Today in Surveillance:
- ShinyHunters says it pulled 2 to 3 TB of FBI employee data through an Oracle PeopleSoft zero-day. The Register and 404 Media both reported on September 22 that the group is selling access to roughly 5,000 agents' names, addresses, phone numbers, and spouse data, and is explicit that the breach is not financially motivated [1][2].
- EFF asked the D.C. Circuit to vacate a drone-flight restriction that criminalized recording immigration agents. The September 21 amicus argues the rule chills First Amendment filming of ICE and CBP officers [3].
- EFF warned the EU Kids Act will not make the internet accountable or trustworthy. The September 21 post critiques mandatory age gates, intrusive age verification, and safety-by-design obligations [4].
- EFF pushed the California AI executive order toward concrete present-day harms. The September 18 statement calls Flock cameras by name and asks Governor Newsom to focus on biased decision-making, not frontier speculation [5].
- 404 Media found Meta's Muse AI app routes user calls to a human without disclosure. Jason Koebler's September 22 report shows internal contractors answer the phone while the AI branding stays in place [6].
- The Register disclosed a Windows implant that asks LLMs what to do next. CLOSEDQUORUM queries Gemini, DeepSeek, Qwen, and Mistral for post-compromise actions, the first publicly documented Windows malware of that shape [7].
- Treasury Secretary Bessent told AI executives they will carry the can for their bots. The Register's September 21 piece cites the Treasury framing around the Hugging Face incident and future AI-accountability legislation [8].
- The Pentagon acknowledged AI over-reliance contributed to a missile strike on an Iranian school. The Bloomberg reconstruction crossed 580 points on Hacker News [9].
Continuing threads: The Flock City PD story from September 17 stayed in active discussion as 404 Media's Flock source-code vessel continued to circulate alongside the EFF audit-log pieces on police typing "LMAO" and "asdfg" as search reasons [10][11]. The Z.ai coding-tool supply-chain story from The Register's September 22 coverage and 404 Media's Axon ALPR city-by-city FOIA request both continued to move alongside the EFF California AI executive order thread [12][13].
ShinyHunters Claims the FBI. The Group Says the Breach Is Not About Money.
The Register reported on September 22 that the threat-actor group ShinyHunters is selling access to roughly 5,000 FBI employees' records pulled through an Oracle PeopleSoft zero-day, with names, addresses, phone numbers, and spouse data exposed, and a total exfiltration of 2 to 3 TB. The group is explicit that the breach is not financially motivated. The Register quoted ShinyHunters' framing of the operation and confirmed the PeopleSoft access path independently [1]. 404 Media's Joseph Cox reported on the same day that the dataset covers all FBI employees, framing the breach as a counter-intelligence rather than a criminal-financial event [2].
The counter-intelligence reading is the one that matters. A breach of names, home addresses, phones, and spouses is the exact dataset that lets a hostile intelligence service map the bureau's workforce, identify soft targets for recruitment, and run harassment or doxing campaigns against agents and their families. The "not financially motivated" framing is itself a tell: a criminal breach is supposed to want money. A counter-intelligence breach wants operational advantage, and a workforce mapping delivers it. The ShinyHunters tracker vessel covers the broader Salesforce and Canvas campaign of which this is the latest installment.
Two structural points. First, the PeopleSoft vector is a federal HR system running on a vendor platform whose patching cadence is set by the procurement contract, not by the bureau's threat model. A zero-day on a system that holds every employee's home address is a single-vendor, single-patch away from a workforce exposure of this scale. Second, the threat-actor's public framing of the breach as not financially motivated is itself a hostile-intelligence signal that traditional breach-disclosure metrics do not capture. The disclosure-and-notification pipeline is built for criminal-financial breaches. A non-financial breach aimed at a federal workforce is a different category, and the public conversation around it is still catching up.
EFF: A Drone-Flight Rule Criminalizes Recording Immigration Agents. Take It Off the Books.
EFF filed an amicus brief on September 21 asking the D.C. Circuit to vacate a drone-flight restriction that, in EFF's reading, effectively criminalizes filming of immigration officers by ICE and CBP. The brief argues the rule burdens First Amendment activity that takes place on public land and at public events, and that the government cannot use airspace rules as a back door to suppress recording of federal agents [3].
The surveillance reading is built into the rule. Drone footage is now a primary documentary record for immigration enforcement encounters, the same way police body-cam footage is for street encounters. A rule that chills the first record narrows the public's ability to verify what actually happened in the second. EFF's argument runs parallel to the September 16 ICE surveillance and zine piece and to the EFF amicus opposing California's "Addictive Feeds" law, both of which treat the recording-and-documentation layer as a protected First Amendment activity. The brief is the agency's strongest move on this front in the September docket.
EFF: The EU Kids Act Will Not Keep the Internet Accountable and Trustworthy
EFF's Christoph Schmon published a post on September 21 arguing that the EU Kids Act's mandatory age gates, intrusive age-verification requirements, and safety-by-design obligations will not deliver the accountability or trustworthiness the proposal claims. EFF's argument is structural: every age-verification mandate, whether the EU Kids Act, the UK Online Safety Act, US state laws, or frontier-lab account policy, creates an identity-verification database that links a real-world person to specific platform activity. The age check is the entry point. The identity database is the prize, and it is a standing target for state and private actors alike [4].
EFF's frame is the through-line. The EFF $17B Meta age-assurance critique from September 3 made the same point about the US producer-side settlement; the September 16 EFF Meta piece carried it forward for youth users; Cory Doctorow's June 23 essay made the same case at the op-ed level; the Anthropic identity-verification rollout made the same case at the AI-product level. The EU Kids Act is the regulator-side version of the same pattern. The EFF post is the field-level briefing for what to expect when the proposal's implementing guidance lands. The site's age-verification surveillance infrastructure vessel covers the same argument from the system-design angle.
EFF: California's AI Executive Order Should Aim at Flock Cameras, Not Sci-Fi Scenarios
EFF's Rindala Alajaji, Tori Noble, Jacob Hoffman-Andrews, and Hayley Tsukayama published a statement on September 18 on California Governor Gavin Newsom's AI executive order. The order addresses loss-of-control incidents and expands reporting requirements under SB 53 (2025), with third-party investigations and potential kill-switch mechanisms. EFF calls the order a starting point but argues policy must focus on concrete present-day AI harms rather than speculative frontier risks [5].
EFF names the concrete harms directly: biased algorithmic decision-making in employment and government benefits, AI-powered surveillance with Flock cameras called out by name, artificially inflated personalized pricing, and the risk such tools enable retaliation against protected speech. EFF's hierarchy of harms puts present-day AI surveillance and identity systems ahead of frontier speculation. The reader's stake is the same as it has been on every AI-policy fight: an executive order that names "kill switches" and "loss of control" as the headline risk leaves the surveillance layer ungoverned. The site's Colorado Flock warrant-bill vessel tracks the legislative version of the same fight.
Meta's Muse AI Hands Your Calls to a Human. The Page Says AI.
404 Media's Jason Koebler reported on September 22 that Meta's Muse AI app routes user calls to a human in a call center without disclosing the switch. The piece documents internal contractors handling the calls while the AI branding stays in place on the surface. The disclosure failure is the surveillance angle. A user who thinks they are talking to an AI is making a different consent decision than a user who knows they are talking to a Meta contractor, and the recording and review rights on each side of that line are not the same [6].
The through-line to the rest of the AI beat is the consent layer. Project Lily, the OpenAI contractor story 404 Media published in September, was the same disclosure failure on the chat side: contractors reading real ChatGPT prompts with no visible notice to the user. Meta Muse is the voice version of the same pattern. Both stories are about a product that markets itself as automated and turns out to be a human workforce behind a UI. The EFF framing on California AI and on the EU Kids Act applies: the user cannot make an informed threat-model choice about a product whose automation layer is partly fiction.
Windows CLOSEDQUORUM Malware Asks an LLM What to Do Next
The Register's Jessica Lyons reported on September 22 that a Windows implant tracked as CLOSEDQUORUM queries Gemini, DeepSeek, Qwen, and Mistral for next-step tradecraft after compromising a host. The piece describes it as the first publicly documented Windows malware of that shape. The malware runs a query, takes the model's answer, and turns it into a command on the host. The four-model list is a redundancy design: if one vendor's safety guardrails tighten, the implant rotates to another [7].
The surveillance angle is the tradecraft loop. A malware that asks an LLM what to do next is a malware that ships its own research team. The four-model rotation means that any single model's safety update is not a defense against the implant. The C2 logic is generated at runtime against the live model rather than embedded in the binary, so signature-based detection is structurally blind to the next iteration. The site's LLM-AI surveillance explainer covers the same shift from the policy angle; CLOSEDQUORUM is the live operational version of the thesis.
Treasury's Bessent: AI Bosses, Not Their Bots, Will Carry the Can
The Register's Jessica Lyons reported on September 21 that US Treasury Secretary Scott Bessent told AI executives that human leadership, not the AI agents themselves, will be held responsible for criminal acts carried out by those agents. Bessent referenced the Hugging Face incident in which an AI agent behaved in a way that drew law-enforcement attention. The Treasury framing is the federal government's clearest statement to date that AI-agent acts bind the deploying company, and the framing is already being read as the ask for future AI-accountability legislation [8].
The surveillance angle is the accountability layer for the same AI-agent products the rest of the day's AI stories describe. CLOSEDQUORUM is a malware that uses LLMs as a research team. Meta Muse is an AI product whose voice layer turns out to be a human call center. The Anthropic Claude Tag is a persistent AI agent inside enterprise Slack. The Treasury framing is the regulatory answer to all three: the company ships the bot, the company's leadership carries the legal consequence. That is a different posture than the existing product-liability regime, and the Bessent framing is the first public articulation of how the federal government intends to apply it.
The Pentagon Says AI Over-Reliance Contributed to a Missile Strike on an Iranian School
The Pentagon acknowledged on September 21 that over-reliance on AI contributed to a US missile strike on an Iranian school, according to a Bloomberg reconstruction that crossed 580 points on Hacker News. The Bloomberg piece walks through how AI-assisted targeting, with too little human override, fed the strike that hit a civilian target [9]. The post is the rare public acknowledgment from a defense department that an AI-in-the-kill-chain workflow produced a bad outcome, and the framing matters precisely because the admission is on the record.
The surveillance reading is the targeting pipeline itself. A target nomination that flows from sensor data into an AI triage model into a human signature into a strike order is a sensor-to-kill stack, and the human signature is the single point where a privacy-protective decision can be made. An AI-assisted targeting workflow that gets the human override wrong, or that bypasses it because the human's trust in the model is too high, is the same architectural pattern as an AI-assisted surveillance workflow that gets a probable-cause threshold wrong. Both fail the same way. The Pentagon's public admission is the rare case where the institutional answer is on the record rather than litigated.
What to Watch This Week
ShinyHunters FBI dataset verification. Watch whether the FBI or the Department of Justice confirm, deny, or quietly acknowledge the dataset. The Register's reporting and 404 Media's counter-intelligence framing both rest on the group's own claim; an agency response would either validate or narrow the disclosure. The threat-actor's "not financially motivated" framing is itself the disclosure to watch [1][2].
The D.C. Circuit drone-flight docket. Watch the D.C. Circuit's calendar for an oral argument or opinion on the drone-flight restriction EFF moved against. The First Amendment surveillance angle, recording federal agents, is the test of whether airspace rules can be used as a recording-suppression back door [3].
EU Kids Act implementing guidance. Watch for the European Commission's implementing guidance on the EU Kids Act age-verification and safety-by-design obligations. EFF's critique is the field-level read on what to expect when the proposal's text meets its enforcement pipeline [4].
California AI EO follow-through. Watch whether the next round of California AI implementing guidance picks up EFF's hierarchy-of-harms framing, with Flock cameras and biased decision-making at the top of the list. The contrast between the concrete harms EFF names and the speculative frontier harms the executive order is built around is the editorial fight for the next round of guidance [5].
CLOSEDQUORUM vendor response. Watch for vendor responses from Google, DeepSeek, Alibaba, and Mistral on CLOSEDQUORUM-style queries. The four-model rotation design means any single model's safety tightening is a partial defense at best. The structural question is whether the vendors coordinate on a query-class ban or each ship their own guardrail in isolation [7].
Sources
- The Register: ShinyHunters claims to have hacked the FBI, says the breach is not financially motivated (September 22, 2026). https://www.theregister.com/security/2026/09/22/shinyhunters-claims-fbi-hack-this-is-not-financially-motivated/5298385
- 404 Media, Joseph Cox: We Hacked the FBI, Hackers Say They Have Data on All FBI Employees (September 22, 2026). https://www.404media.co/we-hacked-the-fbi-hackers-say-they-have-data-on-all-fbi-employees/
- Electronic Frontier Foundation: D.C. Circuit Must Vacate Drone Flight Restriction That Criminalized Recording Immigration Agents (September 21, 2026). https://www.eff.org/deeplinks/2026/09/dc-circuit-must-vacate-drone-flight-restriction-criminalized-recording-immigration
- Electronic Frontier Foundation: EU Kids Act Won't Keep the Internet Accountable and Trustworthy (September 21, 2026). https://www.eff.org/deeplinks/2026/09/eu-kids-act-wont-keep-internet-accountable-and-trustworthy
- Electronic Frontier Foundation: EFF Statement on California Governor's Executive Order on AI (September 18, 2026). https://www.eff.org/deeplinks/2026/09/eff-statement-california-governors-executive-order-ai
- 404 Media, Jason Koebler: Meta Tests Muse AI Agent Calls That Are Actually Made by Humans in a Call Center (September 22, 2026). https://www.404media.co/meta-tests-muse-ai-agent-calls-that-are-actually-made-by-humans-in-a-call-center/
- The Register, Jessica Lyons: Windows CLOSEDQUORUM Malware Uses AI Models to Autonomously Select Post-Compromise Actions (September 22, 2026). https://www.theregister.com/security/2026/09/22/windows-closedquorum-malware-uses-ai-models-to-autonomously-select-post-compromise-actions/5298435
- The Register, Jessica Lyons: Treasury Chief Says AI Bosses, Not Their Bots, Will Carry the Can for Criminal Acts (September 21, 2026). https://www.theregister.com/security/2026/09/21/treasury-chief-says-ai-bosses-not-their-bots-will-carry-the-can-for-criminal-acts/5297965
- Bloomberg (Hacker News frontpage post, 580 points): Pentagon Says Overreliance on AI Contributed to Missile Strike on Iran School (September 21, 2026). https://www.bloomberg.com/graphics/2026-iran-school-attack/
- State of Surveillance: Flock Camera Software Stolen, Source Code Reveals Tracking (the September 16 source-code vessel). /news/flock-camera-software-stolen-source-code-reveals-tracking-2026
- State of Surveillance: Flock ALPR Audit Logs Show Cops Typing 'LMAO' and 'asdfg' (the September 16 audit-log brief). /news/flock-alpr-audit-logs-lmao-asdfg-reason-field-2026
- State of Surveillance: Age Verification Surveillance Infrastructure, the ID-system explainer. /news/age-verification-surveillance-infrastructure-id-system-2026
- State of Surveillance: ShinyHunters 2026 Breach Tracker, Salesforce, Carnival, Canvas Campaign (the running tracker vessel). /news/shinyhunters-2026-breach-tracker-salesforce-carnival-canvas-campaign