Normal view

There are new articles available, click to refresh the page.
Before yesterdayCyberScoop

Senate set to debate package of bills on privacy, AI and kids safety 

By: djohnson
4 August 2026 at 09:23

The Senate is teeing up debate on a raft of new bills that would impact online privacy, kids safety and artificial intelligence.

The Senate Committee on Commerce, Science and Transportation will mark up five bills Wednesday. The most high-profile legislation, the Kids Online Safety Act, sponsored by Sens. Marsha Blackburn, R-Tenn., and Richard Blumenthal, D-Conn., would implement broad changes to how social media and other websites handle data and accounts for users under the age of 17.

KOSA would require online platforms — including social media, video games, messaging apps and streaming services – to exercise “reasonable care” when designing features that could lead to more addictive or harmful online behaviors for minors. It would provide parents with digital tools to control and monitor their children’s accounts, prohibit market or product research on children under the age of 13 and empower the Federal Trade Commission to investigate, fine and enforce the law.

Earlier bill versions earned the backing of large tech companies, including Apple, OpenAI, and others.

By contrast in June, nearly 100 smaller parent, youth and tech-focused organizations signaled their opposition to the bill in a letter to congressional leaders. Some of the signatories, like the nonprofit Issue One, were previous supporters of KOSA who turned on the legislation after the House passed a significantly watered down version that stripped out stronger language around tech companies “duty to care,” which would have set a higher legal standard for covered platforms to consider user harm when designing their products.

Legal and ethical design standards are critical for online services, the groups argue, given lawsuits alleging that major tech platforms contribute to teenage addiction, depression, suicide, and non-consensual deepfakes.

“Major social media companies, the companies this bill regulates, are currently on trial across the country,” the letter said. “The evidence in those cases – internal records prioritizing teen engagement over teen wellbeing, safety changes shelved because platforms would lose users, buried research on the benefits of disconnection shows the default poor choices of these companies when the law does not require otherwise. Stripping the duty of care does not lighten a regulatory burden; it removes the most important obligation requiring these products to be designed safely in the first place.”

However, Blumenthal and Blackburn publicly stated that the House version was “dead on arrival” without those provisions, and they remain in the Senate version of the bill being considered Wednesday.

The markup will also consider other major legislation that would regulate age on the internet, safety features for AI chatbots and more. While proponents claim the bills enhance privacy and safety protections, technology experts largely disagree.

The SCREEN Act, introduced last year by Sen. Mike Lee, R-Utah, would require social media companies to implement age verification technology.

Lee has partnered with parent-led groups to advocate for state-level age verification laws that expand  parental control over children’s social media accounts. Some public surveys have shown broad public support for age verification laws.

Louis Eichenbaum, a former chief information security officer at the Department of the Interior, told CyberScoop that one of the biggest challenges around online age verification is that it “increasingly requires collecting, storing or validating sensitive identity information about them.”

“The goal should not simply be verifying age, it should be doing so while minimizing the collection, retention, and exposure of personally identifiable information,” said Eichenbaum, now federal chief technology officer at ColorTokens. “Every additional piece of identity data collected expands the attack surface and increases the potential impact of a breach.”

Some privacy groups oppose the SCREEN Act and similar age verification laws, arguing the required data collection outweighs child protection benefits. 

The Electronic Frontier Foundation said the SCREEN Act is broader than state-level age verification laws, which only cover websites that are predominantly sexually explicit.

“The bill requires nearly any service hosting even a single piece of sexually explicit content to verify the ages of its users,” wrote EFF director of federal affairs India McKinney. “The result is that the bill would apply not only to adult content sites like PornHub or OnlyFans, but also streaming services like Netflix, and social media platforms like Reddit, Discord, or Bluesky, if they host any adult content.”

The Youth AI Privacy Act, from Sen. Ed Markey, D-Mass., would require new safety features for AI chatbots.

According to a fact sheet released by Markey’s office in March, the bill would ban push alerts, require chatbots to disclose they’re not human, limit data retention, and prohibit using minors’ data for AI training or any purpose beyond providing answers.

The Chatbot Act, by Sens. Ted Cruz, R-Texas, Brian Schatz, D-HawaiI, John Curtis, R-Utah and Adam Schiff, D-Calif. would require AI companies to implement “family accounts” for AI chatbots that give parents the ability to monitor and restrict their children’s interactions. Cruz has said the status quo “has left many parents in the dark” on their kids’ AI use.

The Children’s Artificial Intelligence Toy Safety Act, by Sen. Tammy Duckworth, D-Ill., would create a federal study around toys sold to children that include artificial intelligence or chatbot components.

The post Senate set to debate package of bills on privacy, AI and kids safety  appeared first on CyberScoop.

Security researchers find stalkers abusing Chrome’s sync feature

15 July 2026 at 16:42

Cyberstalkers are increasingly exploiting a feature in Google Chrome meant for mobile phone user convenience, but can give intruders broad access to a device owner’s private information, according to researchers.

Certo Software said in a blog post Tuesday that stalkers are making use of Chrome’s sync capability — meant to make it so signing into Chrome on one device makes it easier to do so on other devices, too — to spy on a phone owner’s browsing history and gain access to their stored passwords.

As an illustration, Certo used the case of a pseudonymous victim, Emma, who had searched for a family lawyer and visited a domestic violence support website while her partner was sleeping, only for him to bring up to her two days later.

“Emma had been careful to only ever use her own device, and she hadn’t noticed any new apps appear on her phone,” wrote Certo co-founder Russell Kent-Payne. “What she didn’t know was that weeks earlier, during a few unattended minutes with her phone, he had opened the Chrome app and quietly signed it into a Google account of his own. From that moment on, every site she visited was being copied straight to his account, viewable from any device, anywhere in the world.”

The surveillance is as easy as that: brief access to a phone, signing into a Google account and making sure sync is turned on for that account.

Eva Galperin, director of cybersecurity at the Electronic Frontier Foundation, said on the Bluesky social media app that Certo’s research serves as “an important reminder that tech-enabled abuse isn’t just limited to stalkerware.”

Certo said that Google could do a couple things, such as providing a temporary notification whenever a new account is added or sync is turned on or offering a regular marker to indicate when sync is active and which account it’s syncing to, to protect users.

Google did not respond to multiple requests for comment about Certo’s findings.

But the uptick in usage of that stalking method could be a byproduct of security successes elsewhere in the fight against spyware, Certo said.

“Modern smartphones are harder to compromise than ever. Regular security updates, stricter app store rules, and on-device threat detection have made traditional spyware a much riskier bet for a cyberstalker than it used to be,” Kent-Payne wrote. “As a result, we’re increasingly seeing abusers turn to something far simpler: the legitimate apps already sitting on their victim’s phone. No installation, no suspicious permissions, no telltale battery drain — just a quiet misuse of a feature the victim never knew existed.”

At the same time, Chrome is the world’s most popular browser, and this isn’t the first time security concerns have popped up about its sync feature, among other worries.

The post Security researchers find stalkers abusing Chrome’s sync feature appeared first on CyberScoop.

Deepfake CSAM lawsuit against xAI, Grok expands

By: djohnson
7 July 2026 at 16:17

Two new parties have been added to a class-action lawsuit against X.ai over its Grok tool including teenagers and children who say it was used by family members or other people they know to create nonconsensual deepfake child sexual assault material (CSAM).

The lawsuit, originally filed in March by three women, was amended this week to include two additional plaintiffs, Jane Does 4 and 5, who say that Grok was used to make the illegal content based on their real photos and videos.

All five of the women in the lawsuit are anonymous, and the complaint said the spread of the material had left them humiliated and ashamed.

Jane Doe 4, a female from Wyoming, said her stepfather uploaded a photo of her when she was 11 and lying on a couch to his phone. Using Grok, the stepfather created more than 7,000 CSAM-related images of her. He also shared and traded the images with others on social media platforms.

The lawsuit alleges that the stepfather opted for Grok “because the platform was less restrictive than other AI models and responded to his prompts to generate sexually explicit material using an image depicting a prepubescent minor.”

It also claims that in February, xAI did generate a tip to the National Center for Missing and Exploited Children regarding the images, but the company only submitted the original, authentic image as evidence. According to the suit, xAI did not respond when law enforcement requested the thousands of Grok-generated images based on the photo and IP address information that would have quickly helped identify her stepfather as the perpetrator.

The lawsuit states that the stepfather shot himself two days after he was arrested and charged with child exploitation crimes. His suicide added to the “extreme personal crisis” brought on by the images created through Grok. She regularly “struggles with self-loathing and disgust” as well as “extreme anxiety” at the thought that the images will be found by others online and suffer from depression, including excessive sleep and suicidal ideation when awake.

Jane Doe 5 claimed that an adult male related to one of her classmates used Grok to convert a photograph from her eighth-grade graduation into illicit material. The images were also traded and shared with others online. While the man was arrested and charged, much of the content is still available on the internet. As a result, she “feels a complete lack of control over the ongoing dissemination of the files.”

“It is impossible to know how many other child sex predators may now possess Jane Doe 5’s CSAM, nor how widely her CSAM has now been disseminated online through darknet channels and applications,” the complaint said.

The press office for xAI did not respond to an emailed request for comment from CyberScoop.

The lawsuit also adds Stability AI as a defendant, alleging the company released Stable Diffusion 1.0 as an open-weight model despite knowing it was trained on CSAM and has declined to alter or modify its guardrails in response.

According to a 2023 Stanford study, the underlying dataset used to train Stable Diffusion models was created through unguided webcrawling of internet content. That means it ingested “a significant amount of explicit material,” including CSAM. Stable Diffusion 1.0 had a classifier meant to block the generation of such images, but because of that training data, downstream developers could more easily exploit the model and create modified versions that bypass those protections.

While Stable Diffusion 2.0 introduced stronger guardrails, the lawsuit claims Stability AI rolled back those protections in response to “disgruntled” users that the new restrictions were “prude” and “unpopular.” That in turn has fed an ecosystem of jailbroken “nudify apps” based on Stability AI’s models.

“Stability AI knew that its models, once capable of generating sexually explicit images, would foreseeably be used to generate CSAM unless appropriate model-level safeguards were implemented,” the complaint said.

Stability AI did not respond to a request for comment from CyberScoop.

The post Deepfake CSAM lawsuit against xAI, Grok expands appeared first on CyberScoop.

Someone infected a spyware probe overseer with spyware

3 July 2026 at 01:00

In 2022 and 2023, the European Parliament’s PEGA Committee investigated spyware abuses across the European Union following journalistic revelations about government deployment of NSO Group’s Pegasus technology.

Now, years later, it turns out that someone was using Pegasus spyware on one of the committee’s own. 

In a report published Friday, the University of Toronto’s Citizen Lab revealed that it found Pegasus on the phone of substitute PEGA Committee member Stelios Kouloglou, a Greek journalist and former member of the European Parliament. It’s the first time a member of the committee has been publicly identified as a Pegasus victim.

For Kouloglou, the Pegasus infection was surprising. For another PEGA Committee member, it was fully expected, if delayed. For Citizen Lab, it was ironic.

For all of them, it was further evidence that much more needs to be done to prevent spyware abuses — such as enacting the very recommendations of the PEGA Committee’s final report that never saw action in the European Parliament.

Kouloglou told CyberScoop that he had run security tests on his phone prior to joining the PEGA committee in 2022, so he didn’t think anyone would be bold enough to try to infect his phone once he became a member. With Greece’s use of Predator spyware under scrutiny, “it would be a big scandal” if he was hacked while on the panel, he said.

But someone — Citizen Lab’s investigation didn’t uncover whom — infected Kouloglou’s phone with Pegasus twice, once around October of 2022 and once around March of 2023, investigators concluded with “high confidence.”

During the first infection, the committee was preparing for some prominent hearings and the first draft of its report. Kouloglou was in the hospital and got a visit from another Greek journalist who had testified before the committee and had himself had his phone infected with spyware earlier. Given the ability of spyware to listen to audio through an infected phone, it’s possible the infection ran afoul of protections for health data.

During the second infection, the panel was preparing for yet more hearings and “was engaged in intense discussions related to the final drafting process,” according to Citizen Lab.

The Citizen Lab investigation of Kouloglou’s came about this May, after he said a lawyer he knew told him there was a way to send his phone’s data to the research organization, during a time when Kouloglou was doing some investigative reporting and writing a “scandal of the week” column. “I said, ‘Why not? Let’s do it,” he said.

Whoever was responsible for infecting Kouloglou’s phone did so during “crucial moments” of the committee’s work, said Hannah Neumann, a member of the PEGA Committee and European Parliament member from Germany.

“Many of us were expecting some hacks during the committee, but it’s still frustrating now to figure out that it really happened,” she told CyberScoop. “When we decided to set up the Pega Committee, we really worked hard with our internal European Parliament IT security…  so that they can provide spyware checks for the members of the Pega Committee and their staff.”

Kouloglou and Neumann could only speculate on who was responsible. But for the two of them, and Citizen Lab, the motive seems clear.

“It is ironic that a member of the committee charged with investigating Pegasus was himself targeted with Pegasus spyware,” Ron Deibert, founder and director of Citizen Lab. “Someone, somewhere likely wanted to breach parliamentary privilege and find out what was going on in that committee. This case shows how the still unregulated and highly abused mercenary spyware industry is poisonous to democratic processes.” 

Kouloglou said he plans to pursue legal action against NSO Group. Many spyware victims have had difficulty winning lawsuits against spyware makers, although not all.

Israel-based NSO Group did not respond to a request for comment Thursday afternoon.

Neuman said the lessons learned as a result of Kouloglou’s phone infection include, “for members of national parliament and the European Parliament: Regularly get your devices checked. Apparently they don’t respect European democracy and parliamentarism.”

Most importantly, it’s time to enact the PEGA committee’s recommendations, she said.

“I don’t know how much more it needs for member states and the commission to wake up and actually start implementing the very good recommendations of our PEGA committee, because we all know that there is a spyware abuse,” Neuman said. “I don’t need to have another committee for that. I just need them to act.”

Kouloglou almost certainly won’t be the last member of parliament to get infected, said John Scott-Railton, senior researcher at Citizen Lab. Some had been infected prior to the work of the PEGA Committee, and some have been found to be targeted since. (The United States’ legislative body has been targeted in the past as well.)

“Providing highly secretive government agencies with surveillance tools supplied by unaccountable and often unethical mercenary firms is a recipe for the abuse of power,” he told CyberScoop. “I can tell you how the next chapter will go: more hacked Parliamentarians. In fact, I suspect there are members voting and attending high level meetings with no idea that their phone has been turned into a spy in their pocket.”

The post Someone infected a spyware probe overseer with spyware appeared first on CyberScoop.

Supreme Court delivers ‘major win’ for tech privacy in Chatrie ruling

29 June 2026 at 13:12

The Supreme Court ruled Monday that collecting phone location data from a geographic area is a Fourth Amendment search, in a decision that both privacy advocates and critics of the ruling say will have vast implications for tech privacy.

The 6-3 ruling in Chatrie v. The United States is a “major win” for privacy under the Fourth Amendment, said one law professor who studies surveillance. And it “will send seismic waves through our Fourth Amendment doctrine” with ramifications “for the foreseeable future,” the dissenting justices wrote. The ruling didn’t fall along some of the traditional lines of justices selected by Republican or Democratic presidents.

Okello Chatrie challenged police’s collection of cell phone data from Google in his bank robbery conviction under a so-called geofence warrant that gleaned insights about his location around the time of the crime. While the Supreme Court punted on the question of whether the specific warrant in his case was proper, it held that the Fourth Amendment’s protections apply to this kind of data collection — and potentially other, future kinds as well.

Among the issues the court debated was whether a generalized collection constitutes a search as defined by the Fourth Amendment’s rights against “unreasonable searches and seizures.” That included questions of whether someone who willingly gives their data to a company like Google retains Fourth Amendment projections for that information, under the “third-party doctrine.”

The majority found that cell location data is substantially similar to cell-site location information addressed in Carpenter v. United States (2018),  where the court similarly held that the government’s collection of this data constitutes a Fourth Amendment search.

In the new opinion, Justice Elena Kagan, writing for the majority, used sweeping language about how the Fourth Amendment might apply as technology advances.

“A new technology should not transform what individuals had reasonably thought they could withhold from the Government,” Kagan wrote for the majority with Justices John Roberts, Sonia Sotomayor, Brett Kavanaugh, and Ketanji Brown Jackson. “An individual has a reasonable expectation of privacy in records about his cell phone’s location, and police intrude on that constitutionally protected interest when they demand the information — even though for only a limited time, and from a third-party tech company.”

Justice Neil Gorsuch wrote a concurring opinion, saying that he differed from Kagan’s opinion only in how it arrived at its conclusions, citing the Fourth Amendment’s language about “papers” and “effects”: “As I see it, Mr. Chatrie’s Location History data qualifies as his personal property.”

Justice Samuel Alito wrote for dissenting justices that the court had gone too far in extrapolating protections specified under the Carpenter decision, saying it “will send seismic waves through our Fourth Amendment doctrine” despite not affecting Chatrie’s case.

“As the majority works its way through the question in this case, it makes sweeping proclamations with implications far beyond the specific procedure that the police used here,” Alito said, adding that the decision “all but guarantees that we will be cleaning up debris for the foreseeable future.”

Andrew Ferguson, a law professor at George Washington University and author of a book about how police use of data threatens personal freedom, said the ruling was big even if it will still be easy for law enforcement to obtain warrants in other ways.

“Chatrie is a major win for Fourth Amendment privacy,” he told CyberScoop. “The Supreme Court did take a significant step today to update the Fourth Amendment in a digital age, and we should be thankful that they did.”

The American Civil Liberties Union also celebrated the ruling.

“The Court’s decision provides critical protection against invasive and overbroad government searches of our personal information,” Brett Max Kaufman, senior counsel with ACLU’s Center for Democracy who helped write a friend of the court briefing on Chatrie’s side, said in a statement to CyberScoop. While Google has changed its system in a way that practically cuts off government requests for future location data, “similar kinds of reverse searches of sensitive data held by other companies will continue to be a threat to privacy. Law enforcement and courts are on notice that new technology does not open up surveillance loopholes, and strict adherence to the Fourth Amendment’s protections is required.”

An attorney who served as Chatrie’s counsel of record said he looked forward to continuing to work on his case.

‘Today the Court decisively held that people have a privacy right in their personal data — no matter how short the timeframe or whether the information is held by a tech company,” Michael Price, Fourth Amendment center litigation director at the National Association of Criminal Defense Lawyers, told CyberScoop. “The government cannot sidestep the Fourth Amendment by labeling location history and other cell phone data as ‘third party’ records. The Court definitively recognized that accessing this data is a search that triggers constitutional protections.”

The Center for Democracy and Technology said in a social media post that “for years, police have treated the trail your phone leaves behind as theirs for the taking, but today in Chatrie v. United States, the Supreme Court slammed that door shut.”

But the ruling indicates the need for Congress to make it illegal to purchase data from third party companies without a warrant, said Don Bell, policy counsel of The Constitution Project at the Project on Government Oversight. The subject has become intertwined with the debate over surveillance powers that expired this month.

Updated 6/29/26: with comments from Price, CDT and POGO.

The post Supreme Court delivers ‘major win’ for tech privacy in Chatrie ruling appeared first on CyberScoop.

ATF cancels controversial commercial geolocation contract

By: djohnson
26 June 2026 at 15:16

The Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) canceled a contract with Penlink that used ad-surveillance technologies to track the location of Americans.

The contract was canceled a little more than a month after ATF Director Robert Cekada acknowledged under questioning from Rep. Michael Cloud, R-Texas, in a congressional hearing that the agency was purchasing the geolocation data of Americans through a contract for “an ad-tech type thing” that would provide the agency with geolocation data “based on the ads that go through.”

 “We have purchased access to that system but we have not used it for a criminal case because we have not established any policies yet on how we would do it,” Cekada said.

He described that system and data as novel and said ATF was still determining how to craft official guidance for how agents would use it in investigative work.

In an email, an ATF spokesperson confirmed to CyberScoop that the contract had been canceled, describing it as a limited pilot project for capabilities the agency was no longer seeking.

”ATF continually evaluates tools and techniques to enhance our investigations and ultimately reduce violent crime in American communities,” the spokesperson wrote. “We did conduct a pilot with Webloc to determine if it could improve our investigative capabilities. After completing our review, we determined the tool does not meet our needs and cancelled the contract. ATF is not currently using any other ad-tech-sourced services.”

According to Sen. Ron Wyden, D-Ore., he requested and his staff received a briefing from ATF on the matter on June 12. In the meeting, Cekada identified purchasing licenses for Penlink’s Webloc commercial location surveillance tool as the contract in question.

Further he said the ATF had already conducted more than 340 searches using the system, including more than 222 that were directly tied to active ATF case numbers.

On its website, Penlink describes itself as an open-source intelligence analysis platform that provides real time data collection, forensic and web analysis and digital evidence collection. The firm touts its use of “AI-driven analysis” to increase case resolution rates by 80% as well as the ability to “tie disparate data together to one subject, place, or group using comprehensive identity resolution capabilities.”

Wyden, who earlier this year led a group of 70 congressional Democrats calling for an investigation into the purchase of commercial location data by Immigration and Customs Enforcement, said that ATF ultimately did “the right thing” but called for Congress to pass his legislation that would change the practice throughout the federal government.

“After Representative Cloud and my staff informed the ATF about the legal and privacy quagmire surrounding adtech data,  the agency did the right thing,” Wyden said in a statement. “Canceling this contract is a victory for Americans’ constitutional rights, but Americans’ privacy shouldn’t depend on ad hoc congressional interventions. Congress must pass the Government Surveillance Reform Act to close the data broker loophole once and for all.”

Wyden’s office noted that the purchase of ad-tech geolocation data is illegal in some states, and that the Federal Trade Commission has already established that selling sensitive location data to government agencies and contractors falls under deceptive and unfair practices under the FTC Act.

The use of ad-tech to surveil and geolocate targets online is a growing problem. While such tools are commonly used by marketing and advertising agencies to send targeted ads based on geography or region, bad actors can also use use to unmask the identities or locations of individuals, or combine them with other public data in ways that worry privacy advocates. A University of Tennessee student is suing a company based in the Virgin Islands for pulling videos from her social media, turning them into nonconsensual ads for their dating service and then using ad-tech geolocation to serve the ads to men online near her.

Wyden’s office said in one instance, the tool was used to get location data for devices associated with a defense contractor at the same time as a suspected arson incident, but that the ATF later backed off from using it in court after both the prosecutor and judge expressed “serious discomfort with the use of warrantless adtech data.” The ATF ultimately opted to seek a court order for bulk cell phone tower data instead.

The post ATF cancels controversial commercial geolocation contract appeared first on CyberScoop.

Russia uses Cellebrite to break into human rights activist’s phone, even after cancellation of contract

25 June 2026 at 10:52

Russian authorities used Cellebrite phone-cracking technology to break into a device belonging to a prominent domestic human rights activist they arrested and imprisoned, despite the company canceling its contract with the Russian government, according to a report published Thursday.

The University of Toronto’s Citizen Lab reached its conclusions after analyzing a phone belonging to Andrey Pivovarov and examining court documents he provided confirming the usage of Cellebrite’s UFED product.

Pivovarov was arrested in March 2021, sentenced in 2022 and released in 2024 as part of a prisoner exchange. Citizen Lab found evidence that authorities accessed his phone around June 2021 while the phone was in Russian government hands.

Investigators also said it appears Russian authorities might have used information it got from Pivoarov’s phone to surveil other regime opponents, combining information in the court documents with the later targeting of fellow dissident Anastasiya Burakova in a hacking campaign linked to Russia’s Federal Security Service (FSB).

“The historic architecture of Cellebrite forensic systems means that much of the functionality in the UFED product has continued to operate long after updates cease,” Citizen Lab said in its report. “Furthermore, Cellebrite systems have historically featured an offline mode. Consequently, the way Cellebrite’s technology was designed appeared to make it difficult for the company to meaningfully cut off problematic customers.

“While Cellebrite has argued that its cancellations in Russia … went beyond what was legally required, this investigation contributes evidence that the contract cancellation did not immediately block Russia from leveraging Cellebrite’s tools for political persecution,” it continued.

Cellebrite provided a response to Citizen Lab’s report, saying that Cellebrite’s technology would be ineffective in Russia today.

“Any use of legacy Cellebrite hardware in Russia after March 2021 is entirely unauthorized,” Cellebrite spokesperson Victor Cooper told CyberScoop, echoing the Citizen Lab response. “The Cellebrite hardware previously sold, prior to March 2021, would now be incompatible with modern devices and would operate without our technical support, our consent or any legal sanction from Cellebrite. Rapid technology advances render legacy digital forensic hardware and software ineffective within a short period of time. Russia remains permanently on our restricted-customer list.”

The Russian Embassy in Washington, D.C. did not immediately respond to a request for comment.

The post Russia uses Cellebrite to break into human rights activist’s phone, even after cancellation of contract appeared first on CyberScoop.

Court rules SAVE database illegal, orders it dismantled

By: djohnson
22 June 2026 at 18:07

A federal court ruled Monday that the Trump administration’s national voter database violates federal privacy laws, interferes with Americans’ right to vote, and must be dismantled.

In the ruling, Judge Sparkle L. Sooknanan of the District Court of Washington D.C. wrote that records reviewed by the court show federal agencies knew that the SAVE voter database violated federal laws like the Privacy Act, the Social Security Act and the Administrative Procedure Act, but were “scrambling” to comply with President Trump’s executive order to create a system for mass voter verification.

That pressure resulted in agencies “haphazardly” combining and repurposing the personal information of millions of Americans from different government databases, including citizenship data they knew was unreliable.

“The Court therefore sets aside and vacates the 2025 SAVE modified system and the related notices because they were contrary to law, arbitrary and capricious, in excess of statutory authority, and without observance of procedure required by law,” Sooknanan wrote.

The League of Women Voters, its local affiliate groups and the Electronic Privacy Information Center filed the lawsuit last year. They argued the administration violated privacy laws that restrict the government’s ability to collect or combine private data without congressional authorization.

Sooknanan wrote that the SAVE database violates a prohibition in the Social Security Act against the disclosure of Social Security numbers and other related SSA records as well as substantive and procedural protections in the Privacy Act, which prevent the non-consensual disclosure of certain information both by federal agencies and between federal agencies and require notice and comment.

The court also ruled that SAVE violates the Administrative Procedures Act, which governs how the federal government develops regulations and makes official decisions to ensure they’re fair and impartial.

Sooknanan had earlier declined to rule the database illegal under the Administrative Procedures Act, saying the plaintiffs had failed to prove the data would cause  irreparable harm. In her final ruling, she changed course, writing that the states have since run their voter rolls through the federal government’s modified SAVE system, and some voters have been wrongfully identified as non-citizens and had their voter registrations canceled.

“All in all, the federal government has knowingly trampled on the privacy rights of American citizens in a manner that threatens the sacred right to vote,” Sooknanan wrote. “This Court cannot stand idly by while that happens.”

The ruling reinforces longstanding objections from former government officials and privacy experts over the past year, who have said Congress has repeatedly passed privacy laws explicitly to prevent the executive branch from using Americans’ data in ways not proscribed through law. That is what DHS did last year when it took SAVE, a database meant to process government benefits for legal immigrants, and combined it with data from the Social Security Administration and other agencies to create a new massive database of American voters and their citizenship status.

John Davisson, deputy director of enforcement at EPIC, celebrated the decision in a statement, saying the ruling “underscores that government agencies must follow the law, defend privacy and remain accountable to the public they serve.”

 “Today’s decision is a victory for us all. By halting the illegal consolidation of sensitive personal data across federal agencies, the court has safeguarded not only our privacy rights but also the bedrock of our democracy: the right to vote,” said Davisson. 

The post Court rules SAVE database illegal, orders it dismantled appeared first on CyberScoop.

Congress tees up No FAKES Act, aiming at AI-generated deepfakes

By: djohnson
18 June 2026 at 16:20

The Senate Judiciary Committee approved a new bill this week that seeks to prevent unauthorized deepfakes of American artists, performers and public figures. While the bill sailed through a committee voice vote, both Senators and outside groups say they’re worried it could become a tool for the powerful to quash free speech. 

The NO FAKES Act, introduced by Sens. Chris Coons, D-Del., and Marsha Blackburn, R-Tenn., would give Americans near-exclusive rights to their own digital AI replicas, and those rights live on, passing to heirs, executors and estates for at least 70 years after an individual dies.

While living, creators would be able to essentially license their likeness and image to others, over 10-year contracts for adults and 5 years for minors.

It would also permit individuals to sue anyone who uses their AI-generated image without permission, and pay up to $750,000 for violations. Blackburn submitted letters of support for the bill from more than 40 groups, including the Screen Actors Guild – American Federation of Television and Radio Artists, the American Medical Association, Creative Artists Agency, the Broadcasters’ Associations and the Human Artistry Campaign.

“It is imperative that we put this national standard in place for voice and visual likeness protection of creators, to protect from proliferation of harmful AIgenerated deepfakes that are created without their consent,” said Blackburn in a Thursday markup of the bill.

The introduction of consumer-grade AI tools has made it trivial to create convincing deepfakes of real individuals and public figures. The harms are well documented: bad actors have used them to create nonconsensual pornography or sexualized media of people they know, create child sexual assault material (CSAM) , and blackmail or humiliate individuals.

Artists have faced real challenges in the AI era when it comes to controlling their digital likeness. Last year, the Better Business Bureau warned that its Scam Tracker had been flooded with complaints about AI-celebrity endorsement scams. These included  deepfakes of Oprah Winfrey promoting weight loss products, Kim Kardashian pleading for donations to fight California wildfires, and pop star Taylor Swift and celebrity chef Gordon Ramsay endorsing cookware.

In the political arena, candidates now create deepfakes of their political opponents, putting words into their mouths or placing them in embarrassing or humiliating situations. Online, disinformation actors have repeatedly spread AI-generated videos and images of politicians like Donald Trump, Kamala Harris, and even regional or local politicians saying or doing scandalous things.

The bill represents one of the most aggressive attempts by U.S. policymakers to protect the digital commercial rights of artists and public figures. New York, for instance, passed a law this month that requires film and television advertisers to publicize when they’re using deepfakes in ads, but does not create a similar copyright regime for artists’ likeness. A Tennessee law, The ELVIS Act, that prohibits the unauthorized use of an individual’s voice and likeness and creates secondary liability for large platforms that publish or distribute the content.

The NO FAKES Act faces opposition from an alliance of tech business and digital rights groups. They argue the bill  fails to balance the commercial rights of artists to control their own image with longstanding First Amendment constitutional rights to free speech and parody.

Amy Bos, vice president of government affairs at NetChoice, a trade association for online businesses, said that while her group supports legislation that prevents unauthorized AI generated deepfakes, “good intentions do not make good law.”

“As written, this bill creates a dangerous financial incentive for platforms to aggressively over-remove lawful content, burdens creators with an unworkable counter-notification system, and fails to deliver the uniform national standard its sponsors promised,” Bos said in a statement.

Many digital civil groups agree with that view. A broad coalition of policy groups – including the American Civil Liberties Union, the R-Street Foundation, the Center for Democracy and Technology, the Electronic Frontier Foundation and others – wrote to the Senate Judiciary Committee this week to urge members to oppose the bill in its current form.

They argued the current bill creates a “Heckler’s veto” over most online content, allowing artists, public figures and advocacy groups to flood the notification system with takedown requests for content they don’t like. Similar to a law already on the books, the Digital Millenium Copyright Act, virtually all the incentives in the bill push platforms to be overaggressive in taking down content, regardless of whether it violates the law or not.

This approach could end up quashing not just unauthorized ads but also scores of other likely First Amendment protected uses, such as education, humor, satire and parody.

In 2023, a humorous AI-generated image of Pope Francis in a puffy Balenciaga jacket went viral. Under the NO FAKES Act, the coalition says that post would be illegal for anyone to post until nearly 2100.

In the political arena, both Republicans like Trump and Democrats like California Governor Gavin Newsom have used AI deepfakes to skewer their political opposition.

“A law that undermines free expression will struggle to survive constitutional review,” the groups wrote. “In the meantime, it can do lasting damage, both to lawful speech and to the autonomy of the people it claims to protect. We urge the Committee not to advance the NO FAKES Act in its current form, to examine how existing state and federal law already addresses the legitimate harms the bill seeks to address, and to pursue narrowly tailored solutions only where a genuine gap remains. We would welcome the opportunity to assist.”

While the bill passed by voice vote and with broad support, multiple Republican and Democratic members of the committee said they had similar concerns and expressed a desire to continue tweaking the bill further before passage into law.

In the Senate meeting, Coons appeared to dismiss those charges, arguing that changes made to the bill ahead of markup adequately address any First Amendment concerns.

“I want to be clear, NO FAKES includes features that protect free speech,” Coons claimed. “Parody, satire documentaries, biopics, newscasts, they’re all protected and we built in appropriate counter notification processes and exempted research libraries and archives.”

The post Congress tees up No FAKES Act, aiming at AI-generated deepfakes appeared first on CyberScoop.

US, France, and Italian authorities shut down massive deepfake porn site

By: djohnson
12 June 2026 at 14:21

The U.S. Departments of Justice and Homeland Security seized multiple internet domains this week, accusing them of being used to publishing thousands of AI or digitally-altered images and videos of nude women.

The domains, CFAKE.com and SOCFAKE.com, specialized in digital forgeries that “were made to appear to be sexual images of famous women, including politicians, first ladies of multiple countries, royalty, journalists, television presenters, athletes, entertainers, and others” either nude or engaged in sexual activity,” according to a Department of Justice release.

In addition to creating sexual images and videos of women without their consent, the service allowed people to browse by topics, including “rape,” “forced,” and “degradation.”

That description comes from a Department of Justice release describing the contents of its probable cause affidavit and search warrants. CyberScoop has not viewed the court documents.  

The sites were seized under the TAKE IT DOWN Act, a law passed last year giving federal authorities the ability to criminally prosecute those who create and distribute deepfake porn. The law was a rare moment of bipartisan agreement in Washington D.C., gaining support from both Democrats and Republicans who said their constituents were demanding tougher laws to curb the use of AI to create nonconsensual deepfake porn.

The operation marks one of the largest seizures since the law went into effect. The details of the operation disclosed by the government show how creators of deepfake porn rely on a web of international assets and infrastructure to evade law enforcement.

Robert Fraiser, U.S. Attorney for the District of New Jersey, said U.S. authorities worked in coordination with law enforcement agencies in France and Italy. According to U.S. officials, they were first notified about the website by Italian Polizia de Stato, while a parallel investigation run by the Paris Public Prosecutor’s Office in France resulted in the arrest of a suspect connected with the site, along with seized cryptocurrency funds.

“These seizures stopped a website that trafficked in humiliation, exploitation, and the violation of personal privacy on a massive scale,” said Frazer in a statement. “For the victims whose images were distributed without their consent, the harm is not virtual — it is deeply personal and often enduring.”

According to the Paris Prosecutor’s Office, Cyrille B., a 47-year-old French national was arrested and accused of being an administrator for CFAKE. A search of his home in Nice found computer equipment related to the site and a little more than $48,000 in Ethereum cryptocurrency that they said came from the site’s advertising.

The French investigation identified 300,000 images, 7,000 videos depicting 14,000 individuals from different countries. The site had approximately 200,000 user accounts, 4 million views per month and uploaded 50 pieces of new content every day.

The suspect had no prior criminal record, and will go to trial on July 7. The charges carry potential penalties of up to seven years in prison and €500,000.

U.S. Immigration and Customs Enforcement’s Homeland Security Investigation division is leading the federal investigation, in conjunction with the U.S. Attorney’s office for New Jersey.

The post US, France, and Italian authorities shut down massive deepfake porn site appeared first on CyberScoop.

Meta accuses NSO Group of defying spyware injunction, files contempt of court complaint

8 June 2026 at 13:11

Meta said Monday that it caught a spearphishing campaign linked to spyware maker NSO Group despite a court injunction, prompting the tech giant to file a contempt-of-court complaint.

The company won a civil case last year against NSO Group barring it from targeting WhatsApp users and securing $168 million in damages, although NSO Group has been appealing the ruling.

But Meta says NSO Group, makers of the Pegasus spyware, isn’t honoring the permanent injunction.

“We successfully disrupted NSO-linked social engineering attempts, after investigating user reports,” it said in a blog post. “They tried to trick people into clicking on malicious links to drive them to external websites outside of WhatsApp, similar to previously reported 1-click phishing campaigns linked to NSO. We also caught them creating test accounts and groups on WhatsApp, which we took down.”

Meta said the campaign resembled spyware infections that hit journalists and activists in Jordan from 2019 to 2023.

NSO Group didn’t respond to requests for comment about Meta’s accusations.

One top researcher who tracks spyware said NSO Group’s actions are an argument for keeping them on the U.S. sanctions “entity” list that the company has fought to be removed from since its designation in 2021.

“NSO’s own actions make the strongest argument for why they should stay on the Entity list,” John Scott-Railton, senior researcher at the University of Toronto’s Citizen Lab, wrote on social media. “And reaffirm that the decision to put them there was the right one.”

Meta made the same argument.

“When a malicious company on the US government’s Entity List continues to defy US courts, existing restrictions must remain firmly in place,” it said in its blog post. “Easing them would undermine US national security and put American companies and billions of people worldwide who depend on secure communications at risk.”

Lawmakers have sought information on the federal government’s prospective use of NSO Group tech and other kinds of spyware, despite a blacklist, given close ties between the company’s new executive chairman and President Donald Trump.

The post Meta accuses NSO Group of defying spyware injunction, files contempt of court complaint appeared first on CyberScoop.

Here’s how the FTC plans to enforce the Take It Down Act

By: djohnson
15 May 2026 at 15:54

The Federal Trade Commission is set to begin enforcing a key provision of the Take Down Act on May 19, requiring websites and online services to remove nonconsensual deepfake media within 48 hours after a victim’s notice—or risk fines and FTC investigation.

The law, passed by Congress last year, allowed law enforcement to immediately prosecute individuals who create and post such content online. But platforms and websites that host the material were given a yearlong runway to build out their reporting and takedown system. Under the enforcement regime taking effect, businesses that fail to remove flagged media within the 48-hour notification window could face fines and an investigation from the FTC.

This week, FTC Chair Andrew Ferguson sent letters to private-sector companies detailing how the commission intends to police compliance once enforcement begins. The FTC set a maximum civil penalty of – $53,088 per violation for companies that don’t take down content as required, and Ferguson’s letter outlines other requirements, including that companies make it easy and convenient for users to submit takedown requests.

“We stand ready to monitor compliance, investigate violations, and enforce the Take It Down Act,” Ferguson said in a statement. “Protecting the vulnerable—especially children—from this harmful abuse is a top priority for this agency and this administration.”

Ferguson’s letter sheds new light on how the FTC will enforce content takedowns under the law.  Both nonconsensual intimate imagery posted online using real photos of other individuals as well as AI-generated or modified “digital forgeries” would be considered violations.

Companies must also make it easy for victims without accounts to report potential violations, details their reporting and removal program on their website “in plain language” and provide “clear and conspicuous” notice to users about how to request removals.

According to the FTC, the law covers websites, apps, social media, image or video sharing services and gaming platforms. Ferguson’s letters were addressed to a who’s who of tech and social media companies, including Amazon, Alphabet, Apple, Automattic, Bumble, Discord, Match Group, Meta, Microsoft, Pinterest, Reddit, SmugMug, Snapchat, TikTok and X.

Earlier this year, Grok, the AI service that X users have access to, was used to flood the social media site with nonconsensual, sexualized deepfakes of real people. Elon Musk, X’s owner, initially brushed off critics but has since been hit with multiple criminal and civil investigations stemming from the incident, as well as lawsuits and calls from some world leaders to ban the app entirely.

 The FTC is also recommending that companies implement hashing technologies “to prevent the reappearance of intimate content you already removed from your platform” and share their findings with nonprofits like the National Center for Missing and Exploited Children and StopNCII.org to track across other parts of the internet.

Becca Branum, director of the Free Expression Project at the Center for Democracy and Technology, told CyberScoop that some elements of the FTC’s approach – like requiring clear and simple reporting options for victims – aligns with best practices established by civil society groups.

But she also said the FTC’s role under the Take It Down Act is materially different from anything the commission has done before. The sheer scale of enforcement and monitoring will require human and technical resources on par with those of major social media companies.

“I’m very concerned about the FTC and its ability to fairly enforce this law,” said Branum. “They are now in the business of regulating content moderation. That is hard work and not something they’re used to doing.”

Some legal and privacy experts pointed to the large financial penalties set by the FTC as a sign that policymakers are looking to put real teeth behind enforcement. Those penalties could pile up quickly if a business is hosting or publishing multiple copies of the same flagged media and declines to remove it within two days.

“For covered platforms, compliance with the Act is critical given the FTC’s emphasis on enforcement – reflecting White House priorities – and potential civil penalties up to $53,088 per violation,” wrote privacy attorneys Duane Pozza and Ian Barlow.

But Branum said the hefty fines also emphasize “just how much incentive will be in place for platforms to take anything that comes down the complaint line.”

While the Take It Down Act is designed to force companies to investigate claims and remove violating content, the regulatory and financial incentives push them to simply remove almost all content reported by default. That approach, which many of the same tech companies have taken under laws like the Digital Millenium Copyright Act, can be exploited by bad faith actors seeking to shut down legal speech or content online.

“If you think there’s any given post [where] if you ask an attorney is it worth $53,000 for me to keep this post up, the answer is always going to be taken it down,” Branum said. “I can’t imagine any service wanting to risk that type of fine on edge cases or anything they can’t verify or account for within 48 hours.”

The post Here’s how the FTC plans to enforce the Take It Down Act appeared first on CyberScoop.

Google and Amnesty International teamed up to make it harder for spyware vendors to hide

12 May 2026 at 13:00

Google launched a feature for Android phones Tuesday for dedicated forensic logs about intrusions from sophisticated attacks like those by spyware vendors, in what design partners at Amnesty International hailed as an important first.

The tech giant has been ramping up the new feature, Intrusion Logging, since last year, and has now begun rolling it out.

“The new intrusion logging feature promises to be a major aid to digital forensics researchers undertaking investigations into sophisticated attacks on Android devices,” Amnesty International said in a Tuesday technical briefing. “This is the first time a major device vendor has released a feature specifically to enhance the ability to forensically detect and respond to advanced digital threats.”

To date, independent investigators have relied on records and often short-lived log files that weren’t meant for forensic use, and Amnesty said surveillance groups have grown increasingly aware of those forensic efforts. Intrusion Logging, a feature of Android Advanced Protection Mode, is designed specifically to keep track of possible intrusions for forensic purposes. It keeps records of security incidents like device unlocking, physical access and spyware installation and removal.

Google’s annual security and privacy update for Android phones mentions the feature and its development with Amnesty International, Reporters Without Borders and others. It also touts new protections against banking scam calls, other features for detecting suspicious activity on Android phones, additional privacy safeguards and more.

The firm has been working on the feature since announcing it last year.

“Intrusion Logging enables persistent and privacy-preserving forensics logging to allow for investigation of devices in the event of a suspected compromise,” wrote Eugene Liderman, director of Android security and privacy.

Intrusion Logging joins an expanding slate of features from tech companies to fight sophisticated attacks like those from commercial spyware, among them Apple’s Lockdown Mode and Memory Integrity Enforcement and WhatsApp’s Strict Account Settings.

Intrusion Logging “promises to help shift the balance to the advantage of defenders, providing civil society investigators with the key evidence needed to detect and expose some of the most advanced attacks facing journalists and activists,” said Donncha Ó Cearbhaill, head of the Amnesty International Security Lab, “With Intrusion Logging Google is the first major vendor to proactively address to challenge of detecting advanced attacks on device. By making more consensual forensic data available for researchers, we can make life more difficult for attackers and help civil society seek accountability when their devices are unlawfully targeted by spyware and mobile data extraction tools.”

The feature has some limitations, though, Amnesty said in its technical briefing. It requires Android 16 and is only available for now on Pixel devices; the device has to be linked to a Google account, and the logs may include sensitive information, like browser navigation history, so secure sharing of the logs is important.

The logs may also be deletable by attackers, Ó Cearbhaill told CyberScoop, but he said he understands there are plans to strengthen protections against that in future versions. And lots of attacks would be detectable in the logs where attackers wouldn’t necessarily have the root access needed to try to delete logs, he said.

To enable Intrusion Logging, users need to be using Android Advanced Protection Mode, and can find the feature at Settings > Security & privacy > Advanced Protection > Intrusion Logging. If users suspect some kind of security incident, they’ll need to export and share the logs with a forensic analyst.

The post Google and Amnesty International teamed up to make it harder for spyware vendors to hide appeared first on CyberScoop.

One House Democrat is pressing Commerce on the government’s spyware use

7 May 2026 at 06:00

A House Democrat who’s been at the forefront of congressional efforts to scrutinize the federal government’s use of commercial spyware wants the Commerce Department to brief Capitol Hill amid apprehension that the Trump administration might further embrace the technology.

Rep. Summer Lee, D-Pa., sent a letter to the department Thursday seeking a briefing on several developments stemming from Immigration and Customs Enforcement acknowledging its use of Paragon’s Graphite spyware, as well as an American company purchasing a controlling stake in Israel’s NSO Group. The Commerce Department sanctioned NSO Group under former President Joe Biden after widespread abuse allegations, including eavesdropping on government officials, activists and journalists.

“The Trump Administration appears to be broadly receptive to using commercial spyware to infiltrate cell phones and allowing U.S. investment in sanctioned spyware companies like NSO Group,” Lee wrote in her letter to Commerce Secretary Howard Lutnick, which CyberScoop is first reporting.

NSO Group’s new executive chairman, David Friedman, is a former Trump ambassador to Israel and was his bankruptcy attorney. He has said in November that he expects the administration will be “receptive” to using NSO Group tech.

“Given those close ties between NSO Group and the Trump Administration, and the serious concerns about how NSO’s technology could be used to spy on Americans, we write to request information regarding the purchase of NSO Group by an American company and the potential usage of NSO Group spyware by federal law enforcement,” wrote Lee, who sits on the Oversight and Government Reform panel and is the top Democrat on its Federal Law Enforcement Subcommittee.

Lee was one of the authors of a recent Democratic letter seeking confirmation of ICE’s use of Paragon’s Graphite, which ICE acknowledged. But they criticized the administration for not answering all their questions, in addition to being outraged.

In her latest letter, Lee asked the Commerce Department to brief Oversight and Government Reform Committee staff about internal department deliberations, Commerce communication with the White House and any outside conversations — including with Friedman — about government use of NSO Group technology or any other commercial spyware, and American investment in NSO.

NSO Group “appears to view the Trump administration as friendly to its interests in the United States, pitching itself as a vital tool for the U.S. government to safeguard national security,” Lee wrote, citing company court filings that it “is reasonably foreseeable that a law enforcement or intelligence agency of the United States will use Pegasus.”

The Biden administration sanctions, and court losses in a case against Meta, represented setbacks for NSO Group’s ambitions. And prior to the U.S. investment firm controlling stake purchase last fall, the Commerce Department under Trump rebuffed efforts to remove NSO Group from its sanctions list.

But the tens of millions of dollars worth of investment, following news that Israel had used Pegasus to track people kidnapped or murdered by Hamas, was a boon.

NSO Group maintains that its products are designed only to help law enforcement and intelligence fight terrorism and crime, and that it vets its customers in advance as well as investigates misuse. News accounts and other investigations have turned up a multitude of abuses.

There have been scattered reports of U.S. flirtation with using NSO Group technology. The FBI acknowledged it had bought a Pegasus license, but stopped short of deploying it. The Times of London reported that “it is believed” the Central Intelligence Agency used Pegasus spyware as part of a rescue mission last month for a U.S. airman downed in Iran.

You can read the full letter below.

The post One House Democrat is pressing Commerce on the government’s spyware use appeared first on CyberScoop.

A college student is suing a dating app that allegedly used her TikTok videos to target men in her dormitory

By: djohnson
4 May 2026 at 12:02

A 19-year-old woman is suing the makers of a dating app, alleging they took a video she posted online, repurposed it without her consent into an advertisement for the app, then used geofencing to target that ad to people in her area. 

According to the lawsuit filed Apr. 28 in Tennessee and an interview with her lawyer, the company allegedly used geotargeting to serve the ads on platforms like Snapchat to users near her, including men in her own dormitory. 

The allegations, if proven, offer another example of how modern technology has made it easier than ever today for bad actors to imitate, objectify, profit off and harass individuals, often women. Recent laws like the Take It Down Act have focused particularly on the use of AI to create sexualized imagery of their victims. In this case, the lawsuit alleges that Meete used not AI, but simple video editing, a voiceover and geofencing to create the same kind of deception. 

 On the day of her high school graduation, Kaelyn Lunglhofer posted a brief video to TikTok, wearing an orange outfit and saying a few words to her followers over background music. She went on to attend the University of Tennessee in the fall, where she began building a following as a TikTok influencer.

The complaint alleges that the makers behind the dating app Meete took that video without Lunglhofer’s consent, overlayed it with graphics advertising the app, and added a voiceover to make it appear she was saying “Are you looking for a friend with benefits? This app shows you women around you who are looking for some fun. You can video chat with them.”

Abe Pafford, Lunglhofer’s attorney, told CyberScoop that his client had no idea Meete was using her likeness until a male student in her dormitory told her he had repeatedly seen her in ads for the app on his Snapchat shortly after the two had met. 

Pafford called it “implausible” that this was a coincidence, pointing to Meete’s premise of connecting users with nearby women and the precision of geofencing technology. Before filing the case, Pafford’s law firm hired an investigative firm to gather additional evidence.

“I think the idea is they want[ed] viewers of these advertisements – and candidly this is pretty clearly targeted at male viewers – to have their eye caught by someone they may know or recognize or think they may have seen around, and that’s part of what makes it so disturbing,” he said.

Pafford said he believes Lunglhofer is far from the only person whose image Meete has misappropriated, and that most victims likely have no idea it’s happening. Lunglhofer herself only had evidence because the student who told her had saved recordings and screenshots of the ads featuring her video.

“The bottom line is we think there are likely others that have been victimized in a similar way, but finding out who they are and landing on tangible proof of that can be challenging,” he said.

After this story was published, Snap told CyberScoop it is investigating.

“Snap’s advertising policies require that advertisers have all necessary rights to the content in their ads, including the rights to any individuals featured,” Snap spokesperson Ahrim Nam said in an email. “Using someone’s likeness without their consent is a violation of our policies. Upon learning of these allegations, we are actively reviewing the matter and will take appropriate action.”

The lawsuit cites alleged violation of multiple federal and state laws, including the Lanham Act, the primary U.S. law governing trademark rights. The suit also alleges violations of Tennessee state law under the ELVIS Act, which prevents the unauthorized use of image or likeness for artists and musicians, and Tennessee common laws for defamation and right of publicity.

Lunglhofer is seeking $750,000 in punitive damages, as well as any revenue tied to the ads featuring her likeness. Pafford said that the advertisements damaged her online brand and reputation while also putting her at risk of harassment or falsely implying she was endorsing a local dating service and was open to casual hookups.

“It’s really kind of grotesque and it’s also kind of dangerous,” he said. “Someone may not be aware that this is happening and they’re targeted in this way, but you can put people at risk in ways that are really troubling if you stop to think about it.”

The suit names Quantum Communications Development Unlimited, based in the Virgin Islands, as well as Chinese companies Starpool Data Limited and Guangzhou Yuedong Interconnection Technology, as defendants. A judge has ordered representatives from all three to appear for depositions in the United States.

Quantum Communications Development Unlimited has a sparse internet footprint: their website consists of a single page with a message written in broken English and an email address that no longer appears to work. Efforts by CyberScoop to reach the company and other defendants for comment were not successful. The company is listed as Meete’s publisher on Apple’s App Store, where it describes the app as “a space where you can be yourself and meet people” and promises “safety and respect first” — adding that “Meete provides a secure environment where your privacy and safety are our top concerns.”

The description also claims the app adheres to Apple’s safety standards, citing a “Zero-Tolerance Policy regarding objectionable content and abusive behavior.” Listed safeguards include “24/7” manual reviews by moderation teams, instant reporting and blocking of other users, and AI filtering “to detect and prevent harassment before it happens.”

On Meete’s Google Play Store page, user reviews accuse the app of failing to match them to nearby users and being largely populated by bots posing as women to sell in-app currency.

Pafford acknowledged that the defendants being based overseas complicates efforts to hold them accountable under U.S. law, but argued that Meete is clearly designed to operate in the United States. The companies behind the app have filed U.S. patents and trademarks, for their business, and distribute their app through the Apple and Google Play Stores while advertising on major U.S. social media platforms like Snapchat.

Apple and Google did not respond to a request for comment.

You can read the full lawsuit below.


5/05/26: This story was updated to include comment from Snap received after publication.

The post A college student is suing a dating app that allegedly used her TikTok videos to target men in her dormitory appeared first on CyberScoop.

Congress kicks the can down the road on surveillance law (again)

30 April 2026 at 16:53

Congress extended a controversial surveillance law for 45 days on Thursday, hours before its latest expiration following an earlier extension.

The Senate passed — then the House cleared — a 45-day extension of Section 702 of the Foreign Intelligence Surveillance Act, which authorizes warrantless surveillance of foreign targets. But those targets are sometimes communicating electronically with Americans, and intelligence officials can search the database using their identifying information, which has long given privacy groups and privacy-minded lawmakers heartburn.

The 45-day reprieve gives lawmakers more time to hammer out a lasting deal, and comes after the leaders of the Senate Intelligence Committee agreed to send a letter to the Director of National Intelligence and attorney general, seeking swift declassification of a letter on a classified ruling from the Foreign Intelligence Surveillance Court.

Sen. Ron Wyden, D-Ore., had sought release of that opinion, and had resisted giving unanimous consent for the latest short-term extension to move forward until Senate Intelligence Chairman Tom Cotton, R-Ark., and top panel Democrat Mark Warner of Virginia agreed to send the letter.

A declassification review was already underway, but the Cotton-Warner letter states that “We expect that this declassification review will be completed and the FISC opinion released publicly within 15 days,” according to Wyden, speaking on the Senate floor.

The March 17 opinion reportedly came with annual recertification of the warrantless surveillance program. The Justice Department is appealing that ruling because it blocked them from using certain tools to analyze communications.

“A few weeks ago, the Foreign Intelligence Surveillance Court found major compliance problems related to the surveillance law known as section 702,” Wyden said earlier this month. “These compliance problems are directly related to Americans’ Constitutional rights.”

Senate Majority Leader John Thune, R-S.D., said the extension will give lawmakers additional room to hold “discussion on reforms.”

The House this week had passed a 3-year reauthorization with some changes to the surveillance program, but key to doing so was leadership’s agreement to attach legislative language on a separate matter that would ban a central bank digital currency. Thune had said that language was going nowhere in the Senate.

On Thursday, the House voted 261-111 to extend the law for 45 days. President Donald Trump has sought a “clean” 18-month reauthorization of the surveillance powers.

The extension continues a perennial ritual for the Hill when it comes to Section 702: A deadline looms, and Congress kicks the can down the road repeatedly.

The post Congress kicks the can down the road on surveillance law (again) appeared first on CyberScoop.

❌
❌