Key developments
Supreme Court restricts geofence warrant use
The U.S. Supreme Court ruled 6-3 in Chatrie v. United States that police acquisition of a person’s cellphone location data from a third-party technology company is a Fourth Amendment search, The Maine Wire’s Libby Palanza reported. Pennlive’s analysis says the case involved a Google geofence warrant covering a 17.5-acre area in Midlothian, Virginia, over two hours after a 2019 bank robbery, including residences and a church. The Court remanded the case to the 4th U.S. Circuit Court of Appeals to decide whether the warrant’s multi-step process met Fourth Amendment requirements.
Why it matters
The decision narrows law enforcement’s ability to use broad location sweeps that identify everyone near a place before investigators have individualized suspicion.
Sources & driving stories
THE MAINE WIRE · Libby Palanza
The Maine Wire coveragePENNLIVE
Pennlive coverageMedtronic and Kubota disclose sensitive breaches
QPulse reported that Medtronic confirmed unauthorized access to corporate IT systems from April 13 to April 19, affecting 3,834,294 people and exposing names, contact details, dates of birth, Social Security numbers and health-related information. The ShinyHunters extortion group listed Medtronic on a Tor leak site on April 18 and claimed more than 9 million stolen records, though Medtronic said it found no evidence of public release. Gblock’s Jacopo Beschi reported that Kubota North America disclosed unauthorized network access from March 16 to April 20 involving HR files with employee and dependent Social Security numbers, government IDs, taxpayer IDs, direct deposit bank details and benefits records.
Why it matters
Both incidents involve high-risk identifiers that can drive identity theft, health privacy exposure, payroll fraud and long-tail phishing.
Sources & driving stories
QPULSE
QPulse coverageGBLOCK · Jacopo Beschi
Gblock coverageSingapore SLA reports IBM cloud data exposure
Must Share News’ Asyiqin Nadzri reported that the Singapore Land Authority said about 70,000 people may have had names, NRIC numbers and property addresses exposed after unauthorized access to an IBM-managed cloud environment. SLA said the affected dataset was meant for mock and anonymized development and testing but improperly contained real personal data from property ownership and lodgement records. SLA said live STARS, eLodgment and other operational systems were not compromised; it has begun notifications, filed a police report and notified Singapore’s Personal Data Protection Commission.
Why it matters
The incident shows how vendor development environments and failed anonymization can expose government-held identity and property data even when production systems remain intact.
Sources & driving stories
MUST SHARE NEWS · Asyiqin Nadzri
Must Share News coverageWorth noting
WORTH NOTING
World Cup surveillance build-out scrutinized
Fast Company reported that U.S. World Cup security preparations include more than $1 billion for monitoring transit hubs, stadiums and surrounding areas, while Amnesty International, the ACLU and others warned visitors about social media screening, device searches and profiling risks.
WORTH NOTING
Australia teen social ban falters
New York Magazine’s John Herrman reported that BMJ researchers found Australia’s under-16 social media ban has been lightly implemented, often circumvented and tied to broader age-verification privacy costs for adults and minors.
WORTH NOTING
EU-US transfer risk resurfaces
Mondaq’s Marie McGinley argued that Trump v. Slaughter may weaken the perceived independence of the FTC, increasing legal risk for the EU-US Data Privacy Framework and prompting anticipated challenges from NOYB.
Still unclear
OPEN QUESTION
How narrow will geofence warrants become?
The Supreme Court recognized location-data acquisition as a search but left lower courts to decide whether specific geofence warrant procedures satisfy probable cause and particularity requirements.
OPEN QUESTION
Are test environments becoming breach weak points?
The SLA incident suggests anonymization failures and vendor-managed development systems can create privacy exposure outside live production infrastructure.
