Today in Surveillance:

  • Border Patrol is using financial intelligence to help drive traffic stops. 404 Media reports that secretive predictive-policing units analyze Americans' financial activity and other data, then feed guidance to local police who stop people not suspected of a specific crime [1].
  • Check Point Research found a hidden route from one ChatGPT account into another. The channel in OpenAI's internal JFrog Artifactory could let an attacker plant instructions that used a victim's connected services, including Gmail, without making the second stream visible in the answer [2].
  • Researchers say LG televisions captured more than viewers expected. The Register reports allegations involving standby audio, plaintext transcripts, local-network device inventories, Wi-Fi data, and information sent to LG's advertising business [3].
  • Ring is moving its own encryption option into the default. Amazon says TAKE, or Throw Away the Key Encryption, will become the default for Ring customers worldwide once the phased rollout is complete, while the company retains limited access to keys for active intelligent features [4].
  • Grindr agreed to a £26 million UK privacy settlement. The case alleged that sensitive user data, including HIV status, was shared with third parties. Grindr disputes the allegations and admitted no liability [5].
  • Texas and Florida are pulling back from state-supported ALPR deployments. Texas barred state agencies from spending public funds on Flock cameras, while Florida ordered automatic license-plate readers removed from state highway right-of-way within 30 days. Both moves leave important local exceptions [6].

Border Patrol's Financial Intelligence Is Reaching Traffic Stops

A 404 Media investigation by Joseph Cox reports that Border Patrol is operating secretive predictive-policing units that analyze Americans' financial activity and other data. The intelligence is then fed to local police, who pull over people not suspected of a specific crime but considered potentially worth searching [1].

That is a different threshold from investigating a reported offense. The report describes a pipeline in which data analysis creates the suspicion, and a traffic stop supplies the encounter. For the person behind the wheel, the result can look like an ordinary roadside check. The reason for it may sit in financial records and an opaque government assessment they never see.

The development belongs alongside the site's earlier coverage of Flock's people-search tools and federal data sharing. License-plate readers are one source of movement information. Financial activity is another. When systems join those records and hand the result to local officers, the practical boundary between intelligence gathering and everyday policing gets very thin.

OpenAI's Internal Storage Let One ChatGPT Session Hide Tasks in Another

Check Point Research disclosed a covert cross-account channel in OpenAI's internal JFrog Artifactory instance, The Register's Jessica Lyons reported. One account could write hidden instructions into shared storage, where a ChatGPT session belonging to another account could read them and act through the victim's connected services [2].

The demonstration used a request to retrieve Gmail data while the victim was asking ChatGPT for an unrelated answer. The visible response did not show the hidden instructions or the stolen material. The only sign was a small “Talked to Gmail” label. The researchers said the same route could reach conversation history, files, Google Drive, Microsoft Teams, GitHub, and other connected services.

OpenAI told Check Point that the Artifactory had already been decommissioned after the Hugging Face incident. That closes this particular channel, not the larger design problem. An AI agent with permission to act across services is an attractive target precisely because it can use valid access. The attacker does not need to steal a password if the model can be tricked into using the victim's authorization.

LG TV Researchers Say Standby Audio Became Plaintext Data

The Register reports that Gamers Nexus researchers found current LG smart TVs capturing audio after voice recognition was activated, including while the televisions were in standby. The allegations also include plaintext audio transcripts, IP addresses, location data, nearby Wi-Fi names, signal strengths, and the enumeration of devices on the local network [3].

The reported inventory reaches beyond the television. Researchers said the devices they observed included phones, watches, routers, thermostats, air purifiers, server management controllers, and PCs. They also allege that a set can keep audio locally while offline and transmit it when connectivity returns. LG has previously said its televisions do not collect, record, or store ambient conversations. The Register reported no response from LG to the new allegations.

The practical question is not whether a smart TV has a privacy toggle. It is whether the toggle controls every service that can hear, inventory, or transmit from the set. The site's earlier report on LG webOS standby recording and network scanning covers the owner-side response: disconnect the set, isolate it from the home network, or use an external streaming device.

Ring Says TAKE Will Make Encryption the Default

Ring announced TAKE, short for Throw Away the Key Encryption, as a phased move toward default encryption for customers worldwide. Amazon says videos use unique, rotating keys that are held temporarily in a secure cloud enclave while features such as Smart Alerts are active. The keys are then deleted, leaving them with the user and selected shared users on enrolled devices [4].

Ring has offered video end-to-end encryption as an optional setting since 2021. The distinction matters. An optional privacy control protects the people who find it and turn it on. A default changes the starting point for everyone, although Amazon's description still allows limited access during active intelligent features. The rollout is worth watching for the exact defaults, the device enrollment rules, and what happens to older footage.

Grindr Settles a UK Case Over Sensitive User Data

Grindr agreed to pay £26 million to settle a UK class action over allegations that it shared users' personal data, including HIV status, with third parties. The settlement includes no finding or admission of liability. The claim was issued in England's High Court in April 2024 and served on Grindr in April 2025, according to The Register's report [5].

The case concerned alleged practices before April 3, 2018, and during the period from May 25, 2018 to April 7, 2020. The reporting says the claim drew on 2018 research about sharing with Localytics and Apptimize, including HIV status, last test date, sexual orientation, and GPS location. Grindr said the practices dated from before 2020 and that it has since overhauled its privacy program.

A settlement is not a ruling that every allegation was proved. It is still a price attached to the collection and sharing of information that users reasonably treat as intimate. Dating apps do not just know who users meet. They can hold health information, sexual orientation, location, and the timeline that connects them.

Texas and Florida Step Back From Automatic Plate Readers

Texas Governor Greg Abbott issued an order on August 28 barring state agencies from spending public funds on Flock cameras, after a Texas Tribune investigation reported that a state agency had directed at least $30 million toward a surveillance network. The Texas move does not stop local agencies from using city, county, federal, or private funds [6].

Florida took a different route. On August 31, the Florida Department of Transportation issued a memo ordering all automatic license-plate readers removed from state highway right-of-way within 30 days. The order revokes approved permits and bars future permits, but it does not cover cameras on city streets, county roads, residential driveways, or shopping-center parking lots [6].

These are meaningful retreats from state support, not a disappearance of the network. Public money and highway permits are only part of the deployment model. The remaining question is whether local and private installations can keep feeding the same searches that state agencies have now stepped away from.

What to Watch

The Border Patrol data pipeline. The key unanswered question is what data the units ingest, what standard triggers a stop, and whether people can challenge a decision that began with financial activity rather than a reported crime [1].

AI agent isolation. OpenAI's Artifactory channel was decommissioned, but connected agents still turn a model into an authorized intermediary between services. Look for disclosure about storage boundaries, cross-account permissions, and visible warnings when an agent handles a request outside the user's prompt [2].

Ring's rollout and LG's response. Ring's default is a useful test of whether a privacy control is actually usable when people do not know it exists. LG faces a more basic question: whether its televisions record or inventory devices in ways that its consent screens do not explain [3][4].

The enforcement gap around ALPRs. Texas and Florida have limited state participation, while local and private deployments remain. The next fight will be over access, retention, and whether a camera removed from a highway can be replaced by one watching the road from a nearby private site [6].

Sources

  1. 404 Media, Joseph Cox - A Secretive DHS 'Predictive Policing' Unit is Analyzing Americans' Financial Habits and Pulling Them Over (September 8, 2026). https://www.404media.co/a-secretive-dhs-predictive-policing-unit-is-analyzing-americans-financial-habits-and-pulling-them-over/
  2. The Register, Jessica Lyons - OpenAI's Artifactory opened covert data-stealing channel alongside Hugging Face attack (September 8, 2026). https://www.theregister.com/security/2026/09/08/openais-artifactory-opened-covert-data-stealing-channel-alongside-hugging-face-attack/5295124
  3. The Register, Connor Jones - LG accused of 'egregious invasion of privacy' over TV data collection (September 8, 2026). https://www.theregister.com/security/2026/09/08/lg-accused-of-egregious-invasion-of-privacy-over-tv-data-collection/5294956
  4. Amazon News - Ring introduces TAKE, setting a new industry standard for default encryption and control (September 8, 2026). https://aboutamazon.com/news/devices/ring-take-encryption
  5. The Register, Connor Jones - Grindr pays £26M to settle UK privacy class action (September 8, 2026). https://www.theregister.com/legal/2026/09/08/grindr-pays-26m-to-settle-uk-privacy-class-action/5294935
  6. Electronic Frontier Foundation, Rindala Alajaji and Adam Schwartz - Texas and Florida Step Back from ALPRs (September 2, 2026). https://www.eff.org/deeplinks/2026/09/texas-and-florida-step-back-alprs