❌

Normal view

There are new articles available, click to refresh the page.
Before yesterdayMain stream

Retail theft bill spurs ‘very large and very dangerous’ surveillance fears

20 August 2026 at 11:27

A bill to battle organized retail theft has wide bipartisan support and momentum on Capitol Hill, even as opponents say it threatens to dangerously expand surveillance centered in Immigration and Customs Enforcement at a time when the agency’s aggressive conduct is under scrutiny.

Backers counter that critics are wrong about the bill that they say only would enhance existing information sharing arrangements, and could play a role in fighting cyber-enabled crime, too.

At its core, the Combating Organized Retail Crime Act (CORCA) establishes an Organized Retail and Supply Chain Crime Coordination Center within ICE’s Homeland Security Investigations division. It also would create criminal penalties for money laundering proceeds from selling stolen goods, and a $5,000 threshold for the combined total value of stolen property over a year for charging purposes.

It passed the House in June by a vote of 348-60, and Senate supporters are pushing for its inclusion in the annual defense policy bill, considered “must-pass” legislation that Congress has cleared for more than 60 consecutive years.

Opponents are trying to beat back CORCA, which arose from fears of mass theft during the COVID-19 pandemic.

“Its design actually creates a very large and very dangerous surveillance network,” said Nina Patel, senior policy counsel at the justice division of the American Civil Liberties Union. “You would hear the words ‘organized retail crime’ and think that this might be about shoplifting, and you would be surprised to learn that much of the apparatus is concentrated within the Department of Homeland Security.”

The objections

Patel and Jina John, her colleague at the ACLU, said the bill inadequately defines key terms: “organized retail crime,” even, as well as “retailers,” and what kind of data can be shared.

“It’s very broadly and vaguely drafted, and so the way it’s done is that it establishes all these mechanisms for data sharing among these entities, including getting data directly from retailers,” said John, senior policy counsel for AI, privacy and technology. “The data sharing is for any threats related to retail and supply chain crime. That’s it, just: threats. …That’s the biggest concern, is that this is basically giving DHS access to retail surveillance,” she said, like surveillance cameras at malls and train stations, Flock cameras and automated license plate readers.

Rather than the federal government purchasing data from brokers for surveillance purposes — already a contentious practice — CORCA gives them an avenue to get it freely, John said.

A variety of civil liberties and civil rights organizations are among the coalition trying to defeat CORCA. A key issue for many of them is the fusion center at ICE, which has collated data like cell phone location, health and other information, said Spencer Reynolds, senior counsel at the Justice in Public Safety Project at the NAACP Legal Defense and Education Fund. Adding retail data makes that worse, he said. 

“Together, this information allows ICE to hunt down people, find their families and associates, and pull them from their communities,”  he said. “The agency, over the last couple of years, especially, has been openly engaging in racial profiling, and poor Black and Brown people are likely to feel the impact of this the most.”

Reynolds continued: “The entire model that CORCA is going to impose allows government and industry participants to overcome protections, safeguards, guardrails, and use government to target their opposition.”

The support

Backers argue that the bill poses no risk to anyone but organized retail crime leaders.

“Over the years, organized retail crime has evolved into a deadly, multi-jurisdictional threat to American lives, the United States’ economy and our national security,” Senate Judiciary Chairman Chuck Grassley, R-Iowa, said in a statement. “My Combating Organized Retail Crime Act is a targeted, bipartisan bill that would crack down on large-scale retail theft by coordinating federal, state and local law enforcement efforts, while aligning existing resources.” 

A Senate Judiciary Committee spokesperson said the bill doesn’t give DHS any additional enforcement authorities, and is housed within DHS’s Homeland Security Investigations to build on the role they currently have in addressing transnational and organized criminal activity.

The American Trucking Associations supports the bill, and its legislative director Alex Rosen disputed opponents’ claims about its surveillance risks. 

“When you can’t argue the merits of the legislation, it’s easy to revert back to stale, overused buzzwords and an attempt to rile up opposition,” she said. “The idea that this would increase government surveillance is nutty because what this does is it creates within HSI a kind of central reporting repository for industry to report high-level crimes, crimes that are part of big organized criminal theft groups … The idea that this would somehow give the government more authority to surveil Americans is crazy because nowhere in the text does it say that.”

David Johnston, vice president of asset protection and retail operations for the National Retail Federation, noted the difference between ICE’s HSI, focused on a variety of criminal investigations including cybercrime, and its Enforcement and Removal Operations division that’s focused on finding and evicting those who violate U.S. immigration laws.

The bill could be one answer to rising cybercrime, he said.

“There has really been a substantial increase in not only the activity but the methods, the tactics, and as retail has evolved into the digital environment as much as it is in the physical store environment — we’ve seen the criminal, the organization, the structure, the convergence between how cyber and physical thieves operate,” he said, mentioning gift card fraud, or e-commerce fraud that started from a phishing or account takeover. “It’s really become a substantial issue for retailers, consumers, communities across the board.”

Cyber means have also aided cargo theft with the creation of false personas and more, Johnston said: “They’re not going and stealing these trucks with physical violence. They’re driving them right out of the yard, waving to the security officer because they’ve got this whole organization behind them that are using these cybercriminal tactics.”

Where it’s headed

Both sides are optimistic that they’re making progress on the bill. Kristina Roth, the senior policy associate leading the NAACP LDF’s criminal legal system policy portfolio, said a number of lawmakers who actually sponsored the legislation voted against it on the floor.

That points to lawmakers becoming more educated on the bill, which moved swiftly this year from committee to a full vote. “I think the connections that this legislation has through DHS were maybe not well enough described as they could have been,” Roth said.

Patel said there’s more work to be done.

“What is really disturbing about this bill is the way it’s been presented to a number of legislators, and it keeps getting this moniker of being a bipartisan bill,” she said. “But I think few people recognize just how much power is being given to ICE, the complete lack of accountability from DHS and ICE under this administration and in the past, and empowering them to reach into Main Street and into consumer spaces.”

Rosen pointed to the wide House vote as well as bipartisan support from leaders of key committees, such as the Judiciary and the Senate Homeland Security and Government Affairs committees, to include the bill in the annual National Defense Authorization Act. The nature of the support has supporters optimistic about the chances for CORCA to become law.

The defense legislation often wins passage around the end of each calendar year. 

The post Retail theft bill spurs ‘very large and very dangerous’ surveillance fears appeared first on CyberScoop.

Most federal cybersecurity reporting rules are duplicative, study finds

22 July 2026 at 17:04

Seven out of 10 federal cyber regulations requiring written reports to federal agencies are duplicated elsewhere, a report from a government watchdog found in a report to Congress Wednesday.

And so far, efforts to de-conflict haven’t had much success, the report from the Government Accountability Office concluded.

At the request of two top lawmakers, the GAO examined federal cyber regulations at 37 agencies. It counted 80 out of 117 rules that “either contain the same kind of reporting requirement applicable to a sector or the same reporting requirement as at least one other regulation.”

The desire to harmonize those conflicting rules gathered steam under the Biden administration, as it undertook a more aggressive push to regulate cybersecurity than prior administrations. It has continued into the second Trump administration.

The GAO scrutinized regulations that required the private sector to report cybersecurity incidents, plans and reviews to federal agencies, as part of a study sought by House Homeland Security Chairman Andrew Garbarino, R-N.Y., and the top Democrat on the Senate counterpart to Garbarino’s panel, Gary Peters, D-Mich.

In some cases, a single critical infrastructure sector could have duplication with several agencies. For example, the Cybersecurity and Infrastructure Security Agency has been working on a regulation stemming from the 2022 Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA), which would require critical infrastructure owners and operators to report when they are the victims of major attacks or make ransomware payments.

Elements of the financial services sector might fall under one of 15 preexisting cybersecurity reporting rules, depending on the agency that has oversight, but they may also be subject to the pending CIRCIA rules, GAO noted.

A 2024 national security memorandum tasked the Office of the National Cyber Director and the Department of Homeland Security to harmonize conflicting regulations, and both agencies made some progress on those goals.

But the executive branch paused some of those efforts after Trump issued an executive order in March of last year while the administration conducted a study of the 2024 memo, a study that was still underway as of last month, according to the GAO.

As such, on harmonization, “many past federal efforts have experienced delays and made limited progress,” the GAO concluded in its report Wednesday, its latest on the topic. 

Congress has also looked at ways to streamline cybersecurity regulations.

GAO’s study was focused only on federal rules. BreachRx, a cyber incident response firm, published its own report Wednesday looking at major cyber incidents and how overlapping regulatory reporting obligations came into play, folding in regulations from states and other sources.

The post Most federal cybersecurity reporting rules are duplicative, study finds appeared first on CyberScoop.

❌
❌