Governments are broadening digital surveillance through a mix of network interception, lawful intercept platforms, deep packet inspection, mandatory data retention, endpoint spyware, platform monitoring, and public-space surveillance, according to a new risk assessment. The report highlights Russia’s opaque SORM model as a prominent example of state interception architecture and says Chinese and Russian surveillance technologies are being exported to multiple countries, extending these capabilities beyond their domestic markets.
The assessment says commercial spyware including Predator, Candiru, Pegasus, and Paragon has been used against journalists, activists, and civil society, while newer laws and policies in countries such as Ecuador, Myanmar, Nicaragua, Vietnam, Cambodia, Kyrgyzstan, Russia, and Kazakhstan are expanding state access to communications, metadata, biometric records, and internet infrastructure. It also points to growing use of Safe City platforms, facial recognition, IMSI catchers, national messenger apps, digital ID systems, and centralized biometric databases, warning that weak oversight raises risks ranging from privacy abuses and human-rights violations to corporate espionage, zero-day exploitation, and exposure of sensitive personal data.

See the reporting duties and controls this puts on the clock.
2 events from the most recent confirmed update back to the earliest known activity.
The Metropolitan Police Service said it plans to deploy static live facial recognition cameras in London's West End and Soho by the end of 2026. The move follows a six-month Croydon pilot in which police said 24 deployments between October 2025 and March 2026 led to 173 arrests and one false alert.
Recorded Future's Insikt Group published an analysis of digital surveillance practices across 193 countries, describing risks from lawful intercept systems, spyware, biometric databases, AI-enabled public surveillance, and weak oversight. The report assessed 31 countries as high or very high risk and 55 more as medium risk.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
3 references tracked. Mallory keeps watching after this page renders.
theregister.com
Open sourcecybersecuritynews.com
Open sourcerecordedfuture.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.