entry walks FISA 702, PRISM, XKeyscore, the NSA Utah data center, GCHQ Tempora, Chat Control, Pegasus, Russia Safe City, Iran's SIAM, and China's Police Cloud side by side. The structural point: democratic and authoritarian states are converging on the same mass-surveillance model [12][13].
149 Million Stolen Passwords Sat in an Unprotected Database for a Month
Jeremiah Fowler, the cybersecurity researcher who has made a career out of finding exposed databases, opened his browser one day in February and found 149,404,754 stolen usernames and passwords sitting in a 96 GB server with no password, no encryption, and no access controls [1]. The trove was not a breach at any single company. It was a collection server for infostealer malware that had been quietly harvesting credentials from infected devices and uploading them in real time. Every entry represented a real person whose computer or phone had been compromised [2].
Fowler broke the count down. The biggest slices: 48 million Gmail accounts, 17 million Facebook logins, 6.5 million Instagram credentials, 4 million Yahoo Mail accounts, 3.4 million Netflix logins, 1.5 million Outlook photos, 900,000 iCloud Mail accounts, and 780,000 TikTok accounts. The same database also held 420,000 Binance credentials and login records for banks, healthcare systems, government portals, and corporate VPNs [1]. Each entry included the username, the password in plaintext, and the direct login URL for the site, the full package for credential reuse.
The structural detail is the response time. Fowler sent a responsible-disclosure email to the hosting provider. It took nearly a month to pull the database [1]. During that month anyone could have copied it: security researchers, criminals, foreign intelligence services. And while he was looking at it, the database kept growing, which meant the malware network feeding it was still active, still infecting machines, still uploading fresh credentials. This is the same malware ecosystem behind the 16 billion credential compilation that surfaced in January [2].
For users the operational read is direct. If your browser has been saving passwords since 2019, your credentials may already be in this database. Stop relying on browser-stored passwords; switch to a dedicated manager (Bitwarden, 1Password); enable two-factor authentication on email, banking, and crypto accounts first; and check haveibeenpwned.com for the addresses you actually use [2].
ShinyHunters' Okta Voice-Phishing Spree Hit CarGurus and Figure on the Same Week
CarGurus is the auto marketplace where shoppers compare car-shopping fees and run pre-qualification forms. Figure Technology Solutions is the largest non-bank HELOC lender in America, with more than $17 billion in home equity loans originated. ShinyHunters stole from both using the same trick: a phone call [3][4][5].
CarGurus lost more than 12 million email addresses plus auto-finance pre-qualification applications, dealer account data, names, phone numbers, physical addresses, and IP addresses, in a 6.1 GB archive published on February 20, 2026 after the company declined a ransom demand [3]. Have I Been Pwned added the breach on February 22. The Register quoted ShinyHunters' threat: "This is a final warning to reach out by 20 Feb 2026 before we leak along with several annoying (digital) problems that'll come your way" [4]. The pattern is familiar: ShinyHunters called an employee pretending to be IT, walked them through an Okta single sign-on approval, and walked out the front door with everything.
Figure confirmed the same approach. An employee was tricked into handing over credentials in January 2026, and the company disclosed the breach on February 13 after TechCrunch confronted it with evidence of the stolen data circulating online [5]. The haul: data on 967,200 people who had applied for home equity loans, including full names, email addresses, phone numbers, physical home addresses, and dates of birth. ShinyHunters published 2.5 GB of data after Figure refused to pay [14].
Researchers at Silent Push traced both attacks to a broader ShinyHunters campaign targeting more than 100 companies that use Okta single sign-on [15]. A ShinyHunters member told The Register that Figure was among the Okta-targeted companies. Betterment (1.4 million users), Crunchbase, and SoundCloud all confirmed similar voice-phishing attacks in the same window [5]. The playbook is structural: call, convince, capture the SSO prompt, exfiltrate. Single sign-on is the new single point of failure.
42 Attorneys General Gave 13 AI Companies 37 Days. The Deadline Passed.
On December 10, 2025, a bipartisan coalition of 42 state attorneys general, led by Pennsylvania Republican Dave Sunday, New Jersey Democrat Matthew Platkin, West Virginia Republican JB McCuskey, and Massachusetts Democrat Andrea Joy Campbell, fired off a 13-page letter to 13 AI companies: Anthropic, Apple, Chai AI, Character Technologies, Google, Meta, Nomi AI, Perplexity AI, Replika (Luka), OpenAI, Microsoft, and xAI [6][7]. The letter documented multiple deaths linked to AI chatbot interactions and laid out 16 specific demands, with a January 16, 2026 deadline [7].
The demands were concrete. Mandatory pre-deployment testing for sycophantic and delusional outputs. Product recalls for chatbots that generate dangerous responses. Independent audits whose findings auditors can publish without company approval. Named individual executives personally responsible for safety outcomes, not committees. Decoupling executive compensation from engagement metrics. Permanent warnings that AI can be wrong. Child-specific protections against grooming, self-harm, and secrecy-from-parents content. Protocols for flagging dangerous interactions to law enforcement and mental-health professionals [7].
January 16 came and went. OpenAI said it "shares the concerns" but made no firm commitments. Perplexity said it was already working on sycophancy issues. Microsoft, Google, Meta, Apple, Anthropic, and Character.AI issued no public comment; Reuters reported Microsoft, Google, and Meta explicitly declined to respond publicly [7]. A week later the coalition escalated with a separate letter to xAI over Grok's ability to generate nonconsensual intimate imagery. Delaware AG Kathy Jennings framed it as "the ability to create nonconsensual intimate images appears to be a feature, not a bug" [8].
The federal collision is the complicating factor. The same week the AGs sent their letter, the White House signed Executive Order 14365, "Ensuring a National Policy Framework for Artificial Intelligence," aimed at preempting state AI laws [6]. Attorney General Pam Bondi set up a DOJ AI Litigation Taskforce to challenge state laws the administration considers inconsistent with its pro-innovation stance [16]. But the executive order carves out child safety protections from preemption. The 42-AG letter targets child safety. Companies that ignore the AGs in reliance on federal preemption may find themselves in state consumer-protection and criminal-enforcement territory untouched by the order.
LastPass Phishing Stole Master Passwords Over the MLK Weekend
LastPass disclosed on January 20, 2026 that attackers were sending emails that warned LastPass users they had to "backup your vault" within 24 hours or risk losing access [9]. Click the link and the warnings redirect through an AWS-hosted page (group-content-gen2.s3.eu-west-3.amazonaws.com) to a fake login at mail-lastpass[.]com. Enter the master password and the attackers get the keys to every account in the vault [10][11]. The real LastPass domain is lastpass.com, no hyphens, no prefixes.
LastPass's team flagged the campaign on January 20, the MLK Day weekend [9]. The holiday timing is the tell. Skeleton IT crews, slower user-side reporting, more people checking personal email from home without corporate filters. The 24-hour deadline adds the urgency that makes them click. LastPass's published advisory is unambiguous: "Please remember that no one at LastPass will ever ask for your master password" [9].
The structural point is what a master password is worth. One password unlocks email, banking, crypto, and any account that can reset any other account. The phishing template is "vishing plus an urgent maintenance window plus a real-looking domain," the same skeleton that worked against the CarGurus and Figure employees. Password managers are an attractive target because the prize from one credential is total account takeover [11]. If you clicked a link in one of these emails and entered a master password, change the master password first, then rotate every stored password, then enable an authenticator-app two-factor authentication on the LastPass account itself.
Mullvad's 4,000-Word Primer Maps Global Mass Surveillance End to End
On June 25, 2026, Mullvad VPN AB in Gothenburg published the longest single piece in its Why Privacy Matters editorial series: a 4,000-word State Mass Surveillance primer that walks the United States, Europe, and the authoritarian world side by side [12]. The U.S. section covers FISA Section 702, PRISM, XKeyscore, the NSA Utah data center, and the data-broker workaround (the Wyden letter and the WSJ/Wired stories on U.S. spy agencies buying Americans' location data) [17][18]. The European section walks UK Tempora, the Five/Fourteen Eyes alliances, the EU Chat Control proposal, France's AI video surveillance, and Pegasus spyware [13]. The authoritarian section covers Russia's SORM and Moscow Safe City, Iran's SIAM, and China's Great Firewall, Police Cloud, and the public-opinion analyst corps.
The structural argument is convergence. The same model is appearing in democracies and authoritarian states: bulk collection, identity-verification infrastructure, programmatic filtering of speech, and predictive policing. The consumer-facing identity-verification infrastructure tied to age checks and account verification is one slice of the same pattern. The primer cites 1984-era language from then-CIA CTO Ira "Gus" Hunt ("collect it all") as a North Star for the entire apparatus [19]. The article also notes that two European courts have ruled parts of this same apparatus illegal. The European Court of Justice struck down bulk data retention in 2020 [20], and a UK court ruled in 2021 that GCHQ's mass data sharing breached privacy rights [21].
The reason it sits on this briefing is the framing. The CarGurus and Figure breaches are about voice phishing, an attack vector. The LastPass phishing is about credential phishing, an attack vector. The 149-million-password database is about infostealer recycling, an attack vector. Underneath all of them, the Mullvad primer argues, sits a mass-surveillance infrastructure that decides what is collected, who can reach it, and what can be done with it. The phone call that walked out the front door at CarGurus depended on the same per-employee access that depends on the same identity layer that depends on the same data-broker pipeline.
What to Watch This Week
ShinyHunters' next Okta target. Silent Track traced the operation to more than 100 Okta-using companies. Watch whether ShinyHunters publishes a third major dump this month and which sector it lands in [15].
The 42-AG escalation against xAI. The coalition's January 23 letter to xAI is the first concrete enforcement step. Watch for subpoenas, state lawsuits under consumer-protection statutes, and coordinated investigations following the May 2026 Take It Down Act effective date [8].
The infostealer database fallout. Fowler's 149-million-record database was one of many infostealer collection servers. Watch for downstream credential-stuffing waves against the 48 million Gmail accounts and 17 million Facebook logins it exposed [1].
EU Chat Control and FISA 702 reform. Mullvad's primer highlights both as the active legislative pressure points. Watch whether Chat Control moves through the Council and whether Wyden-Lee-style warrant requirements get attached to any 702 reauthorization [12].
Sources
- Fox News: 149 million passwords exposed in massive credential leak (February 2026). https://www.foxnews.com/tech/149-million-passwords-exposed-massive-credential-leak
- State of Surveillance: 149 million passwords sat in an unprotected database anyone could grab (February 9, 2026). /news/149-million-passwords-exposed-infostealer-database-2026
- Cyber Insider: CarGurus data breach by ShinyHunters exposed 12.5 million accounts (February 2026). https://cyberinsider.com/cargurus-data-breach-by-shinyhunters-exposed-12-5-million-accounts/
- The Register: ShinyHunters claims it drove off with 1.7M CarGurus records (February 18, 2026). https://www.theregister.com/2026/02/18/shinyhunters_cargurus_breach/
- Cyber Insider: Fintech lender Figure hit by data breach impacting 967k accounts (February 2026). https://cyberinsider.com/fintech-lender-figure-hit-by-data-breach-impacting-967k-accounts/
- Pennsylvania AG: Coalition of 42 attorneys general demands AI safeguards (December 2025). https://www.attorneygeneral.gov/taking-action/ag-sunday-leads-coalition-of-42-attorneys-general-in-letter-to-a-i-software-companies-demanding-safeguards-to-protect-vulnerable-residents-from-harmful-interactions-with-bots/
- TechCrunch: State attorneys general warn Microsoft, OpenAI, Google to fix "delusional outputs" (December 2025). https://techcrunch.com/2025/12/10/state-attorneys-general-warn-microsoft-openai-google-and-other-ai-giants-to-fix-delusional-outputs/
- Delaware AG: Demand action from xAI over Grok's nonconsensual sexual content (January 2026). https://news.delaware.gov/2026/01/23/ag-jennings-colleagues-demand-action-from-xai-over-groks-creation-of-nonconsensual-sexual-content/
- LastPass Blog: New phishing campaign targeting LastPass customers (January 2026). https://blog.lastpass.com/posts/new-phishing-campaign-targeting-lastpass-customers
- The Hacker News: LastPass warns of fake maintenance messages targeting users' master passwords (January 2026). https://thehackernews.com/2026/01/lastpass-warns-of-fake-maintenance.html
- The Register: Don't click the LastPass "create backup" link (January 2026). https://www.theregister.com/2026/01/21/lastpass_backup_phishing_campaign
- Mullvad VPN AB: State mass surveillance, Why Privacy Matters editorial series (June 25, 2026). https://mullvad.net/en/why-privacy-matters/state-mass-surveillance
- Mullvad VPN AB: Chat Control position page (2026). https://mullvad.net/chatcontrol
- The Register: ShinyHunters claims Okta customer breaches, leaks data (January 2026). https://www.theregister.com/2026/01/23/shinyhunters_claims_okta_customer_breaches/
- CyberScoop: A new wave of "vishing" attacks is breaking into SSO accounts in real time (January 2026). https://cyberscoop.com/shinyhunters-voice-phishing-sso-okta-mfa-bypass-data-theft/
- CBS News: DOJ creates task force to challenge state AI regulations (December 2025). https://www.cbsnews.com/news/doj-creates-task-force-to-challenge-state-ai-regulations/
- Senator Ron Wyden: Wyden releases documents confirming the NSA buys Americans' internet browsing records (January 25, 2024). https://www.wyden.senate.gov/news/press-releases/wyden-releases-documents-confirming-the-nsa-buys-americans-internet-browsing-records-calls-on-intelligence-community-to-stop-buying-us-data-obtained-unlawfully-from-data-brokers-violating-recent-ftc-order
- Wall Street Journal, Byron Tau: U.S. spy agencies know our secrets. They bought them (February 27, 2024). https://www.wsj.com/politics/national-security/u-s-spy-agencies-know-our-secrets-they-bought-them-791e243f
- Wired, James Bamford: The NSA is building the country's biggest spy center (March 15, 2012). https://www.wired.com/2012/03/ff-nsadatacenter/
- Politico, Laurens Cerulus: Top EU court strikes down bulk data retention (October 6, 2020). https://www.politico.eu/article/data-retention-europe-mass-surveillance/
- The Guardian, Owen Bowcott: GCHQ's mass data sharing violated right to privacy, court rules (May 25, 2021). https://www.theguardian.com/uk-news/2021/may/25/gchqs-mass-data-sharing-violated-right-to-privacy-court-rules