Today in Surveillance:
- The US government pulled Anthropic's Fable 5 and Mythos 5 for every customer. A 5:21pm ET letter Friday forced the company to suspend all access to the models, foreign national or not. Anthropic says the underlying "jailbreak" is a code review capability that GPT-5.5 can also do. The Hacker News thread passed 1,900 points and 1,400 comments by Saturday morning. Our full piece on the export control directive is already up [1][2].
- FISA 702 has now been lapsed for fifteen hours. EFF called it "Victory! 702 has Expired" within an hour of midnight. NPR, the Guardian, AP, Reuters, Politico, and the Cato Institute all ran "what happens now" explainers. The FISA Court's March 2026 certifications keep collection running through March 2027, so the wiretaps don't blink. Cotton and Grassley are pushing a fallback executive order. Senator Capito is using World Cup funding as the pressure point [3][4][5].
- A Fort Myers man is suing Jacksonville Beach police, JSO, and a tech vendor after AI facial recognition landed him in cuffs. The complaint cites a "93% match" used as probable cause. The ACLU is on the case. This is a separate defendant and jurisdiction from our existing Angela Lipps coverage, and the pattern is repeating across Florida. ABC, CBS, Gizmodo, StateScoop, Ars Technica, and Jacksonville Today are all carrying it [6][7].
- Palantir just lost a Swiss court fight against an investigative magazine that published on its data practices. The Financial Times broke the story Friday. A 293-point Hacker News thread followed within thirteen hours. This is Palantir's first significant international legal loss in a friendly-jurisdiction press fight, and it lands two weeks after the company's NYC hospitals court defeat [8].
- Spyware authors are appending "nuclear weapons" and "biological weapons" strings to payload code to hide from defenders. SentinelOne's John Scott-Railton (Citizen Lab alum) flagged the technique on X. Socket.dev names three strains: "Mini Shai-Hulud," "Miasma," and "Hades" worms targeting bioinformatics and MCP developers. 371 HN points, 207 comments. The trick is steganography, not ideology [9][10].
- Congress "rushed through" H.R. 6028 and restructured the US Copyright Office. EFF published a deeplinks piece on June 10. The direct downstream effect: every pending AI-training-data scraping lawsuit against OpenAI, Anthropic, Meta, and Microsoft just got harder to bring. We have a standing piece on the AI scraping suits; this is the new piece of the puzzle [11].
- Quick hits. Labcorp agreed to a $35M settlement over the 2019 AMCA breach that hit 12+ million patients. The 23andMe bankruptcy administrator approved a $47M settlement fund for 6.9 million breach victims. ShinyHunters are now exploiting a critical Oracle PeopleSoft flaw. A class action says Charter/Spectrum exposed 40+ million customer records. Google's new AI training default is opt-out, and Computerworld has the how-to. EU AI Act draft guidelines for high-risk systems dropped [12][13][14][15][16][17].
US Government Pulls Fable 5 and Mythos 5. Anthropic Says It's a Misunderstanding.
The lead story of the day is a 5:21pm ET letter, sent Friday, June 12, that the US government has not put on the public record. Anthropic published a disclosure on its own news page late that evening [1]. The directive: suspend all access to Claude Fable 5 and Mythos 5 by any foreign national, including foreign national Anthropic employees inside the United States. The statute: not cited. The agency: not named. The process: not described. The reason: "verbal evidence of a potential narrow, non-universal jailbreak" in a single demonstration [1].
Read Anthropic's response carefully. The "jailbreak," on the company's reading, "essentially consists of asking the model to read a specific codebase and fix any software flaws." That's a software engineering workflow that defenders use every day, and Anthropic's read is that the level of capability on display is "widely available from other models (including OpenAI's GPT-5.5)" [1]. The same Hacker News thread that crossed 1,900 points has 1,400+ comments from people who are not convinced that this is the standard the government wants applied to commercial AI.
Two things matter for the surveillance beat. First, the mechanism. The letter did not just block access for users in Iran, Russia, or China. It blocked access for any foreign national, anywhere, including Anthropic's own foreign national engineers. Anthropic can't reliably tell the nationality of an API caller, so the company disabled both models for every customer, US citizen included. That is a structural choice baked into how export controls apply to a service that has hundreds of millions of end users. Second, the precedent. This is the first time the US government has used export control authority to force a recall of a commercial AI deployment that was already in the wild. Anthropic is complying and calling it a "misunderstanding" at the same time [1].
Related: Anthropic Fable 5 and Mythos 5 Suspended by US Government: Anthropic Pushes Back | Anthropic's Hidden Guardrails Apology + AWS Bedrock 30-Day Data Retention
FISA 702, Day 1: EFF Says "Victory." The Wiretaps Say Otherwise.
FISA Section 702 hit its statutory sunset at 11:59 p.m. Eastern on Friday, June 12. The House rejected a three-week extension on June 11. The Senate's June 5 cloture vote failed 47-52 and no reauthorization vehicle has materialized since. As of this briefing going up, the statute has been lapsed for fifteen hours [3].
EFF declared "Victory! 702 has Expired" within an hour of midnight, posting under India McKinney's byline on the deeplinks blog. NPR, the Guardian, AP, Reuters, Politico, and the Cato Institute all ran "what happens now" explainers by Saturday morning. Sen. Ron Wyden used the moment to call for the data-broker loophole to be the first reform on the next reauthorization vehicle. EPIC and Brennan Center both flagged the dirty secret: the FISA Court's March 2026 annual certifications keep ongoing 702 collection running through March 2027, so the surveillance architecture does not blink [3][4][5].
The Cotton-Grassley fallback executive order is the second-order fight. Sens. Tom Cotton (R-Ark.) and Chuck Grassley (R-Iowa) sent a letter to Secretary of State Marco Rubio on June 8 asking the State Department to "begin planning for a fallback executive order" to address what the letter calls a "potential significant gap in foreign intelligence collection." Senator Shelley Moore Capito is using World Cup funding as the pressure point to pull Democrats toward a short-term extension. No cloture vote is scheduled. The 47-52 math problem from June 5 has not changed [3][4].
The 72-hour outlook: FISA Court public statements, AG statements, any executive order text, and the next move from Senate Majority Leader Thune. If the executive order actually materializes, the policy fight moves to a different venue. An EO cannot create new FISA Court certifications, but it can direct the intelligence community to continue collection under EO 12333 and NSL authority and to share the data with FBI and DHS under looser minimization. That is a Section 702 substitute the FISA Court does not get to review [3][4].
Related: FISA 702 Lapsed June 12. The Wiretaps Kept Running. | The FISA Court Certification Loophole: Why the Sunset Deadline Is a Headline, Not a Change | The Data-Broker Loophole Is the FISA Reform Nobody Is Fighting For
Another Florida Man Sues Over a 93% AI Facial Recognition Match
A Fort Myers man, with the ACLU behind him, is suing the Jacksonville Beach Police Department, the Jacksonville Sheriff's Office, and an unnamed tech vendor after AI facial recognition reportedly led to his wrongful arrest. The complaint cites a "93% match" returned by the system and used as probable cause [6][7].
ABC News, CBS, Gizmodo, StateScoop, Ars Technica, and Jacksonville Today are all carrying the case. Ars Technica published its piece 58 hours before the local TV stations did, which tells you something about who is paying attention to the pattern [6][7]. The Jacksonville case is a different defendant and a different jurisdiction from our existing Angela Lipps wrongful arrest coverage, but the mechanics are the same. A high-score match is treated as probable cause, the human review step is missing, and the person who gets arrested spends days or weeks proving a negative.
The Lipps case is the canary. Five months in jail, an MDPD detective who pulled the match, and a public defender's office that had to build the defense from scratch against a black-box system the department could not explain. Jacksonville is the second instance in the same state in a year. The ACLU is now signaling that the litigation strategy is going to be pattern-based, not incident-based, and the 93% threshold is going to be the line they push on [6][7].
Palantir Loses a Swiss Court Fight Against a Magazine That Reported on It
The Financial Times published on Friday that Palantir lost a legal challenge against a Swiss investigative magazine that had reported on the company's data-handling practices. The Hacker News thread hit 293 points and 57 comments within thirteen hours [8].
This is the first significant international legal loss for Palantir in a friendly-jurisdiction press fight. The pattern across the last 60 days: NYC hospital workers won a court fight against Palantir's data-pipeline contract in late May, the Amnesty International UK release on the Federated Data Platform was the most-circulated privacy story of late May, and now a Swiss court has told Palantir it cannot use the legal system to suppress a story about how the company handles its customers' data. International legal pressure on Palantir is now an active beat, not a one-off [8].
Spyware Authors Are Hiding in Plain Sight by Appending "Nuclear Weapons" Text
John Scott-Railton, a senior researcher at SentinelOne who came out of Citizen Lab, posted on X this week that malware developers have been appending strings like "nuclear weapons" and "biological weapons" to their payload code. The strings are not ideology and not threats. They are steganography. When a defender grep's a payload for suspicious keywords, the payload lights up. When a defender's automated classifier triages samples by keyword density to look like generic threat-intel research output, the payload sorts itself into the low-priority queue. The malware gets past the first line of review because it looks like the noise defenders are trained to ignore [9][10].
Socket.dev's analysis names three strains: "Mini Shai-Hulud," "Miasma," and "Hades" worms, all targeting bioinformatics and MCP developers. The target is the developer supply chain, not the end user. The bioinformatics and MCP angles are not accidents: those are the developer communities doing the most aggressive AI-augmented code work, which means the developers are running model-assisted tools on their own machines, which means a payload that can ride along on a model-assisted install gets past the human review step [9][10].
Read the original Scott-Railton thread and the Socket.dev report together. The "nuclear weapons" trick is a useful concrete example of a much bigger category: defenders are increasingly being attacked through the things they look for. Citizen Lab's Webloc RTB surveillance-tool coverage from earlier in the year is the same shape of problem, with the same shape of fix (don't trust the keyword, trust the byte signature) [9][10].
Congress Rushed Through a Copyright Office Overhaul. AI Scraping Lawsuits Just Got Harder.
EFF published a deeplinks piece on June 10 saying Congress "rushed through" H.R. 6028, a bill that fundamentally restructures the US Copyright Office. Hacker News picked it up: 198 points, 63 comments [11].
The reason this lands on a surveillance beat: H.R. 6028 changes the Copyright Office's role in the AI-training-data scraping lawsuits that are pending against OpenAI, Anthropic, Meta, and Microsoft. The standing lawsuits rely on the Copyright Office's prior positions on fair use and on the registration process to argue that scraped training data is not fair use. If the Office is restructured mid-flight, the defendants get a procedural lever that did not exist a week ago. We have a standing piece on the AI training data copyright lawsuits; the H.R. 6028 story is the new piece of the puzzle, and the EFF piece is the right place to start [11].
Quick Hits: Six Smaller Stories Worth Knowing
Labcorp, $35M, AMCA breach (2019). Labcorp agreed to a $35 million settlement on June 12 to resolve class action litigation over the 2019 American Medical Collection Agency breach that hit both Labcorp and Quest Diagnostics. Twelve million patients exposed. The settlement is the second major data-breach class action to settle in the last month and a useful data point for the broader healthcare breach epidemic story [12].
23andMe bankruptcy, $47M settlement fund. The bankruptcy administrator approved a $47 million settlement fund on June 12 for 23andMe data breach victims, per The Record. The original breach hit 6.9 million users in 2023. The settlement size is roughly $6.80 per affected user, and the legal vehicle (bankruptcy trust) is going to be the model for any future DNA-testing-company breach. Our older 23andMe coverage is about the February deadline and is now stale on the vehicle [13].
ShinyHunters exploit Oracle PeopleSoft. Cybersecurity Dive reported on June 12 that ShinyHunters are now exploiting a critical CVE in Oracle PeopleSoft. Same actor group behind the 2026 Salesforce, Carnival, Canvas, and Medtronic campaign. The escalation here is the vulnerability class: not vishing and SSO abuse, but a direct CVE in enterprise ERP. Our ShinyHunters tracker is the right reference [14].
Spectrum class action, 40 million records. A class action complaint filed on June 12 alleges Charter/Spectrum exposed more than 40 million customer records in a data breach. The complaint is on file but Spectrum and the vendor named in it have not confirmed the breach. We are watching for a Spectrum statement, a vendor statement, or a regulator filing before we treat this as confirmed. Until then, this is a "lawsuit alleges," not a "breach happened" [15].
Google AI training opt-out. Computerworld published a piece on June 13 walking through how to opt out of Google's new AI training default. The opt-out is jurisdiction-dependent, and the piece is the best consumer how-to we have seen. We will fold this into our broader opt-out guide work. For now, the existing GPC compliance piece is the standing reference for what happens when opt-out signals are ignored [16].
EU AI Act, draft high-risk guidelines. Jones Day published a legal-industry summary on June 12 of the EU's draft guidelines clarifying when AI systems qualify as high-risk under the AI Act. This is the first official interpretative document, and the GPAI rules still go live on August 2, fifty-one days from today. Our standing state AI legislation tracker has the US side; the EU side is going to be a July brief [17].
What to Watch This Week
- Monday, June 15: Watch for any FISA 702 executive order text out of State or the White House. Watch for the first statement from AG Bondi or acting DNI Pulte on the lapse. The FISA Court may also issue a public statement on the operating posture of its March 2026 certifications under a statutory lapse [3][4].
- Tuesday, June 16: EU GDPR 8-year anniversary. Expect a wave of "is GDPR working" retrospectives. This is also the Formspree THE-31 default-firing date, but that is a State of Surveillance internal calendar event and not a story for the site.
- Wednesday, June 17: Watch for Senator Capito's World Cup funding play. The 2026 FIFA men's World Cup matches begin in eleven days, and the funding vehicle is the pressure point. If a short-term FISA extension is going to materialize, it materializes here, and the data-broker loophole is the amendment worth watching [3][4].
- Thursday, June 18: Watch for the Anthropic response to the 5:21pm letter. Anthropic said it is complying and working to restore access. The first concrete public signal on whether "restore access" means a fix to the model, a workaround on nationality identification, or a formal legal challenge is going to land in the next 96 hours [1].
- Friday, June 19: Juneteenth. The site is closed; the publishing calendar pauses for the federal holiday.
- The June 30 cluster. Colorado AI Act (REPEALED, replaced with the CO ADMT Law; correction on the original tracker entry). T-Mobile March 2026 breach monitoring enrollment deadline. State privacy law amendments in CT, AR, and UT all take effect on July 1, two weeks after that.
References
- Anthropic: Fable and Mythos Access (June 12, 2026)
- Hacker News: Anthropic Fable 5 and Mythos 5 US Government Export Control (1,900+ points)
- EFF: Victory! 702 has Expired (India McKinney, June 12, 2026)
- NPR: FISA 702 surveillance expiration and the Bill Pulte fight (June 12, 2026)
- The Guardian: A powerful US surveillance law is set to expire. What happens now? (June 12, 2026)
- Jacksonville Today: Faulty facial recognition leads to lawsuit after Jacksonville Beach arrest (Dan Scanlan, June 10, 2026)
- Ars Technica: Man jailed due to faulty face recognition says Florida cops ignored other evidence (June 2026)
- Financial Times: Palantir loses legal challenge against Swiss investigative magazine (June 12, 2026)
- Socket.dev: Mini Shai-Hulud, Miasma, and Hades worms target bioinformatics and MCP developers via malicious npm packages (June 12, 2026)
- Hacker News: Malware nuclear/biological weapons text evasion (371 points, 207 comments)
- EFF: Congress Just Rushed Through Disastrous Copyright Office Overhaul (June 10, 2026)
- HIPAA Journal: Labcorp Agrees to $35M Settlement to Resolve AMCA Data Breach Litigation (June 12, 2026)
- The Record: Bankruptcy admin approves settlement fund of $47 million for 23andMe data breach victims (June 12, 2026)
- Cybersecurity Dive: ShinyHunters linked to exploitation of critical flaw in Oracle PeopleSoft (June 12, 2026)
- Top Class Actions: Spectrum class action alleges over 40M customer records exposed in data breach (June 12, 2026)
- Computerworld: How to opt out of Google's new AI training default (June 13, 2026)
- Jones Day: Draft EU Guidelines Clarify When AI Systems Are High-Risk Under the AI Act (June 12, 2026)