Nobody Watched Who Saw the ID Photos (09/18/2026)
- › A DHS watchdog found TSA lacked oversight of vendor access to passenger identity document images.
- › Boston city councilors say they were not told police had bought AI-powered social media monitoring.
- › Data from home robots and smart devices is being introduced as evidence in court.
- › Consumer Reports found companies make it materially difficult to exercise access rights under state privacy laws.
- › Fake passkey setup requests are being used to compromise Microsoft 365 accounts.
A government agency collects your identity document at a checkpoint you cannot decline to pass through, and the watchdog report today says nobody was tracking which vendors could reach the images afterward. The collection was mandatory and the oversight was not.
Top 5 Critical Privacy Alerts
1. TSA Did Not Track Who Could Reach Passenger ID Images
The DHS Office of Inspector General found that TSA lacked oversight of vendor access to passenger identity document images. A traveler presenting identification at a checkpoint has no alternative and no negotiating position, which is exactly the circumstance that should attract the strictest handling downstream. The finding is about access management rather than a breach, and access management is what determines whether a breach is possible. Biometric Update has the report.
Operator Note: For any dataset you cannot let people opt out of, keep a current list of every vendor account that can read it, because that list is the control an inspector will ask for first.
2. Boston Councilors Say They Were Not Told About Social Monitoring
Boston police used AI-powered social media monitoring software and city councilors say they were not informed of the purchase. This lands two days after Boston canceled its plate reader contract over a different disclosure failure, which makes two surveillance oversight gaps in the same city in one week. The pattern in both is procurement moving faster than the body that is supposed to authorize it. PogoWasRight has the reporting.
3. Your Home Robot Can Be Called as a Witness
Data from home robots and other smart devices is being introduced as evidence in court proceedings. A device that maps your floor plan, logs when rooms are occupied, and records the times a household is empty produces a detailed account of domestic life that nobody bought it to produce. The legal questions are being worked out case by case, well after the devices reached millions of homes. PogoWasRight has the analysis.
4. Access Rights Exist and Are Hard to Use
Consumer Reports found that companies make it materially difficult to exercise data access rights granted by state privacy laws, through processes that are slow, incomplete, or effectively unnavigable. A right nobody can practically use is a right in name, and the difficulty is rarely a single refusal so much as an accumulation of steps that exhausts the requester. The finding is useful precisely because the laws are working as written and the outcome is still poor. PogoWasRight has the study and EPIC has the summary.
Operator Note: Have somebody outside your privacy team submit an access request to your own company and time it, because the experience you designed and the experience people get are rarely the same.
5. Fake Passkey Setup Requests Are Taking Microsoft 365 Accounts
Attackers are compromising Microsoft 365 accounts through messages impersonating passkey enrollment. We flagged this pretext on Monday when Microsoft first described the campaigns, and it has continued because the rollout it imitates is genuinely happening at most organizations right now. A security improvement in progress is the most credible thing an attacker can impersonate. Biometric Update has the campaign.
Additional Privacy Alerts
Digital Identity
- Westpac is the first New Zealand bank accredited to issue digital credentials: Bank-issued identity moves verification into an institution people already have a relationship with. Biometric Update
- Malaysia’s digital ID is becoming difficult to decline: Analysis describes the point at which an optional national identity scheme stops being optional in practice. Biometric Update
The Axe Report is a daily briefing from Grab The Axe. Need help assessing your organization’s security posture? Take our free Human Attack Surface Score assessment.
A PhD candidate in Health Psychology and former Corrections Officer, Jeff founded GTA to dismantle passive security models. He focuses on the 'Human Zero-Day', mitigating executive burnout and decision fatigue before they become security breaches.
View Profile →Media Inquiries
For expert commentary, interview requests, or high-res assets regarding this announcement, initialize the terminal.