Today in Surveillance:
- Federal agencies queried San Francisco PD’s Flock cameras over 1.6 million times in seven months. A class action lawsuit filed February 26, 2026 in San Francisco Superior Court alleges Flock Safety violated California’s ALPR Privacy Act by letting ICE, CBP, FBI, ATF, DEA, and USPS reach into California plate-reader data the state law says must stay in California [1][2][4].
- Oxnard suspended every Flock camera on February 27, 2026. A “vendor-based issue” left a “nationwide query” feature on despite a “California only” setting. Ventura County’s audit found 364,000 unauthorized accesses between February and March 2025; Flock could not explain who reactivated the feature [3][5].
- DocketWise disclosed a five-month-old breach exposing 116,666 immigration clients. Attackers used valid credentials to clone third-party partner repositories containing passport numbers, Social Security numbers, medical records, and login credentials. Notifications went out April 3, 2026 [6][7][8].
- Google handed a Cornell Ph.D. student’s bank and credit-card numbers to ICE. The EFF filed complaints with the California and New York attorneys general on April 14, 2026, alleging Google broke its decade-old promise to notify users before handing data to law enforcement [9][10][11].
- The FTC banned Kochava from selling sensitive location data and fined Cox Media Group $930,000. The Kochava settlement, finalized May 4, 2026, is the FTC’s sixth location-data enforcement action in 18 months [12][13].
- The Five Eyes alliance issued a rare joint warning on June 3 and 4, 2026. The MI5-led advisory warned that Chinese military intelligence is running industrial-scale spy recruitment on LinkedIn, Indeed, Upwork, and Craigslist [14][15][16].
Federal Agencies Queried San Francisco PD’s Flock Cameras 1.6 Million Times in Seven Months
The biggest surveillance story of the week landed in court on February 26, 2026, when Oakland-based Gibbs Mura filed a class action against Flock Safety. The complaint lays out the volume: out-of-state agencies queried San Francisco Police Department’s Flock database over 1.6 million times in seven months, in alleged violation of California’s ALPR Privacy Act [1][4]. The searches are documented in audit logs the city was forced to disclose after a separate public-records fight. Plaintiffs seek the statutory minimum of $2,500 per violation under California Civil Code § 1798.90.54, plus punitive damages for willful conduct [1].
SFist obtained the search-reason strings from the audit logs. The federal agencies named: FBI, ATF, ICE, CBP, DEA, USPS, GSA OIG, and the VA Police at Loma Linda Healthcare System. Some San Jose PD logs listed nothing but “CBP” or “ICE” in the search-reason field [1][4]. CBS Los Angeles’ audit-log review of Ventura County found 364,000 unauthorized accesses between February and March 2025. The Sheriff’s Office confirmed the “National Lookup” feature had been disabled in June 2023 to comply with California law, and “No one from our agency activated the national lookup feature” [3]. Flock told CBSLA it could not pinpoint whether a Flock employee, a sheriff’s deputy, or a system bug was responsible, citing “technical logging limitations” [3].
Oxnard Police Chief Jason Benites suspended every Flock camera in his city on February 27, 2026, after the same audit pattern surfaced there. “Proper guardrails must not only be in place, but they must work reliably,” Benites told CBSLA [3][5]. Edhat reported the cameras will stay dark until Oxnard is “fully confident that our data is secure.” The California Highway Patrol had already warned Flock in November 2025 that sharing data with federal agencies violated its contract. Mountain View, Richmond, and Oakland have moved to block or end their Flock contracts. The class action tracks the data flow that the contract was supposed to stop. Our article walks the numbers, the agencies themselves, and the full audit timeline [17].
DocketWise Sat on a 116,666-Record Immigration Breach for Five Months
The DocketWise breach disclosure, finalized April 3, 2026, exposed a different slice of the same enforcement stack. DocketWise is the cloud case-management platform thousands of US immigration law firms use to file cases, store client documents, and run their practices. The breach notification says an unauthorized actor used valid credentials to clone third-party partner repositories that were part of a data-migration pipeline [6][7]. The cloned data included full names, Social Security numbers, dates of birth, passport numbers, driver’s license numbers, government identification numbers, financial account numbers, payment card numbers, health insurance policy numbers, medical condition and treatment information, and login credentials [7][8].
The disclosure window is the structural failure. DocketWise discovered the intrusion in October 2025 and did not start sending notification letters until April 3, 2026, a five-month gap during which affected individuals had no chance to freeze credit, file an IRS Identity Protection PIN, or warn their attorneys [8]. Schubert Jonckheer and Kolbe, Shamis and Gentile, and Edelson Lechtzin LLP have opened class action investigations [19]. For a population whose legal status, home address, and family structure is on file with their attorney, a five-month lag between breach and notification is more than a privacy inconvenience. Our full write-up walks the timeline and the litigation [20].
Google Gave ICE a Cornell Student’s Bank Data and Broke Its Notification Promise
Amandla Thomas-Johnson, a British and Trinidadian dual citizen and a Cornell Ph.D. candidate, attended a pro-Palestine protest at a campus job fair for about five minutes in September 2024 [9]. Within hours of Cornell revoking his student visa in early 2025, ICE sent Google an administrative subpoena. Google handed over usernames, physical addresses, IP addresses, phone numbers, an itemized list of every Google service Thomas-Johnson used, his credit card numbers, and his bank account numbers [10]. The same subpoena asked Google not to notify him. Google complied, sending the notification from a no-reply email address on the same day it transferred the data [11]. By the time he saw the email, his data was already in ICE’s hands [10][11].
Google’s transparency policy for years said it would notify users before handing data to law enforcement, with narrow exceptions. None of those exceptions applied. ICE included a non-binding notation on the subpoena asking Google not to notify. No judge signed it. The EFF filed complaints with the California and New York attorneys general on April 14, 2026, alleging deceptive trade practices. Google received 28,622 subpoenas in the first half of 2025 alone [18]. The case is the producer-side version of the Flock data-sharing problem: a private intermediary decides what is enforceable when the government writes “please don’t tell them.” Our article lays out the subpoena, the EFF complaint, and the bigger pattern [21].
The FTC Banned Kochava and Fined Cox Media Group. Six Down, A Few Thousand to Go.
The FTC finalized the Kochava settlement on May 4, 2026, capping a lawsuit filed in August 2022, two months after Dobbs. The complaint alleged Kochava sold geolocation data from hundreds of millions of mobile devices that “can identify a mobile device that visited a women’s reproductive health clinic and trace that mobile device to a single family residence” [12][22]. The settlement bans Kochava and its subsidiary Collective Data Solutions from selling sensitive location data without “affirmative express consent,” requires a sensitive-location classification program, mandates supplier vetting, and gives consumers the right to request the names of every business their location data was sold to [12]. The settlement carries no monetary penalty.
Kochava is the FTC’s sixth location-data enforcement action since January 2024, joining X-Mode Social and Outlogic, InMarket Media, Gravy Analytics and Venntel, and Mobilewalla [13][23]. The Mobilewalla case set a separate first: the FTC ruled that harvesting location data from real-time bidding auction requests, even losing bids, is an unfair practice [13]. On the adjacent fraud track, the FTC announced a $930,000 settlement with Cox Media Group, MindSift, and 1010 Digital Works on May 21, 2026 for selling a fake “Active Listening” AI service that never listened to anything; CMG paid $880,000 and the two smaller firms paid $25,000 each [24]. The Data and Marketing Association estimated over 4,000 data broker companies operating in the US as of 2024; Vermont’s registry lists over 500 [25]. The FTC is building precedent at a pace of about one case every three months, against an industry that size. Our full write-up tracks the enforcement timeline and what each case changed [26].
Five Eyes Warned: Chinese Military Intelligence Is in Your LinkedIn Inbox
On June 3 and 4, 2026, the Five Eyes intelligence alliance published an unusual joint advisory led by Britain’s MI5. The advisory warned that Chinese military intelligence services are running a coordinated recruitment campaign across LinkedIn, Indeed, Upwork, and Craigslist [14][15]. The advisory lays out the tradecraft: operatives pose as headhunters, screen applicants by access to sensitive information, run virtual interviews that probe government contacts, then ask recruits to write a “trial report” on a China-related topic. Conversations move to encrypted messaging apps, and payments arrive via PayPal, Zelle, Wise, Western Union, or cryptocurrency [15]. The statement: “China’s military intelligence services ultimately seek to acquire privileged military, political and economic intelligence that can provide China with a strategic and tactical advantage” [16].
MI5’s 2021 estimate was that approximately 10,000 Britons had been targeted on LinkedIn over the previous five years, a figure the agency called “conservative” [15]. The track record is documented. Former CIA officer Kevin Mallory, $230,000 in debt, was recruited through a LinkedIn message in 2017 and is serving 20 years under the Espionage Act [27]. Singaporean national Dickson Yeo pled guilty in July 2020 to acting as an illegal agent of Chinese intelligence after using LinkedIn to identify and approach US government employees, then set up a fake consulting company to collect reports [28]. The advisory’s structural point: LinkedIn lowered the marginal cost of a recruitment pitch to zero, so the targeting widened from senior officials to contractors, IT admins, and academics. The user-side mitigation is profile hygiene: drop the clearance references, audit your connections, and report suspected approaches to your agency’s counterintelligence unit. Our full walkthrough of the playbook, the tradecraft stages, and the operational security steps is on the site [29].
What to Watch This Week
The Flock data-sharing case in court. Watch whether the San Francisco Superior Court class action advances past motion to dismiss, and whether the $2,500 per violation minimum damages stick. Oxnard’s February 27 camera suspension, Mountain View’s contract vote, and the November 2025 CHP letter all sit in the case record. Federal agencies have not been named as defendants, so the discovery fight will turn on the Flock audit logs [1][3][4].
The EFF complaint against Google. The April 14, 2026 filings with the California and New York attorneys general could produce a public investigation. With 28,622 subpoenas in the first half of 2025, the exposure adds up fast if the notification promise is found to be deceptive in more than one case [11].
DocketWise litigation. Four firms have opened class action investigations, and the five-month notification delay is the most concrete legal hook. Watch for a consolidated complaint in the Northern District of California or the Central District of California and for any motion to dismiss that turns on the state-law notification standards [8][19].
The FTC’s next data broker case. Six down, several thousand to go. Watch whether the SECURE Data Act moves, and whether industry groups succeed in challenging the FTC’s data-broker jurisdiction in court, which would undermine the entire enforcement strategy [12][25].
Five Eyes follow-through. Watch whether MI5, the FBI, and the other agencies publish platform-specific indicators of compromise from the LinkedIn recruitment campaign, and whether the platforms respond with bulk-account removals or just continued removals on a case-by-case basis [14][15].
Sources
- Gibbs Mura: Flock Safety License Plate Reader Cameras Lawsuit (February 26, 2026). https://www.classlawgroup.com/flock-safety-license-plate-reader-cameras-lawsuit
- KTVU: Class action lawsuit alleges Flock license plate readers violate CA law (February 27, 2026). https://www.ktvu.com/news/class-action-lawsuit-alleges-flock-license-plate-readers-violate-ca-law-privacy-residents
- CBS Los Angeles: Flock license plate readers shared data with out-of-state, federal agencies (February 2026). https://www.cbsnews.com/losangeles/news/flock-license-plate-readers-shared-data-with-out-of-state-federal-agencies/
- SFist: Lawsuit Says SFPD’s Flock Cameras Were Accessed by Federal Agencies 1.6 Million Times (February 28, 2026). https://sfist.com/2026/02/28/lawsuit-says-flock-allowed-out-of-state-agencies-access-to-sfpd-database-1-6-million-times/
- Edhat: Oxnard police suspend Flock license-plate readers (February 2026). https://www.edhat.com/ventura/news/oxnard-police-suspend-flock-license-plate-readers-ventura-agencies-tighten-controls-after-out-of-state-access/
- GBlock: DocketWise Breach Exposed 116,000 Immigration Clients’ Most Sensitive Data (2026). https://www.gblock.app/articles/docketwise-immigration-data-breach
- ClaimDepot: DocketWise Data Breach Affects 116k People, Exposing SSNs (2026). https://www.claimdepot.com/data-breach/docketwise-2026
- PR Newswire: PRIVACY ALERT: DocketWise Under Investigation for Data Breach of Over 116,000 Records (April 3, 2026). https://www.prnewswire.com/news-releases/privacy-alert-docketwise-under-investigation-for-data-breach-of-over-116-000-records-302737614.html
- The Intercept: Google Fulfilled ICE Subpoena Demanding Student Journalist’s Bank and Credit Card Numbers (February 10, 2026). https://theintercept.com/2026/02/10/google-ice-subpoena-student-journalist/
- TechCrunch: Google sent personal and financial information of student journalist to ICE (February 10, 2026). https://techcrunch.com/2026/02/10/google-sent-personal-and-financial-information-of-student-journalist-to-ice/
- EFF: Google Broke Its Promise to Me. Now ICE Has My Data. (April 2026). https://www.eff.org/deeplinks/2026/04/google-broke-its-promise-me-now-ice-has-my-data
- FTC: FTC to Ban Kochava and Subsidiary from Selling Sensitive Location Data (May 2026). https://www.ftc.gov/news-events/news/press-releases/2026/05/ftc-ban-kochava-subsidiary-selling-sensitive-location-data-settle-charges-they-sold-location-data
- FTC: FTC Takes Action Against Mobilewalla for Collecting and Selling Sensitive Location Data (December 2024). https://www.ftc.gov/news-events/news/press-releases/2024/12/ftc-takes-action-against-mobilewalla-collecting-and-selling-sensitive-location-data
- Bloomberg: US, Five Eyes Warn of Chinese Spies Using LinkedIn for Recruitment (June 3, 2026). https://www.bloomberg.com/news/articles/2026-06-03/us-and-five-eyes-allies-warn-of-linkedin-china-spying-threat
- The Register: Five Eyes: Watch out for odd LinkedIn connection requests, China’s back on the hunt for state secrets (June 4, 2026). https://www.theregister.com/security/2026/06/04/five-eyes-china-expanding-state-secret-recruitment-campaign/5250978
- SCMP: US and Five Eyes allies warn of LinkedIn China spying threat (June 2026). https://www.scmp.com/news/world/united-states-canada/article/3355885/us-and-five-eyes-allies-warn-linkedin-china-spying-threat
- State of Surveillance: Class Action: Flock Shared California Plate Data With Feds (March 17, 2026). /news/flock-safety-class-action-lawsuit-california-federal-data-sharing-2026
- CyberInsider: EFF Urges State Probe into Google Over Undisclosed Data Sharing with ICE (April 2026). https://cyberinsider.com/eff-urges-state-probe-into-google-over-undisclosed-data-sharing-with-ice/
- Schubert Jonckheer and Kolbe: DocketWise Under Investigation for Data Breach (2026). https://www.classactionlawyers.com/blog/docketwise
- State of Surveillance: DocketWise Breach Exposes 116,000 Immigration Clients (April 10, 2026). /news/docketwise-immigration-data-breach-116000-records-2026
- State of Surveillance: Google Broke Its 10-Year Privacy Promise. Now ICE Has His Bank Data. (May 31, 2026). /news/google-broke-privacy-promise-ice-data-sharing-eff-2026
- CNN: FTC sues data broker Kochava for selling location information that could unmask abortion-seekers (August 2022). https://www.cnn.com/2022/08/29/tech/ftc-kochava-abortion-suit/index.html
- FTC: FTC Order Prohibits Data Broker X-Mode Social and Outlogic from Selling Sensitive Location Data (January 2024). https://www.ftc.gov/news-events/news/press-releases/2024/01/ftc-order-prohibits-data-broker-x-mode-social-and-outlogic-selling-sensitive-location-data
- FTC: FTC to Require Cox Media Group, Two Other Firms to Pay Nearly $1 Million (May 2026). https://www.ftc.gov/news-events/news/press-releases/2026/05/ftc-require-cox-media-group-two-other-firms-pay-nearly-1-million
- WilmerHale: FTC Continues to Bring Enforcement Actions Against Data Brokers (December 2024). https://www.wilmerhale.com/en/insights/client-alerts/20241217-ftc-continues-to-bring-enforcement-actions-against-data-brokers
- State of Surveillance: The FTC Is Finally Going After Companies That Track Your Every Move (May 28, 2026). /news/ftc-kochava-location-data-ban-cmg-enforcement-wave-2026
- NBC News: How a $230,000 debt and a LinkedIn message led an ex-CIA officer to spy for China (2026). https://www.nbcnews.com/politics/national-security/how-230-000-debt-linkedin-message-led-ex-cia-officer-n990691
- The Quint: How a Chinese Agent Weaponised LinkedIn to Steal Sensitive US Information (2026). https://www.thequint.com/tech-and-auto/how-chinese-agent-dickson-yeo-weaponised-linkedin-to-steal-united-states-information
- State of Surveillance: Five Eyes Issues Rare Joint Warning (June 5, 2026). /news/five-eyes-linkedin-chinese-spy-recruitment-warning-2026