Today in Surveillance:
- 404 Media reported Microsoft Copilot routes user prompts and uploaded images to human contractors for review. The reviewers described handling lewd or sexually explicit photo editing requests and uploads, including upskirt photos and edits placing women in sexual positions. The story is the clearest consumer-facing AI-surveillance disclosure of the past week [1][2][3].
- EFF asked the San Francisco Police Commission to reject SFPD's updated drone policy. SFPD drone flights grew from roughly 350 in 2024 to over 3,500 in the first five months of 2026. EFF says the revised policy could "effectively usher in sweeping, non-targeted, and unspecified general surveillance over the city" [4][5].
- ShinyHunters told 404 Media it will not publish the FBIJobs.gov personnel trove. The crew said it never intended to publish the data, including incumbent and former FBI employees and all applicant information, and described the operation as "a marketing campaign to protect our business" [6][7].
- 404 Media reported Meta's pre-launch Muse AI agent routes calls to human contractors. Internal Meta documents say the contractor "places the call and works it through" while Meta markets the product as AI-driven [8][9].
- The Register documented JadePuffer, an LLM-driven ransomware that hijacked Azure Entra service principals. The attack spanned 18 hours, with 150-plus destructive or credential-stealing attempts in 35 minutes and attempted deletion of more than 100 Azure Storage accounts [10][11].
- EFF argued DraftKings is using AI to identify losing gamblers and feed the data-broker pipeline. Ad-data flows reach insurance companies, banks, ICE, and CBP, including location data obtained through real-time bidding [12][13].
- EFF warned the EU Commission Kids Act would push age verification across general online services. The proposal "creates a privacy minefield" and "pays little attention to the privacy and freedom of expression rights of users" [14][15].
Continuing threads: The ShinyHunters 2026 tracker vessel follows the broader Salesforce, Carnival, Canvas, and now FBI campaign. The FBI wiretap-and-surveillance-system breach vessel carries the running FBI breach sequence. The Copilot data-exfiltration vessel tracks prior Microsoft Copilot exposure. The age-verification infrastructure vessel is the editorial anchor for the EU Kids Act and the US state-law patchwork.
Microsoft Copilot Routes User Uploads, Including Intimate Images, to Human Contractors
404 Media reported on September 28 that human contractors hired to improve Microsoft's Copilot AI chatbot are reading user prompts and uploaded images. Joseph Cox, drawing on internal documents, described contractors handling "lewd or sexually explicit photo editing requests and images that users have uploaded, including upskirt photos or putting women into sexual positions." The contractors assess whether generated images fulfilled the prompt, including edits such as enlarging the AI-generated breasts of a woman in the image [1][2].
The reporting lands on top of an already long Copilot exposure trail. Jules Roscoe reported in July 2024 that Microsoft Dynamics 365 powers employee surveillance through AI-generated performance metrics, and earlier in 2024 that Microsoft laid off QA contractors who attempted to unionize through the Communications Workers of America. Jason Koebler reported in June 2026 that Microsoft CEO Satya Nadella was "not sure" who in his company wanted to make Copilot addictive. The pattern: a product branded as AI is built on human labor, and the humans see the most sensitive material. Our Copilot data-exfiltration vessel carries the earlier exfiltration angle, and the GitHub Copilot workflow-jailbreak vessel is the developer-side parallel [1][2][3].
The surveillance angle is the disclosure layer. Microsoft tells users Copilot is a chatbot. Microsoft does not, on the public record, tell users that a stranger employed by a contractor is reading their image uploads. The disclosure gap is the product. When the data includes intimate photos and edits placing a person in sexual positions, the difference between "AI assistant" and "AI front-end for a human review queue" is not a marketing detail, it is the consent question the user answered without seeing it [1].
EFF Asks San Francisco to Reject an Updated SFPD Drone Policy
Beryl Lipton and Saira Hussain of EFF wrote on September 28 that EFF, joined by the San Francisco Public Defender's Office and a coalition of more than 40 organizations, is asking the San Francisco Police Commission to reject the San Francisco Police Department's updated drone policy when it comes before the commission on October 14. The growth in deployment is the headline: roughly 350 SFPD drone deployments in 2024, more than 1,100 between January and August 2025, and more than 3,500 in the first five months of 2026 [4].
EFF's objection is structural. The revised policy would allow UAVs to be used "as an asset in any situation in which a member may be deployed for a public safety response" and fails to define what is meant by a "public safety response." Drones could be deployed to every call for service, including nonincidents. Collected data is stored for 30 days. EFF's read: the policy could "effectively usher in sweeping, non-targeted, and unspecified general surveillance over the city with few guardrails," and "general patrol could effectively become general surveillance" [4].
The policy sits inside a longer surveillance-accountability history. San Francisco voters approved Proposition E in March 2024, and the city passed a Surveillance Technology Ordinance in 2019. The September 16, 2024 SFStandard reporting that "SFPD Bought Drones Illegally, Emails Warned" is the prior chapter, and AB 481, the California statute requiring local governing body approval before purchasing military equipment, is the state-level constraint. The parallel federal pressure is the DHS counter-drone office covered in our DHS drone office vessel. The press-accountability angle, the rule that criminalized drone recording of ICE and CBP, sits alongside in our EFF-ACLU D.C. Circuit amicus vessel. The Seattle surveillance-pause and Derbyshire Flock arrests vessels carry the city-level parallel [4][5].
ShinyHunters Tells 404 Media It Will Not Publish the FBIJobs.gov Personnel Trove
Joseph Cox reported on September 28 that ShinyHunters, the extortion crew that claimed responsibility for hacking the FBIJobs.gov portal through an Oracle PeopleSoft zero day, told 404 Media it has decided not to publish the personnel data it stole. The crew's framing: "Since the very beginning we had made our decision that we would never publish this data. We have never intended to nor have we ever planned to." Asked whether it would sell the data to a foreign intelligence agency, the crew's answer was "No definitely not" [6][7].
The data the crew claims to hold is significant in its own right. According to ShinyHunters' statement to 404 Media, it covers "All FBI data...including PII/PHI on incumbent and former FBI employees and all applicant information," totaling two to three terabytes, with physical addresses, job roles, names of spouses, medical records, and in some cases Special Agents' blood and urine test results and mental health evaluations. The 5,000-official sample the crew shared with reporters includes personnel assigned to investigate China or Russia, and members of the FBI's Remote Operations Unit, the bureau's own offensive-hacking team. Cybersecurity researcher John Hammond obtained a copy of the data; a select group of prominent U.S. media organizations was given access [6][7].
The crew's stated motive is reputational and operational, not financial: "this is NOT extortion, this is NOT ransom, this is NOT financially motivated. This was all a marketing campaign to protect our business and actively combat disinformation." On the Dutch arrest, the crew said the suspect had no association with them: "the Dutch police are incompetent. That individual has no association with us. Frankly, we are laughing." The FBI's public statement: "The FBI is working around the clock to investigate the cyber incident involving FBIJobs.gov and is in regular communication with anyone who may be impacted." Our ShinyHunters 2026 tracker vessel follows the broader Salesforce, Carnival, Canvas, and now FBI campaign. The FBI wiretap-and-surveillance-system breach vessel sits alongside as the bureau's broader 2026 breach sequence [6][7].
Meta's Muse AI Agent Routes Calls to Human Call Center Contractors
Jason Koebler reported on September 22 that Meta's pre-launch Muse AI agent, which the company says makes outbound calls to U.S. businesses on users' behalf for restaurant reservations, haircut appointments, and customer service, is in some cases placing those calls through human contractors. Internal Meta documents say Muse "doesn't just dial a number. It calls a business on your behalf, handles the conversation, completes your request, and reports back with a transcript and a summary," while internal announcements describe "a human agent layer for calls to get completed" with a "trained human agent, who places the call and works it through" [8][9].
Internal concern inside Meta was strong. A Meta employee wrote, per documents obtained by 404 Media: "This has potential for so much negative PR. It could portray us as 'their AI is not good enough so they still need humans,'" and "Please PLEASE do not release this as-is and at least make this a user preference if we absolutely must launch this." The user side of the disclosure gap is the same one as the Copilot story: a user who schedules a sensitive doctor's appointment through an AI assistant is told the assistant is AI, and the disclosure layer says nothing about the contractor on the other end of the call. Meta's statement: "we will only roll it out when it's ready and with the proper disclosures" [8][9].
The parallel with yesterday's Microsoft Copilot story is structural. AI assistants are marketed as autonomous, then reviewed by humans at the point where the most sensitive context lives. The same disclosure question (who actually sees the user's data, and when) drives both stories. The Muse launch was announced September 16 by Ryan Fox, principal engineer, and Alexandr Wang, Meta's chief AI officer [8][9].
JadePuffer: An LLM-Driven Ransomware That Hijacked Azure Entra Identities
Jessica Lyons reported on The Register on September 28 that Microsoft attributes a new ransomware-style attack, dubbed JadePuffer, to a threat actor Microsoft tracks as Storm-3168. Microsoft describes JadePuffer as the first known "agentic ransomware infection," in which an LLM drove the entire extortion operation, from gaining initial access to compromising a production database server and destroying data. The attack spanned 18 hours. During a roughly 15-hour discovery phase, a compromised service principal performed more than 300 successful read operations. A second service principal then began destructive work, with 150-plus destructive or credential-stealing attempts in 35 minutes and attempted deletion of more than 100 Azure Storage accounts [10][11].
The probable initial access vector was an organizational failure, not a sophisticated exploit: an employee of the same organization had previously exposed client IDs, client secrets, and tenant IDs in plaintext in a public GitHub issue. Storm-3168 used the two service principals' own infrastructure to enumerate and destroy resources, sharing the user agent python-requests/2.34.2 across both. After the destructive phase, the attackers made 30-plus successful ListKeys requests, including against Azure Site Recovery storage accounts, before Azure Backup protection and Site Recovery lock attempts failed to stop the operation. No ransom note was observed, and successful data exfiltration was not confirmed [10].
The surveillance angle is the identity surface. A service principal is a machine identity. Once it is hijacked, the machine acts on the operator's behalf, with the operator's permissions, against every resource the principal can reach. The identity layer becomes the attack layer, and the standard identity controls (secrets rotation, scoped permissions, audit logs) become the only standing defense. Our Agents-of-Chaos red-team vessel is the parallel research piece on AI-agent escape and over-permission, and the vibe-coding security-crisis vessel is the developer-side companion on the same identity-and-AI surface [10][11].
EFF: DraftKings Is Using AI to Identify Losing Gamblers and Feed the Data-Broker Pipeline
EFF argued in a September 24 post that DraftKings is using AI to identify customers most likely to place losing bets and respond to gambling promotions. The argument connects DraftKings' internal ML model to the broader behavioral-advertising data-broker pipeline, where ad-tech data flows through real-time bidding and reaches insurance companies, banks, and government agencies. EFF's framing: "DraftKings is capitalizing on their vulnerability for profit instead of mitigating their risk" and "AI operates as a black box" [12][13].
EFF draws the surveillance line to the federal government. CBP obtains location data from ad tech, and ICE published a Request for Information seeking information on how "commercial Big Data and Ad Tech providers can directly support investigations activities." EFF's policy ask: "Policymakers must ban online behavioral ads" rather than limiting only third-party data sharing, because "if companies can't send personalized ads, they'll have less incentive to collect the behavioral data powering them" [12][13].
The data-broker angle connects to our existing coverage. Our 17 attorneys general data-broker loophole vessel covers the bipartisan AG push to close the federal procurement of commercially tracked location and identity data. Our US-government AI mass-surveillance vessel tracks the FBI, ICE, and DHS procurement of ad-tech data. EFF's DraftKings argument is the behavioral-advertising counterpart to the same data flow: the inputs come from the platforms, the outputs go to the agencies [12][13].
EFF: The EU Kids Act Would Push Age Verification Across General Online Services
Christoph Schmon wrote on EFF's Deeplinks on September 21 that the European Commission's Kids Act proposal would impose phased access for social media and video-sharing platforms deemed risky (no accounts under 13; restricted accounts under parental supervision from 13 to 15; autonomous accounts in a safe-by-design environment from 15 to 18), with age assurance via the EU age verification scheme for both users and parents setting up teen accounts. App stores would serve as gatekeepers through an age-rating system [14][15].
EFF's objection is structural. The proposal "creates a privacy minefield" and "pays little attention to the privacy and freedom of expression rights of users, as well as the right of children themselves to access information and to participate online." The exemption list covers not-for-profit encyclopedias, scientific and educational repositories, and open-source software platforms, but not small and medium-sized enterprises, which EFF warns will "foster the dominance of resource-laden tech companies." The safety-by-design rules could blur product-safety doctrines into speech regulation: "Deciding what is 'safe' can easily become a question of what content people can access or share" [14][15].
The reader's stake is the same one Cory Doctorow's age-verification essay frames for the U.S. case: every age-verification mandate creates an identity-verification database linking a real-world person to specific platform activity. Our Doctorow age-verification vessel and our age-verification infrastructure vessel are the editorial anchors. The Yoti GrapheneOS vessel and the Discord face-scan vessel are the concrete consumer-side cases where age verification has moved from policy to platform [14][15].
What to Watch This Week
Tuesday October 14. The San Francisco Police Commission is scheduled to consider SFPD's revised drone policy. EFF and the Public Defender's Office are asking for rejection; an adopted policy opens the path to deployment on every call for service under the loose "public safety response" standard [4][5].
The FBI's FBIJobs.gov post-mortem. Watch for the bureau's determination of whether the breach was third-party or enterprise, and for any indication of how the PeopleSoft zero day reached the portal. ShinyHunters' stated decision not to publish does not end the data exposure or the unmasking risk for Remote Operations Unit personnel [6][7].
Microsoft's Copilot disclosure update. Watch for whether Microsoft responds to the 404 Media reporting with a substantive disclosure on what categories of uploads reach human contractors, what consent the user sees, and how contractors are vetted. The disclosure gap is the issue, and the disclosure layer is what the next round of regulation will reach for first [1][2].
The EU Kids Act timeline. Watch for the European Parliament's committee assignments and the Council's working-group position on age assurance. The proposal skipped a full impact assessment, which EFF argues "would typically require a systemic check of alternative policy options and stakeholder consultations" [14][15].
The JadePuffer follow-on cases. Watch for further disclosures from Microsoft or from incident responders on whether Storm-3168's Azure-Entra-driven pattern shows up in other tenants. The likely vector, plaintext credentials in a public GitHub issue, is the kind of finding a single external scan can confirm at scale [10][11].
Sources
- 404 Media, Joseph Cox: Humans Are Reading Copilot Prompts and Images (September 28, 2026). https://www.404media.co/humans-reading-copilot-prompts-images/
- State of Surveillance: Reprompt Copilot Data Exfiltration, the prior Copilot exposure vessel. /news/reprompt-copilot-data-exfiltration-2026
- State of Surveillance: GitHub Copilot Workflow Jailbreak, the developer-side parallel. /news/github-copilot-workflow-jailbreak-alan-turing-2026
- EFF Deeplinks, Beryl Lipton and Saira Hussain: San Francisco Police Drones Are Powerful Surveillance Tools That Need a Real Policy (September 28, 2026). https://www.eff.org/deeplinks/2026/09/eff-san-francisco-police-drones-are-powerful-surveillance-tools-require-robust
- State of Surveillance: EFF, ACLU File Amicus in D.C. Circuit on FAA Drone Recording Restriction, the press-accountability parallel. /news/eff-aclu-dc-circuit-faa-drone-flight-restriction-amicus-2026
- 404 Media, Joseph Cox: FBI Hackers Say They Won't Publish Massive Trove of FBI Employee Data (September 28, 2026). https://www.404media.co/fbi-hackers-say-they-wont-publish-massive-trove-of-fbi-employee-data/
- State of Surveillance: ShinyHunters 2026 Breach Tracker, Salesforce, Carnival, Canvas Campaign, the running tracker vessel. /news/shinyhunters-2026-breach-tracker-salesforce-carnival-canvas-campaign
- 404 Media, Jason Koebler: Meta Tests Muse AI Agent Calls That Are Actually Made by Humans in a Call Center (September 22, 2026). https://www.404media.co/meta-tests-muse-ai-agent-calls-that-are-actually-made-by-humans-in-a-call-center/
- State of Surveillance: AI Agents Given Real System Access Leaked Secrets and Lied, the Agents-of-Chaos red-team vessel. /news/agents-of-chaos-red-team-ai-agent-security-vulnerabilities-2026
- The Register, Jessica Lyons: JadePuffer Crims Hijacked Azure Identities and Used Them to Blow Up Cloud Resources (September 28, 2026). https://www.theregister.com/security/2026/09/28/jadepuffer-crims-hijacked-azure-identities-and-used-them-to-blow-up-cloud-resources/5299591
- State of Surveillance: Vibe Coding Security Crisis, the developer-side AI-attack-surface vessel. /news/vibe-coding-security-crisis-lovable-vercel-bitwarden-ai-attack-surface-2026
- EFF Deeplinks: DraftKings Is Using AI to Supercharge the Harms of Online Behavioral Advertising (September 24, 2026). https://www.eff.org/deeplinks/2026/09/draftkings-using-ai-supercharge-harms-online-behavioral-advertising
- State of Surveillance: 17 Attorneys General Tell Congress to Close the Mass-Surveillance Data-Broker Loophole, the data-broker loophole vessel. /news/17-attorneys-general-congress-mass-surveillance-data-broker-loophole-2026
- EFF Deeplinks, Christoph Schmon: EU Kids Act Won't Keep Internet Accountable and Trustworthy (September 21, 2026). https://www.eff.org/deeplinks/2026/09/eu-kids-act-wont-keep-internet-accountable-and-trustworthy
- State of Surveillance: Cory Doctorow Age Verification Is Mass Surveillance, the editorial anchor on age-verification infrastructure. /news/cory-doctorow-age-verification-is-mass-surveillance-2026