:

DHS USED 1930S LAW TO DEMAND GOOGLE DATA ON CANADIAN

INDUSTRY DESK2 MIN READ
SUN, MAY 24, 2026

■ AI-SUMMARIZED FROM 4 SOURCES ▸ TIMELINE

The Department of Homeland Security demanded Google surrender location and activity data on a Canadian citizen who criticized ICE operations online. The man, who hasn't entered the US in over a decade, was targeted using an obscure trade statute from the Great Depression era.

DHS invoked the International Emergency Economic Powers Act—a 1930s customs law—to pressure Google into handing over browsing history, location data, and other activity information on the Canadian national. The request followed his posts on X condemning ICE following the deaths of Renee Good and Alex Pretti. The case highlights how legacy legislation can be repurposed for modern surveillance. The law, originally designed for trade enforcement, gave DHS leverage to demand user data without a traditional warrant or court oversight. Google's response to the demand remains unclear, but the incident raises questions about how tech companies handle government data requests using unconventional legal frameworks. It also underscores risks for non-US citizens whose speech on global platforms can trigger US government scrutiny. The action comes as the White House simultaneously escalates tech oversight in other areas. The administration recently briefed Anthropic, Google, and OpenAI on plans for a government AI review process—potentially requiring companies to submit new AI models for government approval before release. The proposal reportedly triggered by Anthropic's "Mythos" model follows a year of relative regulatory hands-off approach. Separately, Google is developing new AI capabilities that could blur lines between user control and autonomous action. The company is testing an agent codenamed "Remy" within its Gemini app that can integrate with Google services and take actions on a user's behalf—raising privacy and security implications as AI systems gain deeper access to personal accounts. Together, these developments paint a picture of increasing government pressure on tech companies and expanding AI capabilities with limited transparency around data handling and government access.

■ SOURCES

WiredThe DecoderArs TechnicaTechmeme

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

Iran-linked hackers have compromised approximately 100 American water utilities in a sustained campaign targeting critical infrastructure. The EPA is allocating $11 million in funding to strengthen cybersecurity defenses across water systems.

JUST NOWSecurity Desk

Attackers exploited BGP routing vulnerabilities to redirect Virtualizor VPS management software update requests to malicious servers. The compromise affected users attempting to download legitimate updates for the widely-used hosting control panel.

JUST NOWSecurity Desk

A critical authentication bypass vulnerability in JFrog Artifactory is being actively exploited to create administrative access tokens. The flaw (CVE-2026-82329) grants attackers full control over software repositories.

JUST NOWSecurity Desk

Spyware was used against Serbian student activists and politicians organizing anti-corruption protests ahead of March local elections, according to a new report. The targeting allegedly focused on opponents of President Aleksandar Vucic.

JUST NOWIndustry Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.