❌

Reading view

There are new articles available, click to refresh the page.

Phone-hacking company that won U.S. security agency contracts hid Russian ownership, DOJ alleges

Law enforcement has arrested two leaders of a Russian-owned phone hacking company used by Kremlin agencies who allegedly masked its foreign ownership from the U.S. Defense Department, Department of Homeland Security and others to win millions of dollars worth of contracts, the Justice Department announced Wednesday.

Lee Reiber of Boise, Idaho, the CEO of Oxygen Forensics (Oxygen US), was arrested in his home state and Oleg Davydov, one of five Russian nationals whom DOJ said actually controlled the company, was arrested in London, from where the department plans to seek his extradition. They face charges of conspiracy to commit wire fraud.

Publicly, Oxygen went to great lengths to present Reiber as the true leader of a company based in Alexandria, Va., asserting that the company was not controlled by Russian-based executives, according to a criminal complaint., While the company told government agencies it was U.S.-owned, Russian officials with the company repeatedly overruled him, the complaint alleges. 

Oxygen’s business aims were complicated in 2022 after the United States expanded sanctions against Russia following its invasion of Ukraine. That’s when the company installed Reiber as CEO and removed the owners from public corporate filings. An unnamed co-conspirator in the complaint nonetheless said that “fateful decisions will be made by” five shareholders, including Davydov. 

Since March 2022, Oxygen has sold its forensics software to the U.S. Secret Service, Homeland Security Investigations, the DHS inspector general and DOD. After the 2022 sanctions, Oxygen won more than $2 million in contracts and purchases from the Secret Service and its National Computer Forensics Institute. Reiber asserted U.S. ownership as recently as February of this year to the NCFI, according to the complaint.

Reiber knew the company had to conceal its true ownership, the complaint states. Oxygen and its competitors have quarreled in the media and in courts. Oxygen in 2023 faced accusations that Oxygen US and Oxygen Russia were both using software code reverse-engineered from Elcomsoft’s products. Oxygen Russia’s customers included the Russian Federal Security Service (FSB). 

“The accusation mattered to Reiber because answering it truthfully would have required disclosing that Oxygen US and Oxygen Russia sold the same software, developed by the same team, and were owned by the same people,” the complaint reads, citing email correspondence.

Knowing Oxygen’s actual ownership configuration would’ve changed the equation for the government agencies, according to the complaint.

“Procurement officials at the U.S. government customers have represented that they would not have awarded or renewed contracts for the forensic software had they known that OxygenUS was a Russian-owned company,” the complaint reads.

Natalia Krapiva, senior tech-legal counsel at Access Now, celebrated what she nonetheless called an overdue move from DOJ.

“For years, civil society warned that Oxygen Forensics was owned and built from Russia. Now the Justice Department confirmed it,” Krapiva told CyberScoop. “We applaud the U.S. government for taking this crucial step, but the fact that it took so long is both a national security and a human rights scandal.”

“The same technology that extracted data for U.S. investigations has been used inside Russia to jail journalists, activists, and peaceful dissenters. And it doesn’t stop at the U.S. border,” she continued. “We call on the U.S. and over 100 governments using this technology to immediately sever all ties to the company, implement sanctions, and conduct full investigation(s) of how Russian tech designed for the FSB spent all these years inside their sensitive law enforcement operations.”

Court-listed attorneys for Reiber listed in court documents didn’t respond to requests for comment. No attorney for Davydov could be located.

The DOJ in its announcement specified that “The complaint does not allege that the software contained malicious code or that it was used to gain unauthorized access to any customer’s computer systems or data.”

The post Phone-hacking company that won U.S. security agency contracts hid Russian ownership, DOJ alleges appeared first on CyberScoop.

FTC rescinds policy statement requiring health apps to notify customers after a breach 

The Federal Trade Commission has rescinded a Biden administration-era policy statement that asserted coverage over health and fitness apps under federal data breach notification regulations.

In a half-page statement posted Wednesday, the FTC said it “has determined that the statement – contentious at the time of issuance – provided minimal benefit and has been superseded by rulemaking.” The commission said the statement’s withdrawal also aligns with guidance from the White House to pursue a deregulatory agenda and avoid “unnecessary use of subregulatory guidance.”

Unlike a formal regulation, which carries the legally binding force of law created through a public rulemaking process, an agency policy statement is non-binding guidance that merely outlines how officials intend to interpret and enforce existing statutes. An FTC spokesperson told CyberScoop that the underlying policy including health apps remains codified through a regulatory update in 2024.

“Each of these reasons is independently sufficient to support the Commission’s decision to rescind this policy statement,” the FTC continued. “Parties understand that guidance generally creates neither substantive rights nor binding obligations.”

The initial policy statement, passed in a divided 3-2 vote during the Biden administration under then-FTC chair Lina Khan, asserted that health apps, fitness trackers and other connected devices were covered under an existing regulation requiring companies to disclose health-related data breaches to customers.

The interpretation targeted any “vendor of personal health records that contain individually identifiable health information created or received by health care providers.” Many health and fitness apps ask users to upload medical records and other health-related data in order to function effectively.

More recently, health and cybersecurity experts have pointed to similar regulatory gaps that exist for AI companies that make healthcare specific models that can answer questions, examine patient records and dispense medical advice to users.

The underlying Health Breach Notification Rule also triggers automatic notification when a covered entity suffers a breach of security, which can include both standard breaches and data losses as well as the disclosure of sensitive health information to third parties without users’ authorization. That would potentially put health apps on the hook for selling customer data to third-party data brokers and other entities-a standard formally codified in a binding 2024 FTC rule update.

A Sept. 2021 statement by the FTC justifies its interpretation by citing digital security and privacy provisions in the 2009 American Recovery and Reinvestment Act as well as gaps in major health privacy laws like the Health Insurance Portability and Accountability Act that allow such apps to handle and store sensitive personal health records or data without being subject to the same breach notification requirements as other health care organizations.

The FTC said it intended to enforce health apps under the law and subject violators to daily fines of $43,792 per violation.

“As many Americans turn to apps and other technologies to track diseases, diagnoses, treatment, medications, fitness, fertility, sleep, mental health, diet, and other vital areas, this Rule is more important than ever,” the FTC said in 2021. “Firms offering these services should take appropriate care to secure and protect consumer data.”

This week, the FTC voted unanimously to rescind the policy statement. But that unity is in part because President Trump fired Democratic FTC commissioners who voted in favor of the original rules, while advancing party allies as their replacements.

The two dissenting votes against the policy statement in 2021 were from Republican-appointed commissioners casting their dissents under a Democratic executive. Andrew Ferguson, a Republican commissioner nominated by former Democratic President Joe Biden, is now chair of an FTC filled entirely with Republican appointees, and has defended President Trump’s authority to fire and hire new commissioners at-will.

Update, 9/11/26, 4:15 p.m.: This story has been updated to clarify the impact of the FTC’s policy statement revision.

The post FTC rescinds policy statement requiring health apps to notify customers after a breach  appeared first on CyberScoop.

Lawmakers call on Commerce to sanction hackers-for-hire

A bipartisan trio of lawmakers is asking the Commerce Department to sanction three India-based mercenary hack-for-hire groups that have reportedly stolen data from thousands of American citizens and companies.

Democratic Sens. Ron Wyden of Oregon and Sheldon Whitehouse of Rhode Island and Rep. Pat Harrigan, R-N.C., sought in a letter to Secretary Howard Lutnick Wednesday to have the mercenary firms added to the Treasury Department’s Entity List, which would limit their access to American software, cybersecurity tools and cloud infrastructure.

“Several India-based cyber-mercenary groups have spent more than fifteen years conducting targeted espionage against U.S. citizens, businesses and the lawyers representing them,” Wyden, Harrigan and Whitehouse wrote. “Compounding this security threat, these cyber mercenaries and their associates have engaged in an aggressive campaign of global lawfare to censor investigative reporting by prominent American media organizations. This coordinated effort effectively allows foreign entities to use foreign courts to keep the American public in the dark about cyber threats to their own country and undermines the fundamental constitutional rights of U.S. citizens.”

The three firms are Sunkissed Organic Farms, BellTroX and CyberRoot. The first of those three was formerly known as Appin and has been the subject of investigative reports and criminal probes. The Citizen Lab at the University of Toronto has delved into the work of BellTroX, and journalists also have reported on the activity of CyberRoot.

“The threat is further heightened by evidence that these groups have operated at the behest of the Qatari government, targeting opponents of Qatar’s World Cup bid and even the family of a former Republican Chairman of the House Permanent Select Committee on Intelligence,” the lawmakers wrote. “While one of these operatives has been indicted by the Department of Justice, the foreign hackers continue to operate with impunity.”

Reuters reported in 2023 that the family member was Kristi Rogers, wife of former House Intelligence Chairman Mike Rogers, now running for Senate as the GOP candidate against one of the midterms’ most important and contested races against Democrat Abdul El-Sayed.

Some of the hacking groups also have sought to censor reporting on their hacking activities, the lawmakers noted.

CyberScoop couldn’t reach the companies for comment. The Commerce Department also didn’t immediately respond to a request for comment, and the government of Qatar didn’t immediately respond to an email seeking comment on the letter. TechCrunch first reported on the letter.

Corrected 9/10/2026: to reflect department to which the lawmakers addressed the letter.

The post Lawmakers call on Commerce to sanction hackers-for-hire appeared first on CyberScoop.

FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching

Artificial intelligence is souping up the speed and capabilities of malicious hackers, a top FBI official said Tuesday. And the speed of vulnerability discoveries is forcing organizations to patch more frequently, said another top FBI official.

The officials made their remarks one day before the release of a new FBI cyber strategy Wednesday, which touches on AI, relief and justice for victims and other bureau priorities.

Speaking to both CyberScoop and at the Billington CyberSecurity Summit, Jason Bilnoski, deputy assistant director of the FBI’s cyber division, said AI is “taking actors to the next level.” 

“You’re going to have additional offensive actions coming at your environment, targeting the network at speed and capability,” he said. And he expects it to keep getting worse, with AI-enabled attacks already having a measurable impact, as demonstrated by the numbers in a new section of the annual FBI report on digital crimes.

“The wave is coming. I don’t think we’ve hit the crest yet,” Bilnoski said. “We see an exponential increase in the use of AI, whether it’s nation-state or criminal.”

Still, AI isn’t doing anything that attention to cybersecurity basics wouldn’t prevent, Bilnoski said. It’s something the FBI sees again and again when it conducts investigations, even those with an AI element.

“The adversaries are still [exploiting] basic principles or basic cyber hygiene principles that we are not following,” he said, referring to a recent FBI emphasis on 10 fundamental defensive measures like multifactor authentication. “If we can harden up those top 10 controls that we talked about, it would certainly reduce the risk of both criminal and nation-state targeting of our environment.”

“What will prevent the attacks in the next 18 months are the same things that would have prevented the attacks of yesterday,” he said.

The FBI, meanwhile, will “continue to pursue AI in a way that will help us defend at scale,” Bilnoski said.

Patching pacing

The speed at which AI models are uncovering vulnerabilities means organizations need to rethink their approach to patching, another FBI official said at the Billington event.

“We no longer can essentially do the quarterly patching,” said Colleen Ferranti, assistant section chief, cyber engagement and intelligence section. “We have to evolve with the time, and we have to do more risk-based type patching, and we have to be doing that continuously.”

“So, from our perspective, the day-to-day or quarterly or Patch Tuesday — this needs to be a patch-all-of-the-time, and making sure that we are tracking our systems to also be engaging with that type of technology and at that speed and that level,” she continued.

AI now in FBI cyber strategy

The FBI strategy also has a section devoted to artificial intelligence.

“FBI Cyber will deploy AI-enabled tools to triage large datasets, surface relationships, accelerate malware analysis, prioritize victim notifications, map adversary infrastructure, support attribution, and identify patterns that no human analyst could process at the required pace,” it states. “Consistent with President Trump’s Cyber Strategy for America, FBI Cyber will rapidly adopt agentic AI in ways that securely scale defense and disruption, and will implement AI-enabled tools to detect, divert, and deceive threat actors where operationally appropriate.”

The FBI likewise wants to develop additional tools and techniques, according to the strategy.

“The FBI will continue to develop its Computer Network Operations (CNO) program, providing investigative teams with the court-authorized or otherwise lawfully authorized technical operations tools to remotely collect, conduct surveillance, and disrupt the activities of nation-state and cybercriminal actors when traditional investigative techniques will not achieve the required outcome,” it reads.

The strategy largely reflects a number of existing practices at the agency, such as a focus on disrupting attackers. But one emphasis is on relief and justice for victims.

It contains a “pledge” in support of them: “Pursuing our mission, we recognize that we will encounter unique and novel issues related to privacy and the handling of sensitive data. We will always treat victims with dignity and respect, protect their privacy and data, and rigorously adhere to the U.S. Constitution; applicable laws, regulations, and policies; and the FBI’s Core Values.”

It also promises to quickly share threat intelligence, swiftly respond after incidents and expand “its Industrial Control Systems (ICS) Coordinator program to designate dedicated personnel in every field office.” 

It’s the latest document of the Trump administration to focus on cyber strategy, following the release earlier this year of its overall cyber strategy and the Defense Department’s version expected to publish soon as well.

Clarified 9/9/2026: A quote from Colleen Ferranti has been edited for clarificiation.

The post FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching appeared first on CyberScoop.

European parliament members call for slowdown of Serbia’s EU entry over spyware use

A group of European Parliament representatives are seeking to delay Serbia’s entry into the European Union and send other messages to Belgrade over the government’s usage of spyware.

The 29 members of the European Parliament (MEPs) cited a report this week from the SHARE Foundation about spyware found on the phones of Serbian student activists and that targeted others as well. The foundation, along with Amnesty International and The Citizen Lab at the University of Toronto, discovered both Pegasus and NoviSpy spyware infections.

The groups didn’t assign responsibility for the Pegasus infection, but said evidence from the NoviSpy infections pointed to Serbian government authorities.

“This is not a technical glitch; it is a direct state attack on democracy,” the 29 MEPs wrote Friday. “With upcoming elections ahead, Aleksandar Vučić’s regime is using illegal digital surveillance to systematically dismantle political opposition.”

The MEPs’ demands include slowing Serbian accession into the EU until completing an investigation into Serbia’s spyware usage and making Serbia’s accession contingent on improving rule-of-law accountability.

They also said President Ursula von der Leyen should cancel a planned visit to Serbia. European leaders were already outraged by the response from Serbia to the death of former Bosnian Serb army commander and war criminal Ratko Mladic, with Enlargement Commissioner Marta Kos canceling her own visit Friday over the alleged “glorification” of Mladic.

The spyware letter adds to the pressure, said Hannah Neumann, an MEP who signed it.

“It could very well be that some of these demands will be honored, but for sure the spyware won’t be the only reason why,” she told CyberScoop. Serbia’s history of spyware use contributed to Friday’s letter, she said: “We have been critical towards the government for already quite some time and demanded consequences so this was another straw.”

The Serbian government did not respond to multiple requests late Friday for comment.

“Appeasement has failed,” the members wrote. “It is time for the Commission to demonstrate that compliance with fundamental democratic standards is a non-negotiable requirement, not an option.”

European Union member nations have faced their own allegations over using spyware, and recent revelations of spyware found on the device of a member of the European Parliament’s PEGA Committee has prompted some to renew calls for enactment of recommendations from that committee to address spyware abuses.

The post European parliament members call for slowdown of Serbia’s EU entry over spyware use appeared first on CyberScoop.

Pegasus, NoviSpy variant spyware found on devices of Serbian activists

Researchers say they have uncovered the first confirmed Pegasus spyware infection of 2026, as well as another spyware variant infection, targeting Serbian student activists and others in what one group called the largest documented wave of that kind of surveillance in the country to date.

The SHARE Foundation said Wednesday that it found 14 people targeted in all, including one member of parliament and a local government official. The University of Toronto’s Citizen Lab confirmed the Pegasus infection of a student activist with “high probability,” while Amnesty International confirmed that two devices had been infected with a new version of the NoviSpy spyware.

The SHARE Foundation noted that the infections coincided with the build-up to key local elections in March that were viewed as a test of the ruling Serbian Progressive Party, with student protests rising in the wake of the 2024 Novi Sad railway station canopy collapse, and in advance of October parliamentary elections.

Serbian activists have found themselves targeted with spyware numerous times before, including by Pegasus and NoviSpy. But the SHARE Foundation said this was the biggest wave there so far.

Spyware is noted for its ability to access everything on a device, record screens or take over its microphone.

NoviSpy variant infections

One NoviSpy variant infection came after authorities took a student’s phone during police questioning, and the same spyware was found on another device as well after private messages from the phone were disclosed by a media outlet that favors the ruling party, SHARE Foundation said.

The SHARE Foundation said signs point to Serbian police or secret service being behind the NoviSpy variant cases, with Amnesty International offering a similar assessment. 

“These new forensic findings show that Serbian student activists continue to be targeted with invasive spyware,” Donncha Ó Cearbhaill, head of Amnesty International’s Security Lab, told CyberScoop. “As with NoviSpy, which Amnesty International found used extensively in Serbia in 2024, the evidence suggests the infections are being carried out during detention by the Serbian authorities.”

Pegasus infection

In the case of the infection from NSO Group’s Pegasus spyware, it’s rare for investigators to determine who specifically made use of it, although they found that the student’s device was hacked with a Pegasus zero-click exploit from December of last year to January of this year. The infection came via a zero-click exploit — meaning without victim interaction.

But Citizen Lab said the Serbian case harkens back to the first discovery of Pegasus a decade ago when it was against a pro-democracy activist, Ahmed Mansoor.

“Today, Pegasus is still being used to hack people campaigning for democracy,” said John Scott-Railton, senior researcher. “NSO spent a decade promising reform, yet their spyware is still an instrument of political repression.”

NSO Group maintains that its spyware is for usage against terrorism and crime, and that it halts any abuses it discovers.

The spyware discoveries in Serbia came after Apple sent threat notifications to the targets.

“Apple’s updates have broken this particular exploit, so we urge everyone to make sure they are updated to the latest version of iOS,” said Bill Marczak, senior researcher at Citizen Lab.

The post Pegasus, NoviSpy variant spyware found on devices of Serbian activists appeared first on CyberScoop.

Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities

A class action lawsuit filed by victims of child sexual abuse material (CSAM) accuses xAI of training Grok’s synthetic deepfake “nudify” capabilities on real images and videos of child abuse.

The lawsuit, filed Wednesday in the U.S. District Court for the Northern District of California, names Jane Doe 1 and other anonymous individuals as plaintiffs, calling Doe “an identified victim of child pornography tracked by the Federal Bureau of Investigation’s Child Exploitation Notification Program.”

Doe was a pre-school aged child when her perpetrator’s abuse began and continued for years, for the explicit purpose of making CSAM material to distribute online. Media depicting the victim has circulated online since at least the early 2000’s, with, according to the lawsuit “hundreds of thousands of files” being included in law enforcement submissions to the National Center for Missing & Exploited Children (NCMEC).

As part of the FBI’s program, she still receives updates when images related to her abuse surface online, and the suit alleges her material has “well known hash-values” that have shown up in deepfakes created with Grok and spread on X.

“CSAM depicting Plaintiff has been found on xAI as part of investigative reporting, takedown request efforts, and criminal investigations, arrests, and convictions for violations of state and federal laws,” the lawsuit states. It also claims “xAI, using Grok, has generated images depicting Plaintiff and the child pornography series in which she is the victim.”

The lawsuit cites “Masha’s Law” as the basis for its allegations. That law, passed in 2018,  protects civil legal remedies to victims of child pornography and online exploitation.

According to an analysis by the Center for Countering Digital Hate, during an 11-day period between Dec. 2025 and Jan. 2026, Grok created more than 3 million sexualized images, at least 23,000 of which appeared to depict children.

On Jan. 14, after the period tracked by the center, Musk wrote on X that he was “not aware of any naked underage images of Grok. Literally zero.” Must also implied that users, not his technology, were primarily responsible for images created using Grok while simultaneously claiming the model “will refuse to produce anything illegal” if asked.

The suit claims that while other competitors enacted guardrails to prevent their AI models from generating “nudified” images of adults and children, xAI “did the opposite,” embedding Grok and it’s deepfake capabilities directly into X, effectively creating an instantaneous CSAM generation and distribution system for the internet.

While xAI said it built in guardrails to prevent Grok from creating deepfake sexualized images, the suit notes that they are “very weak,” diverge from standard industry best practice and can be easily circumvented.

The system rejects prompt prompts where the chatbot detects “clear intent by the user in the phrasing of their request,” the complaint stated. “Indirect or euphemistic prompts can easily slip past a text-based filter, so if the model retains the underlying capability to generate sexual or abusive content, some volume of CSAM becomes effectively inevitably generated by the system.”

The lawsuit also notes that Grok’s terms of service treat anything that gets posted on X as training material, meaning any CSAM material posted on the site over the past year was likely ingested by the model.

The alleged victims are asking for monetary damages along with injunctions to prevent Grok from creating additional harm through future sexualized deepfakes or CSAM. The suit lists “thousands” of members in the class, all with similar claims against xAI.

A request for comment on the lawsuit sent to xAI was not returned.

Grok’s nudification capabilities, and xAI owner Elon Musk’s dismissive public attitude around the fallout have led to international outrage, criminal investigations and a wave of private lawsuits against the company.

Another lawsuit against X filed earlier this year claims that a man used Grok to generate thousands of instances deepfake CSAM material of his stepdaughter. That lawsuit also claims xAI withheld information from law enforcement authorities that would have helped them identify the stepfather as the perpetrator. Days after authorities traced and seized the material on the wte, he committed suicide.

In July, Musk sued Minnesota Attorney General Keith Ellison over a new state law that bans nudification technology and impose a $500,000 fine for each instance where an AI tool is used to generate or alter an image in a sexually explicit way. Musk’s lawsuit claims the ban violates the First Amendment.

The post Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities appeared first on CyberScoop.

Lawmakers seek watchdog review of federal hacking of Americans

A pair of lawmakers wants a watchdog agency to probe how the federal government hacks Americans, including with the use of spyware, and deliver a report to the public.

Sen. Ron Wyden, D-Ore., and Rep. Greg Casar, D-Texas, wrote to the Government Accountability Office on Friday to request the review.

“While federal law enforcement agencies have used hacking and spyware as an investigative tool for more than 25 years, there exists little public information regarding its scope, frequency, or operational safeguards,” they wrote. “Unlike traditional surveillance authorities, such as wiretaps or pen registers, the government does not publish annual reports for hacking operations.”

The issue of U.S. government spyware usage has grown in prominence in President Donald Trump’s second term, as Immigration and Customs Enforcement has acknowledged working with spyware firm Paragon. Lawmakers have been asking whether that’s the full extent of U.S. government reliance on spyware after the Biden administration largely shunned it.

But the Wyden and Casar letter is broader than just spyware. It also touches on the federal government’s acquisition of hacking tools, like those in the case of a former senior official at defense contractor L3Harris who was sentenced this year for stealing and selling capabilities developed for the federal government, and Rule 41 hacking powers.

The congressional duo asked GAO to review documented cases of federal law enforcement misusing hacking capabilities for personal or otherwise unauthorized reasons, and what kind of safeguards agencies have against hacking abuses.

“Spyware and other hacking tools grant expansive access to personal devices, including webcams, location data, stored files, and encrypted communications,” they wrote. “Unrestricted access to such invasive surveillance capabilities invites abuse by rogue agency personnel. Indeed, there are countless documented examples of government employees abusing other sensitive surveillance databases and tools for unauthorized personal purposes.”

They also asked GAO to review how agencies buy and protect sophisticated hacking tools, and how agencies make Rule 41 hacking requests to courts.

TechCrunch first reported on the letter from Wyden and Casar.

Casar is the top Democrat on the House Oversight Subcommittee on Federal Law Enforcement, and Wyden has a long career of scrutinizing federal intelligence and surveillance efforts.

The post Lawmakers seek watchdog review of federal hacking of Americans appeared first on CyberScoop.

Retail theft bill spurs ‘very large and very dangerous’ surveillance fears

A bill to battle organized retail theft has wide bipartisan support and momentum on Capitol Hill, even as opponents say it threatens to dangerously expand surveillance centered in Immigration and Customs Enforcement at a time when the agency’s aggressive conduct is under scrutiny.

Backers counter that critics are wrong about the bill that they say only would enhance existing information sharing arrangements, and could play a role in fighting cyber-enabled crime, too.

At its core, the Combating Organized Retail Crime Act (CORCA) establishes an Organized Retail and Supply Chain Crime Coordination Center within ICE’s Homeland Security Investigations division. It also would create criminal penalties for money laundering proceeds from selling stolen goods, and a $5,000 threshold for the combined total value of stolen property over a year for charging purposes.

It passed the House in June by a vote of 348-60, and Senate supporters are pushing for its inclusion in the annual defense policy bill, considered “must-pass” legislation that Congress has cleared for more than 60 consecutive years.

Opponents are trying to beat back CORCA, which arose from fears of mass theft during the COVID-19 pandemic.

“Its design actually creates a very large and very dangerous surveillance network,” said Nina Patel, senior policy counsel at the justice division of the American Civil Liberties Union. “You would hear the words ‘organized retail crime’ and think that this might be about shoplifting, and you would be surprised to learn that much of the apparatus is concentrated within the Department of Homeland Security.”

The objections

Patel and Jina John, her colleague at the ACLU, said the bill inadequately defines key terms: “organized retail crime,” even, as well as “retailers,” and what kind of data can be shared.

“It’s very broadly and vaguely drafted, and so the way it’s done is that it establishes all these mechanisms for data sharing among these entities, including getting data directly from retailers,” said John, senior policy counsel for AI, privacy and technology. “The data sharing is for any threats related to retail and supply chain crime. That’s it, just: threats. …That’s the biggest concern, is that this is basically giving DHS access to retail surveillance,” she said, like surveillance cameras at malls and train stations, Flock cameras and automated license plate readers.

Rather than the federal government purchasing data from brokers for surveillance purposes — already a contentious practice — CORCA gives them an avenue to get it freely, John said.

A variety of civil liberties and civil rights organizations are among the coalition trying to defeat CORCA. A key issue for many of them is the fusion center at ICE, which has collated data like cell phone location, health and other information, said Spencer Reynolds, senior counsel at the Justice in Public Safety Project at the NAACP Legal Defense and Education Fund. Adding retail data makes that worse, he said. 

“Together, this information allows ICE to hunt down people, find their families and associates, and pull them from their communities,”  he said. “The agency, over the last couple of years, especially, has been openly engaging in racial profiling, and poor Black and Brown people are likely to feel the impact of this the most.”

Reynolds continued: “The entire model that CORCA is going to impose allows government and industry participants to overcome protections, safeguards, guardrails, and use government to target their opposition.”

The support

Backers argue that the bill poses no risk to anyone but organized retail crime leaders.

“Over the years, organized retail crime has evolved into a deadly, multi-jurisdictional threat to American lives, the United States’ economy and our national security,” Senate Judiciary Chairman Chuck Grassley, R-Iowa, said in a statement. “My Combating Organized Retail Crime Act is a targeted, bipartisan bill that would crack down on large-scale retail theft by coordinating federal, state and local law enforcement efforts, while aligning existing resources.” 

A Senate Judiciary Committee spokesperson said the bill doesn’t give DHS any additional enforcement authorities, and is housed within DHS’s Homeland Security Investigations to build on the role they currently have in addressing transnational and organized criminal activity.

The American Trucking Associations supports the bill, and its legislative director Alex Rosen disputed opponents’ claims about its surveillance risks. 

“When you can’t argue the merits of the legislation, it’s easy to revert back to stale, overused buzzwords and an attempt to rile up opposition,” she said. “The idea that this would increase government surveillance is nutty because what this does is it creates within HSI a kind of central reporting repository for industry to report high-level crimes, crimes that are part of big organized criminal theft groups … The idea that this would somehow give the government more authority to surveil Americans is crazy because nowhere in the text does it say that.”

David Johnston, vice president of asset protection and retail operations for the National Retail Federation, noted the difference between ICE’s HSI, focused on a variety of criminal investigations including cybercrime, and its Enforcement and Removal Operations division that’s focused on finding and evicting those who violate U.S. immigration laws.

The bill could be one answer to rising cybercrime, he said.

“There has really been a substantial increase in not only the activity but the methods, the tactics, and as retail has evolved into the digital environment as much as it is in the physical store environment — we’ve seen the criminal, the organization, the structure, the convergence between how cyber and physical thieves operate,” he said, mentioning gift card fraud, or e-commerce fraud that started from a phishing or account takeover. “It’s really become a substantial issue for retailers, consumers, communities across the board.”

Cyber means have also aided cargo theft with the creation of false personas and more, Johnston said: “They’re not going and stealing these trucks with physical violence. They’re driving them right out of the yard, waving to the security officer because they’ve got this whole organization behind them that are using these cybercriminal tactics.”

Where it’s headed

Both sides are optimistic that they’re making progress on the bill. Kristina Roth, the senior policy associate leading the NAACP LDF’s criminal legal system policy portfolio, said a number of lawmakers who actually sponsored the legislation voted against it on the floor.

That points to lawmakers becoming more educated on the bill, which moved swiftly this year from committee to a full vote. “I think the connections that this legislation has through DHS were maybe not well enough described as they could have been,” Roth said.

Patel said there’s more work to be done.

“What is really disturbing about this bill is the way it’s been presented to a number of legislators, and it keeps getting this moniker of being a bipartisan bill,” she said. “But I think few people recognize just how much power is being given to ICE, the complete lack of accountability from DHS and ICE under this administration and in the past, and empowering them to reach into Main Street and into consumer spaces.”

Rosen pointed to the wide House vote as well as bipartisan support from leaders of key committees, such as the Judiciary and the Senate Homeland Security and Government Affairs committees, to include the bill in the annual National Defense Authorization Act. The nature of the support has supporters optimistic about the chances for CORCA to become law.

The defense legislation often wins passage around the end of each calendar year. 

The post Retail theft bill spurs ‘very large and very dangerous’ surveillance fears appeared first on CyberScoop.

Senate set to debate package of bills on privacy, AI and kids safety 

The Senate is teeing up debate on a raft of new bills that would impact online privacy, kids safety and artificial intelligence.

The Senate Committee on Commerce, Science and Transportation will mark up five bills Wednesday. The most high-profile legislation, the Kids Online Safety Act, sponsored by Sens. Marsha Blackburn, R-Tenn., and Richard Blumenthal, D-Conn., would implement broad changes to how social media and other websites handle data and accounts for users under the age of 17.

KOSA would require online platforms — including social media, video games, messaging apps and streaming services – to exercise “reasonable care” when designing features that could lead to more addictive or harmful online behaviors for minors. It would provide parents with digital tools to control and monitor their children’s accounts, prohibit market or product research on children under the age of 13 and empower the Federal Trade Commission to investigate, fine and enforce the law.

Earlier bill versions earned the backing of large tech companies, including Apple, OpenAI, and others.

By contrast in June, nearly 100 smaller parent, youth and tech-focused organizations signaled their opposition to the bill in a letter to congressional leaders. Some of the signatories, like the nonprofit Issue One, were previous supporters of KOSA who turned on the legislation after the House passed a significantly watered down version that stripped out stronger language around tech companies “duty to care,” which would have set a higher legal standard for covered platforms to consider user harm when designing their products.

Legal and ethical design standards are critical for online services, the groups argue, given lawsuits alleging that major tech platforms contribute to teenage addiction, depression, suicide, and non-consensual deepfakes.

“Major social media companies, the companies this bill regulates, are currently on trial across the country,” the letter said. “The evidence in those cases – internal records prioritizing teen engagement over teen wellbeing, safety changes shelved because platforms would lose users, buried research on the benefits of disconnection shows the default poor choices of these companies when the law does not require otherwise. Stripping the duty of care does not lighten a regulatory burden; it removes the most important obligation requiring these products to be designed safely in the first place.”

However, Blumenthal and Blackburn publicly stated that the House version was “dead on arrival” without those provisions, and they remain in the Senate version of the bill being considered Wednesday.

The markup will also consider other major legislation that would regulate age on the internet, safety features for AI chatbots and more. While proponents claim the bills enhance privacy and safety protections, technology experts largely disagree.

The SCREEN Act, introduced last year by Sen. Mike Lee, R-Utah, would require social media companies to implement age verification technology.

Lee has partnered with parent-led groups to advocate for state-level age verification laws that expand  parental control over children’s social media accounts. Some public surveys have shown broad public support for age verification laws.

Louis Eichenbaum, a former chief information security officer at the Department of the Interior, told CyberScoop that one of the biggest challenges around online age verification is that it “increasingly requires collecting, storing or validating sensitive identity information about them.”

“The goal should not simply be verifying age, it should be doing so while minimizing the collection, retention, and exposure of personally identifiable information,” said Eichenbaum, now federal chief technology officer at ColorTokens. “Every additional piece of identity data collected expands the attack surface and increases the potential impact of a breach.”

Some privacy groups oppose the SCREEN Act and similar age verification laws, arguing the required data collection outweighs child protection benefits. 

The Electronic Frontier Foundation said the SCREEN Act is broader than state-level age verification laws, which only cover websites that are predominantly sexually explicit.

“The bill requires nearly any service hosting even a single piece of sexually explicit content to verify the ages of its users,” wrote EFF director of federal affairs India McKinney. “The result is that the bill would apply not only to adult content sites like PornHub or OnlyFans, but also streaming services like Netflix, and social media platforms like Reddit, Discord, or Bluesky, if they host any adult content.”

The Youth AI Privacy Act, from Sen. Ed Markey, D-Mass., would require new safety features for AI chatbots.

According to a fact sheet released by Markey’s office in March, the bill would ban push alerts, require chatbots to disclose they’re not human, limit data retention, and prohibit using minors’ data for AI training or any purpose beyond providing answers.

The Chatbot Act, by Sens. Ted Cruz, R-Texas, Brian Schatz, D-HawaiI, John Curtis, R-Utah and Adam Schiff, D-Calif. would require AI companies to implement “family accounts” for AI chatbots that give parents the ability to monitor and restrict their children’s interactions. Cruz has said the status quo “has left many parents in the dark” on their kids’ AI use.

The Children’s Artificial Intelligence Toy Safety Act, by Sen. Tammy Duckworth, D-Ill., would create a federal study around toys sold to children that include artificial intelligence or chatbot components.

The post Senate set to debate package of bills on privacy, AI and kids safety  appeared first on CyberScoop.

Security researchers find stalkers abusing Chrome’s sync feature

Cyberstalkers are increasingly exploiting a feature in Google Chrome meant for mobile phone user convenience, but can give intruders broad access to a device owner’s private information, according to researchers.

Certo Software said in a blog post Tuesday that stalkers are making use of Chrome’s sync capability — meant to make it so signing into Chrome on one device makes it easier to do so on other devices, too — to spy on a phone owner’s browsing history and gain access to their stored passwords.

As an illustration, Certo used the case of a pseudonymous victim, Emma, who had searched for a family lawyer and visited a domestic violence support website while her partner was sleeping, only for him to bring up to her two days later.

“Emma had been careful to only ever use her own device, and she hadn’t noticed any new apps appear on her phone,” wrote Certo co-founder Russell Kent-Payne. “What she didn’t know was that weeks earlier, during a few unattended minutes with her phone, he had opened the Chrome app and quietly signed it into a Google account of his own. From that moment on, every site she visited was being copied straight to his account, viewable from any device, anywhere in the world.”

The surveillance is as easy as that: brief access to a phone, signing into a Google account and making sure sync is turned on for that account.

Eva Galperin, director of cybersecurity at the Electronic Frontier Foundation, said on the Bluesky social media app that Certo’s research serves as “an important reminder that tech-enabled abuse isn’t just limited to stalkerware.”

Certo said that Google could do a couple things, such as providing a temporary notification whenever a new account is added or sync is turned on or offering a regular marker to indicate when sync is active and which account it’s syncing to, to protect users.

Google did not respond to multiple requests for comment about Certo’s findings.

But the uptick in usage of that stalking method could be a byproduct of security successes elsewhere in the fight against spyware, Certo said.

“Modern smartphones are harder to compromise than ever. Regular security updates, stricter app store rules, and on-device threat detection have made traditional spyware a much riskier bet for a cyberstalker than it used to be,” Kent-Payne wrote. “As a result, we’re increasingly seeing abusers turn to something far simpler: the legitimate apps already sitting on their victim’s phone. No installation, no suspicious permissions, no telltale battery drain — just a quiet misuse of a feature the victim never knew existed.”

At the same time, Chrome is the world’s most popular browser, and this isn’t the first time security concerns have popped up about its sync feature, among other worries.

The post Security researchers find stalkers abusing Chrome’s sync feature appeared first on CyberScoop.

Deepfake CSAM lawsuit against xAI, Grok expands

Two new parties have been added to a class-action lawsuit against X.ai over its Grok tool including teenagers and children who say it was used by family members or other people they know to create nonconsensual deepfake child sexual assault material (CSAM).

The lawsuit, originally filed in March by three women, was amended this week to include two additional plaintiffs, Jane Does 4 and 5, who say that Grok was used to make the illegal content based on their real photos and videos.

All five of the women in the lawsuit are anonymous, and the complaint said the spread of the material had left them humiliated and ashamed.

Jane Doe 4, a female from Wyoming, said her stepfather uploaded a photo of her when she was 11 and lying on a couch to his phone. Using Grok, the stepfather created more than 7,000 CSAM-related images of her. He also shared and traded the images with others on social media platforms.

The lawsuit alleges that the stepfather opted for Grok “because the platform was less restrictive than other AI models and responded to his prompts to generate sexually explicit material using an image depicting a prepubescent minor.”

It also claims that in February, xAI did generate a tip to the National Center for Missing and Exploited Children regarding the images, but the company only submitted the original, authentic image as evidence. According to the suit, xAI did not respond when law enforcement requested the thousands of Grok-generated images based on the photo and IP address information that would have quickly helped identify her stepfather as the perpetrator.

The lawsuit states that the stepfather shot himself two days after he was arrested and charged with child exploitation crimes. His suicide added to the “extreme personal crisis” brought on by the images created through Grok. She regularly “struggles with self-loathing and disgust” as well as “extreme anxiety” at the thought that the images will be found by others online and suffer from depression, including excessive sleep and suicidal ideation when awake.

Jane Doe 5 claimed that an adult male related to one of her classmates used Grok to convert a photograph from her eighth-grade graduation into illicit material. The images were also traded and shared with others online. While the man was arrested and charged, much of the content is still available on the internet. As a result, she “feels a complete lack of control over the ongoing dissemination of the files.”

“It is impossible to know how many other child sex predators may now possess Jane Doe 5’s CSAM, nor how widely her CSAM has now been disseminated online through darknet channels and applications,” the complaint said.

The press office for xAI did not respond to an emailed request for comment from CyberScoop.

The lawsuit also adds Stability AI as a defendant, alleging the company released Stable Diffusion 1.0 as an open-weight model despite knowing it was trained on CSAM and has declined to alter or modify its guardrails in response.

According to a 2023 Stanford study, the underlying dataset used to train Stable Diffusion models was created through unguided webcrawling of internet content. That means it ingested “a significant amount of explicit material,” including CSAM. Stable Diffusion 1.0 had a classifier meant to block the generation of such images, but because of that training data, downstream developers could more easily exploit the model and create modified versions that bypass those protections.

While Stable Diffusion 2.0 introduced stronger guardrails, the lawsuit claims Stability AI rolled back those protections in response to “disgruntled” users that the new restrictions were “prude” and “unpopular.” That in turn has fed an ecosystem of jailbroken “nudify apps” based on Stability AI’s models.

“Stability AI knew that its models, once capable of generating sexually explicit images, would foreseeably be used to generate CSAM unless appropriate model-level safeguards were implemented,” the complaint said.

Stability AI did not respond to a request for comment from CyberScoop.

The post Deepfake CSAM lawsuit against xAI, Grok expands appeared first on CyberScoop.

Someone infected a spyware probe overseer with spyware

In 2022 and 2023, the European Parliament’s PEGA Committee investigated spyware abuses across the European Union following journalistic revelations about government deployment of NSO Group’s Pegasus technology.

Now, years later, it turns out that someone was using Pegasus spyware on one of the committee’s own. 

In a report published Friday, the University of Toronto’s Citizen Lab revealed that it found Pegasus on the phone of substitute PEGA Committee member Stelios Kouloglou, a Greek journalist and former member of the European Parliament. It’s the first time a member of the committee has been publicly identified as a Pegasus victim.

For Kouloglou, the Pegasus infection was surprising. For another PEGA Committee member, it was fully expected, if delayed. For Citizen Lab, it was ironic.

For all of them, it was further evidence that much more needs to be done to prevent spyware abuses — such as enacting the very recommendations of the PEGA Committee’s final report that never saw action in the European Parliament.

Kouloglou told CyberScoop that he had run security tests on his phone prior to joining the PEGA committee in 2022, so he didn’t think anyone would be bold enough to try to infect his phone once he became a member. With Greece’s use of Predator spyware under scrutiny, “it would be a big scandal” if he was hacked while on the panel, he said.

But someone — Citizen Lab’s investigation didn’t uncover whom — infected Kouloglou’s phone with Pegasus twice, once around October of 2022 and once around March of 2023, investigators concluded with “high confidence.”

During the first infection, the committee was preparing for some prominent hearings and the first draft of its report. Kouloglou was in the hospital and got a visit from another Greek journalist who had testified before the committee and had himself had his phone infected with spyware earlier. Given the ability of spyware to listen to audio through an infected phone, it’s possible the infection ran afoul of protections for health data.

During the second infection, the panel was preparing for yet more hearings and “was engaged in intense discussions related to the final drafting process,” according to Citizen Lab.

The Citizen Lab investigation of Kouloglou’s came about this May, after he said a lawyer he knew told him there was a way to send his phone’s data to the research organization, during a time when Kouloglou was doing some investigative reporting and writing a “scandal of the week” column. “I said, ‘Why not? Let’s do it,” he said.

Whoever was responsible for infecting Kouloglou’s phone did so during “crucial moments” of the committee’s work, said Hannah Neumann, a member of the PEGA Committee and European Parliament member from Germany.

“Many of us were expecting some hacks during the committee, but it’s still frustrating now to figure out that it really happened,” she told CyberScoop. “When we decided to set up the Pega Committee, we really worked hard with our internal European Parliament IT security…  so that they can provide spyware checks for the members of the Pega Committee and their staff.”

Kouloglou and Neumann could only speculate on who was responsible. But for the two of them, and Citizen Lab, the motive seems clear.

“It is ironic that a member of the committee charged with investigating Pegasus was himself targeted with Pegasus spyware,” Ron Deibert, founder and director of Citizen Lab. “Someone, somewhere likely wanted to breach parliamentary privilege and find out what was going on in that committee. This case shows how the still unregulated and highly abused mercenary spyware industry is poisonous to democratic processes.” 

Kouloglou said he plans to pursue legal action against NSO Group. Many spyware victims have had difficulty winning lawsuits against spyware makers, although not all.

Israel-based NSO Group did not respond to a request for comment Thursday afternoon.

Neuman said the lessons learned as a result of Kouloglou’s phone infection include, “for members of national parliament and the European Parliament: Regularly get your devices checked. Apparently they don’t respect European democracy and parliamentarism.”

Most importantly, it’s time to enact the PEGA committee’s recommendations, she said.

“I don’t know how much more it needs for member states and the commission to wake up and actually start implementing the very good recommendations of our PEGA committee, because we all know that there is a spyware abuse,” Neuman said. “I don’t need to have another committee for that. I just need them to act.”

Kouloglou almost certainly won’t be the last member of parliament to get infected, said John Scott-Railton, senior researcher at Citizen Lab. Some had been infected prior to the work of the PEGA Committee, and some have been found to be targeted since. (The United States’ legislative body has been targeted in the past as well.)

“Providing highly secretive government agencies with surveillance tools supplied by unaccountable and often unethical mercenary firms is a recipe for the abuse of power,” he told CyberScoop. “I can tell you how the next chapter will go: more hacked Parliamentarians. In fact, I suspect there are members voting and attending high level meetings with no idea that their phone has been turned into a spy in their pocket.”

The post Someone infected a spyware probe overseer with spyware appeared first on CyberScoop.

❌