Today in Surveillance:
- ShinyHunters listed Instructure on its Tor extortion site with claims of 275 million student and educator records and 3.65 terabytes of data. The Canvas LMS operator confirmed the breach on May 1, 2026, and named names, email addresses, student IDs, and private messages as confirmed exposures. ShinyHunters also says the Salesforce instance was compromised, the same playbook that hit Bumble, Crunchyroll, Wynn, and Kemper [1][2][3].
- Everest ransomware published 108 GB of Liberty Mutual insurance files on May 4, 2026. The dump contains 52,429 files across 14,979 folders including policyholder names, addresses, and policy numbers. Liberty Mutual calls it a third-party vendor incident and has not started customer notifications [4][5].
- West Virginia Attorney General JB McCuskey filed the first state lawsuit against Apple over iCloud child-safety detection on February 19, 2026. The complaint cites Apple's 2023 CSAM reports to NCMEC at 267, against Google's 1.47 million and Meta's 30.6 million, and frames Apple's encryption expansion as the enabler [7][8][9].
- Milwaukee Police Chief Jeffrey Norman banned every facial recognition tool on February 6, 2026. The directive came one day after a packed Fire and Police Commission meeting where MPD Inspector Paul Lao admitted the department had already been using the technology without any standard operating procedures [13][14][15].
- Hawaii's Department of Law Enforcement plans 12 Skydio X10 drones over Waikiki starting in March. Director Mike Lambert confirmed the drones ship with facial recognition capability and thermal imaging, calling the FRT hardware ready but not yet activated [17][18][19].
Canvas LMS Breach: ShinyHunters Claims 275 Million Student Records, 3.65 Terabytes
ShinyHunters added Instructure to its Tor extortion site on May 3, 2026, three days after the company first noticed that API-key-dependent tools were misbehaving. The threat actor claims 3.65 terabytes of data covering 275 million users at roughly 9,000 schools and universities walked out the door, and publicly taunted that "your Salesforce instance was also breached and a lot more other data is involved" [1]. Instructure's own May 2 update confirmed that names, email addresses, student ID numbers, and private messages between Canvas users were taken; passwords, dates of birth, government IDs, and financial information were not [2]. ShinyHunters has not been known to inflate numbers, and the company has not denied them.
Canvas is the dominant American learning-management system in K-12 and higher ed. The Canvas Data 2 analytics platform was offline during the response window. The platform processes parent-teacher messages, stores student work, and integrates with single sign-on and Salesforce [3]. A name plus an email plus a student ID plus a thread of private messages is a phishing kit, which is exactly what ShinyHunters specializes in producing. Web searches and Google Threat Intelligence Group reporting in 2025 tied ShinyHunters to a Salesforce OAuth campaign that hit multiple large companies. Schools were not on the list of likely victims a year ago. They are now.
This is Instructure's second public breach in less than a year [3]. Three days from "tools acting weird" to "extortion listing" is the new normal in the Salesforce supply-chain era. The full article walks the timeline, what Instructure did right, and the unanswered questions about how many users were actually affected [6].
Liberty Mutual Lost 108 GB to Everest Ransomware. The Data Is Already Out.
Everest published 108 GB of data it says it stole from systems connected to Liberty Mutual Insurance on April 30, 2026, after the insurer reportedly failed to respond to ransom demands. The dump landed on May 4 and was redistributed across multiple hacker forums [4]. Researchers who reviewed the archive counted 52,429 files organized into 14,979 folders, including policyholder names, home addresses, policy numbers, financial information tied to policies, individual claim records, and corporate client documentation [5]. The trove's internal timestamps suggest the attackers had access for months before the exfiltration.
Liberty Mutual's response: this is a vendor problem, not ours. The company told reporters it is investigating "a possible incident at a third-party vendor" and added that "our current review does not indicate a compromise of Liberty Mutual systems or networks" [4]. For the policyholder, it does not matter whether Everest broke into Liberty Mutual directly or through a vendor. Names, addresses, and policy numbers are exposed.
Liberty Mutual is the ninth-largest property and casualty insurer in the world, a Fortune 100 company with $50.5 billion in net revenue in 2025 and more than 40,000 employees across 27 countries [22]. Everest is on a tear: the group also listed payment processor Fiserv on its leak site on May 3, one day before the Liberty Mutual dump [23]. Watch for insurance-themed phishing, fraudulent insurance claims filed in your name, and targeted scam calls from people who now know you have homeowner's insurance. The full article walks the dump's contents and what to do today [23].
West Virginia Sues Apple Over iCloud CSAM: 267 Reports Against Meta's 30.6 Million
West Virginia Attorney General JB McCuskey filed suit against Apple in Mason County Circuit Court on February 19, 2026, the first state lawsuit of its kind. The complaint makes four claims: strict liability for design defect, negligence, public nuisance, and consumer-protection violations, and frames Apple's approach to child safety as "absolutely inexcusable" [7]. Apple reported 267 instances of CSAM to NCMEC in 2023. Google reported 1,470,000. Meta reported 30,600,000 [9]. West Virginia cites 18 USC § 2258a, the federal reporting obligation, and the company's own abandonment of the NeuralHash on-device scanning system Apple killed in December 2022 after privacy backlash [8][10].
The complaint quotes Apple's then-head of fraud describing iCloud in 2020 as "the greatest platform for distributing child porn." Not an outside critic. Not a competitor. Apple's own internal language, per the lawsuit [8][9]. McCuskey's full statement closed on the human cost: "Behind every sexually explicit image or video is a child's rape, molestation, or sexual abuse. CSAM is a permanent record of that child's trauma, forcing upon children a lifetime of re-victimization" [7].
The case forces the question the encryption fight has been avoiding. If Apple loses, on-device scanning could be mandated, with all the expansion risk that implies for other content categories. A separate 2024 federal lawsuit representing approximately 2,680 victims is already pending against Apple seeking $1.2 billion [10]. The full article traces the NeuralHash build-then-kill arc, the wider encryption-pressure context, and what the case means for EARN IT, Chat Control, and the UK's already-litigated backdoor [11].
Milwaukee Banned Police Facial Recognition After Three Hours of "No"
Milwaukee's Fire and Police Commission meeting on February 5, 2026 was supposed to rubber-stamp a draft policy: MPD trades 2.5 million mugshots to Biometrica, gets facial recognition access for free. The room had other plans. Dozens of residents packed City Hall. Three solid hours of public comment. Speaker after speaker said not in our city [13]. Nadiyah Johnson of Milky Way Tech Hub told the commission: "The harm is not theoretical. The harm is real. It impacts real people" [13].
The bombshell landed during the meeting. MPD Inspector Paul Lao confirmed under questioning: "As needed right now, we are still using [facial recognition technology]." No standard operating procedures existed. No tracking records of when or on whom the technology had been deployed. The department that came to ask permission had been running the tool without asking at all [15]. One day later, on February 6, Chief Jeffrey Norman reversed course. He issued a department directive banning facial recognition for all members and announced that MPD would not proceed with the Biometrica acquisition at this time [14]. Norman's statement: "Despite our belief, this is useful technology to assist in generating leads for apprehending violent criminals. We recognize that the public trust is far more valuable."
The ban is voluntary, not legislative. A future chief could reverse it. The ACLU of Wisconsin flagged exactly that concern; binding legislation (a CCOPS ordinance) is the durable version. Milwaukee joins San Francisco and Oakland in rejecting the technology, but stands out for being a community win mid-negotiation, not a preemptive ban on something hypothetical. The full article covers the secret-use admission, the union pushback, and the CCOPS gap [16].
Waikiki Is Getting 12 Skydio Drones With Facial Recognition Sitting in the Dashboard
Hawaii's Department of Law Enforcement, led by Director Mike Lambert, is preparing to launch a Skydio drone program over Waikiki as early as March 2026. Twelve drones. Four launch pads. The drones ship with facial recognition capability built in; Lambert has not activated it yet [17]. The annual cost is $500,000, about what four full-time officers would cost.
Crime in Waikiki is already declining. The Honolulu Police Department is down roughly 20% on officers; the Department of Law Enforcement is roughly 25% understaffed. The drone pitch is efficiency: 30-second response, live streaming to officers en route, remote speakers, no on-site pilot [17][19]. An ACLU count cited in Civil Beat coverage put the number of US police departments running drone programs at more than 1,400 as of 2023. Milwaukee launched its own Skydio X10 program in January 2026 [18].
The privacy governance in Waikiki is thin. The Neighborhood Board approved the program in October 2025. One board member asked for drones not to launch over his hotel's sun deck. Citizen member Jacob Wiencek raised Fourth Amendment concerns. The ACLU has warned against normalizing aerial surveillance without strict limits and complete deployment transparency [19]. Cleveland wrote a formal policy banning facial recognition on its Skydio drones. Hawaii has not. The full article walks the spec sheet, the staffing rationale, and the lack of an activation policy [20].
What to Watch This Week
Canvas sample data drop. ShinyHunters typically posts a teaser within 7 to 14 days of a leak-site listing. That will tell us whether the 275 million figure is real. Watch for Instructure's first formal affected-user count and any Salesforce confirmation or denial [1][2].
Liberty Mutual customer notifications. The company has not yet announced credit monitoring or affected-policyholder counts. Watch for the first state breach-notification filings and the class action opening [4][23].
The West Virginia CSAM case docket. The first state lawsuit of its kind is also the first test of whether a court can mandate on-device scanning. Watch for Apple's response, the standard 18 USC § 2258a reporting argument, and any other state AG signaling they will join [7][10].
A Milwaukee CCOPS ordinance. Chief Norman's directive is reversible. The durable version is a Community Control Over Police Surveillance ordinance binding the department through future administrations. Watch for aldermanic introduction, public-records requests into past FRT use, and the state-level replication question [16].
The Waikiki drone launch. As soon as Director Lambert's X10s leave the pad, any drone-feed footage becomes the test case for Hawaii's lack of aerial-surveillance law. The ACLU of Hawaii is the leading pushback. Watch for the first public-flight report and any facial recognition activation announcement [17][19].
Sources
- BleepingComputer: Instructure confirms data breach, ShinyHunters claims attack (May 2026). https://www.bleepingcomputer.com/news/security/instructure-confirms-data-breach-shinyhunters-claims-attack/
- SecurityWeek: Edtech Firm Instructure Discloses Data Breach Amid Hacker Leak Threats (May 2026). https://www.securityweek.com/edtech-firm-instructure-discloses-data-breach/
- DataBreaches.net: Instructure discloses second data breach in less than a year (May 3, 2026). https://databreaches.net/2026/05/03/instructure-discloses-second-data-breach-in-less-than-a-year/
- BankInfoSecurity: Everest Group Begins Leaking Alleged Liberty Mutual Data (May 2026). https://www.bankinfosecurity.com/everest-group-begins-leaking-alleged-liberty-mutual-data-a-31589
- CyberNews: Hackers claim Liberty Mutual breach exposed thousands of individual insurance records (May 2026). https://cybernews.com/security/liberty-mutual-ransomware-attack-policyholder-data/
- State of Surveillance: Canvas LMS Breach ShinyHunters 275M Records (May 4, 2026). /news/instructure-canvas-shinyhunters-275-million-students-3-6tb-breach-2026
- West Virginia Attorney General: Press Release (February 19, 2026). https://ago.wv.gov/article/west-virginia-attorney-general-sues-apple-role-distribution-child-sexual-abuse-material
- JURIST: West Virginia Attorney General Sues Apple Over Encryption, Child Porn (February 2026). https://www.jurist.org/news/2026/02/west-virginia-attorney-general-sues-apple-over-encryption-child-porn/
- MacRumors: Apple Sued by West Virginia for Allegedly Allowing CSAM Distribution Through iCloud (February 2026). https://www.macrumors.com/2026/02/19/apple-west-virginia-csam-lawsuit/
- WV MetroNews: W.Va. Attorney General Files Lawsuit Against Apple Over CSAM (February 2026). https://wvmetronews.com/2026/02/19/w-va-attorney-general-files-lawsuit-against-apple-over-csam/
- State of Surveillance: West Virginia Sues Apple Over iCloud CSAM (February 21, 2026). /news/west-virginia-apple-icloud-csam-lawsuit-encryption-2026
- Fox News: West Virginia Sues Apple, Accuses Tech Giant of Letting iCloud Become Hub for Child Sexual Abuse Material (February 2026). https://www.foxnews.com/politics/west-virginia-sues-apple-accuses-tech-giant-letting-icloud-become-hub-child-sexual-abuse-material
- CBS58: Packed House Urges FPC to Reject Facial Recognition Technology for MPD (February 5, 2026). https://www.cbs58.com/news/packed-house-urges-fpc-to-reject-facial-recognition-technology-for-mpd
- FOX6 Milwaukee: Milwaukee Police Department Facial Recognition Technology Banned (February 6, 2026). https://www.fox6now.com/news/milwaukee-police-department-facial-recognition-technology-banned
- WUWM 89.7: Milwaukee Commission Finds Out MPD Is Using Facial Recognition Tech Without Operating Procedures (February 5, 2026). https://www.wuwm.com/milwaukee-police-facial-recognition-without-operating-procedures
- State of Surveillance: Milwaukee Police Ban Facial Recognition After Community Revolt (February 9, 2026). /news/milwaukee-police-facial-recognition-ban-community-victory-2026
- Honolulu Civil Beat: A New Era Of Police Surveillance Is Coming To Waikiki (February 2026). https://www.civilbeat.org/2026/02/waikiki-new-era-police-surveillance-drones/
- DroneXL: Milwaukee Police Launch Drone First Responders (January 2026). https://dronexl.co/2026/01/16/milwaukee-police-drone-first-responders/
- Beat of Hawaii: Waikiki Says Crime Is Down. So Why The Drones? (February 2026). https://beatofhawaii.com/waikiki-says-crime-is-down-so-why-the-drones/
- State of Surveillance: Hawaii Plans to Fly Surveillance Drones Over Waikiki (February 8, 2026). /news/waikiki-police-drones-skydio-surveillance-hawaii-2026
- State of Surveillance: Liberty Mutual Everest Ransomware 108GB Policyholder Data Leaked (May 6, 2026). /news/liberty-mutual-everest-ransomware-108gb-policyholder-data-leaked-2026
- Ransomware.live: Victim Liberty Mutual Insurance (Everest group). https://www.ransomware.live/id/TGliZXJ0eSBNdXR1YWwgSW5zdXJhbmNlQGV2ZXJlc3Q=
- State of Surveillance: Fiserv Everest Ransomware: The Company Behind Your Bank (May 2026). /news/fiserv-everest-ransomware-payment-processor-10000-banks-2026
- Helping Survivors: West Virginia Files Lawsuit Against Apple Over CSAM on iCloud (February 2026). https://helpingsurvivors.org/news/west-virginia-sues-apple-over-csam/