The surveillance news that affects your household — without the noise.
● Now accepting signups
Stay Ahead of What's Watching You
ISPs are billing you for access and selling your behavior to advertisers. Government agencies are buying location data without warrants. Surveillance infrastructure is compounding faster than most people realize. We cover it when it matters, not on a schedule.
No tracking pixels. No third-party sending. Unsubscribe in one click.
The incidents below are real, sourced, and in most cases still unresolved. They represent the structural problem GhostPort exists to address: the people paid to connect you to the internet have a parallel business in profiling and monetizing that connection — and the law hasn't caught up.
● ISP / AI • January 15, 2026
Starlink enrolled 9 million subscribers in AI training — by default, without announcement
On January 15, SpaceX quietly updated Starlink's global privacy policy to allow the use of customer data — including location, IP addresses, payment details, and behavioral inferences — to train machine learning models, including by third-party AI collaborators. The change applied automatically to all 9 million-plus subscribers. No email was sent. No notification appeared in the app. Customers who didn't scroll to the bottom of their account settings to uncheck a box were opted in. A November 2025 archive of the policy confirmed this language did not previously exist.
● ISP / Advertising • Full Year 2025
Comcast's residential broadband division logged $3.7 billion in ad revenue from customer data
Comcast's Residential Connectivity & Platforms segment — the division that provides Xfinity internet service to roughly 30 million US households — recorded $3.7 billion in advertising revenue in 2025, per their annual SEC filing. The revenue model: customers pay monthly for access; Comcast analyzes behavioral data derived from that access and sells targeting to advertisers. No federal law requires them to obtain consent for this in most states. The FCC's net neutrality rules, which provided some framework for this, were vacated by a federal appeals court in early 2025.
● Data Breach • 2026
40 million Charter (Spectrum) customer records stolen by criminal gang
A criminal group obtained at least 40 million records from Charter Communications, the ISP behind the Spectrum brand. Charter is the second-largest cable ISP in the United States. The breach illustrates a compounding risk that's easy to miss: your ISP collects your data through normal business operations, and then that same data becomes a high-value target for criminal exfiltration. Privacy exposure isn't just a policy question — it's a security surface that grows with every byte they retain about you.
● Government • April 2026
FBI declared a major incident after its own surveillance system was compromised
In April 2026, the FBI declared a major cyber incident after identifying that one of its domestic surveillance systems had been breached, potentially exposing the phone numbers of people under federal surveillance. The same month, the House voted to extend Section 702 — the surveillance authority that permits NSA collection of communications involving foreign targets, which routinely sweeps in American communications — over bipartisan objections. The dual event: the infrastructure of surveillance was breached, and the legal authority powering it was extended anyway.
● AI Surveillance • Ongoing 2026
Federal agencies are pushing to use AI on warrantless data broker purchases
Multiple US agencies have been lobbying to apply AI analysis to data purchased commercially from data brokers — data obtained without warrants, justified under the third-party doctrine courts are slowly narrowing. Talks between Anthropic and the Department of Defense collapsed after Anthropic required safeguards against using their AI for mass surveillance of Americans. The market for warrantless surveillance data + AI analysis is real and actively being expanded by the same entities nominally responsible for oversight.
● What Actually Helps • California, August 2026
California's DELETE program re-runs deletion requests against data brokers every 45 days
The California Delete Request and Opt-out Platform (DROP), authorized by the California Delete Act and operated by the California Privacy Protection Agency, now submits deletion requests to over 500 registered brokers on your behalf — and re-runs them every 45 days so newly collected data gets swept too. It's the most powerful single privacy tool available in the US right now. California residents: use it. Everyone else: your state almost certainly doesn't have the equivalent.
📱
ISP Tracking Alerts
When major ISPs change their data policies, get caught selling data, or face regulatory action — you find out from us before the news cycle buries it.
⚖
Surveillance Legislation
Section 702 renewals. Data broker bills. State-level privacy laws. The legislative calendar that directly affects what agencies can do with your data — and when.
🔐
GhostPort Product Updates
New features, security patches, architecture changes, and the honest engineering notes that go into building privacy hardware that holds up under scrutiny.
📊
Data Breach Digests
Not every breach. The ones where the data collected, the failure mode, or the downstream risk tells you something you can actually act on.
We're a privacy hardware company. If we ran a surveillance newsletter, that would be the most embarrassing possible failure of values alignment.
Your email address isn't a product. It's a way to reach you. We treat it accordingly.
Already subscribed? You're set — no need to sign up again.