Identity & Trust
eIDAS, the EU Digital Identity Wallet, BankID, NIMC, PKI, biometrics — the credentials the digital economy runs on.
Every major incident looks like its own story - AI governance one week, an enterprise authentication bypass the next, then a banking malware campaign, a cloud migration, a nation-state compromise, a national blackout. Read enough of them and the same thing keeps surfacing underneath. The breach is rarely the beginning of the story; the beginning is almost always an assumption that had never been tested. Storm-0558 exposed the assumption that a consumer signing key could never authenticate an enterprise account. ServiceNow, that the platform holding the map of every system deserved less scrutiny than the systems. Kimi K3, that self-hosting a model resolves the trust question. The Iberian blackout, that transparency and operational security are the same objective. FASTCash, that banks on shared payment rails carry risk independently. The subject of the analysis is not the technology - it is the widening distance between what organisations believe about their systems and how those systems actually behave under pressure, which may be one of the most important attack surfaces in modern security.
I saw The Lives of Others in 2011, and it shook me to my core — not the cruelty of the Stasi, but the ordinariness of it: a life catalogued by professionals simply doing their jobs. I have spent the years since watching a version of that filing system being rebuilt, not by a police state but by democracies, for reasons that are mostly good, using tools most people carry willingly in their pockets. This DSI assessment maps the six-layer identity-and-surveillance stack now in deployment across the EU, UK, Australia and beyond — identity wallets, age verification, message scanning, biometric driver monitoring, ambient audio, and behavioural data — each introduced with a genuine justification, and ungoverned in combination. It corrects the viral misreading of what Von der Leyen actually said, sets the 1984 Stasi against the 2026 stack, and closes with five dated, falsifiable forecasts and the risks I would put on any register I was responsible for. The Stasi needed forty years, 91,000 staff and 175,000 informants. The equivalent capability now needs an app, a camera, and a terms-of-service agreement — and there is no wall to tear down.
Pavel Durov says the ship of our personal freedoms has hit the iceberg and is sinking without us realising it. He is partly right, partly wrong, and entirely worth taking seriously. This GISI assessment evaluates his argument against the evidence: the UK's 30 online-speech arrests a day, Germany's platform-fining model, France's crypto-kidnapping wave, the EU's Chat Control revival on 9 July 2026, and the online-safety regimes of Australia and New Zealand. What is accurate survives scrutiny. What is exaggerated — the collapse of the distinction between Western democracies and Russia, China, and Iran — does not. The right question is not whether the West is becoming authoritarian. It is whether the architecture being built in the name of safety — age verification, identity wallets, bulk collection, biometric mandates — creates the conditions under which essential liberty becomes, in practice, optional, regardless of who governs it. The series has been asking that question. The answer, so far, is not consistently yes.
The EU's 'Chat Control' is back for the sixth time - and the way it is coming back matters more than whether it passes. Chat Control 1.0, the interim derogation letting US platforms voluntarily scan unencrypted messages for CSAM, expired on 3 April 2026 after Parliament rejected an extension 311-228 (not, as claimed, by a single vote). The Council is reviving it through a formally 'new' law with identical content: an urgent-procedure vote cleared the way 331-304 on 7 July, with the substantive vote on Thursday 10 July - the last sitting day before recess, when 361 members (an absolute majority) would be needed to stop it. Whose interest does this serve? Several at once: a genuine child-protection case; institutional pressure (four Commissioners lobbied MEPs); the EPP closing a 'legal gap' while dodging the Chat Control 2.0 vote its members are blocking; and - the interest nobody names - legal-cover restoration for Meta, Google, Microsoft and Snap, who have scanned without authorisation since April. My assessment: this is not the EU overriding democracy but circumventing it through procedure while keeping formal cover - harder to name, and harder to stop. And the surveillance architecture (EUDI Wallet, age verification, ADDW cameras) keeps building regardless of Thursday's vote. Every box is governed; the intersection is no one's job.
Our Q2 2026 Special Report. Robert Axelrod showed cooperation among rivals survives only where four conditions hold - a long shadow of the future, clear signals, enforceable reciprocity, and legible reputation. Across every domain we cover - chokepoints, ransomware, cyber attribution, the AI race, the quantum transition, digital identity, and the dollar itself - the security environment is systematically destroying those four conditions. The report scores seven games on one board, asks whose game we are actually in (China's Go, Russia's reflexive control, the West's chess), names the Defection Premium as the largest unpriced liability on the balance sheet, and grades our own Q2 forecasts in the open. Read the interactive report or download the 67-page PDF.
Since 7 July 2026, every new car and van registered in the EU must carry an infrared camera aimed at the driver's face - the Advanced Driver Distraction Warning (ADDW), specified under the General Safety Regulation. It tracks gaze, warns after 3.5 seconds' distraction above 50 km/h, and cannot be permanently turned off. The safety case is real (the wider package is projected to save 25,000+ lives by 2038) and the rule prohibits facial recognition. But the regulation mandates the hardware while leaving the data surface unanswered - retention, sharing, insurer and law-enforcement access - and the same automakers now installing it have already been documented collecting, sharing, and losing connected-vehicle data. The stronger concern is structural: the camera is always-on infrastructure, and the Commission has committed to further ADDW requirements by July 2027. My assessment: this is 'every box is governed, the space between is no one's job' arriving on the road. The camera cannot be turned off - and who benefits from what it sees, beyond the driver, is still being answered by the parties with the most incentive to answer it in their own favour.
Your voiceprint is not a password. A password can be changed; your voice cannot. In January 2021 Walmart settled for $10M over palm scans of 22,000 Illinois employees; by July it was sued over warehouse-headset voiceprints, then over uploading shoppers' faces to a Clearview AI database - three biometric systems, one company, all under Illinois's Biometric Information Privacy Act, the only US law that lets individuals sue. McDonald's, Chipotle, Verizon, Microsoft Teams face the same claims; 107 BIPA class actions were filed in Illinois in 2025 alone. In 47 of 50 states, collecting your fingerprint, face, or voiceprint needs no consent, no disclosure, and carries no consequence. Under GDPR Article 9 it is special-category data requiring explicit consent, with fines to EUR 20M or 4% of turnover - and the EU AI Act bans workplace emotion inference from 2 August 2026. My assessment: this is not a regulatory gap but a policy choice, applied to the one category of data that is permanent. If the database holding your voiceprint is breached, the credential is compromised for life - and in 47 states no one is obliged to tell you.
Is there an industry ShinyHunters has not breached lately? Food distribution, healthcare, higher education, entertainment, telecoms, finance, the Council of Europe. Sysco: 61 million Salesforce records claimed on 16 June, published after the 18 June deadline, 2,691,852 confirmed on HaveIBeenPwned by 28 June. The question is not who they target. It is whether sector, size, and security budget are all secondary to one variable: whether an unrevoked OAuth token is sitting in your Salesforce connected apps or a 2023 code commit. My assessment: ShinyHunters is not a group you arrest but a brand and a playbook that outlive their operators — one industrialised technique (voice-phish an employee or scan GitHub for forgotten tokens, both bypassing passwords; enumerate the CRM; loop and exfiltrate; extort). The reason the industry keeps being surprised is not sophistication. It is that the monitoring is pointed at the boxes, and the attack happens in the space between them. Every box is governed — identity, exposure, data, software, AI, supply chain, governance. The space between is no one's job. That argument is now a book: The Wrong Map, reading cybersecurity as political economy across Susan Strange's four structures. Contributors welcome — especially the dissenters.
In June 2024, Paradigm Initiative proved the largest data leak in Nigerian history by buying it: for 100 naira a record, rogue sites were selling the NIN, BVN, passport, and phone number of 104 million Nigerians from NIMC's database, including the slips of the digital-economy minister and the national data regulator. On 27 June 2026, President Tinubu signed the NIMC Act 2026, replacing a 19-year-old law, and named that same commission the Root Certification Authority for Nigeria's national PKI. My assessment: the Act hardens the cryptography, but the 2024 breach was never cryptographic. It leaked through custody and access, third-party agents with legitimate credentials, the exact layer a certificate hierarchy does not fix. The new 14-agency board (INEC, DSS, EFCC, CBN, the population commission, the national security adviser) concentrates the state's coercive machinery around one dataset. For every Nigerian fintech, identity verification now chains to a single sovereign root you cannot switch away from, held by a custodian with a demonstrated breach history. The law is overdue and much of it is sound. But a root of trust is the one credential that cannot be reissued, and it now sits on the custody layer that already failed once, at the scale of a nation. What to watch: the secondary regulations, the data regulator's enforcement teeth, the access-governance layer, and whether any redress ever reaches the 104 million.
In March 2026, FulcrumSec found an Azure Container Registry token in a public JavaScript bundle on a Novo Nordisk subdomain. Two months later it had walked out with 1.3 terabytes: 41,000 drug compounds, 30 trained AI models, and a marketed drug's manufacturing recipe. The pharmaceutical industry's credential problem, mapped globally.
985,000 passports and driver's licences sat on public URLs with no password, no access control, nothing. No hack, no exploit chain. The custodian was not a government agency or a bank but Nefos Solutions, a two-person Irish startup that built membership software for Spanish cannabis clubs, with a Stripe key in plain text inside its app. My assessment: this is not one breach. France Titres (national identity agency, IDOR found by a 15-year-old, 11.7M records), the UK Visa Portal (guessable URL, 100,000+ passports), the Texas hunting-licence vendor (third-party breach, 3.09M Texans), and Nefos (public URL, 985,000 passports) are four expressions of one structural reality. From the most capable national agency to a two-person startup, the security outcome is identical: government identity documents on the open internet. The EU's age-verification mandate will create thousands more Nefos-scale custodians collecting the one category of data that cannot be reset. Identity documents are only as secure as the weakest custodian in the chain that now holds them. Extends the DSI EU regulatory series: France Titres, the EUDI Wallet, and the age-verification oxymoron.
After the October 2023 Okta compromise, Cloudflare rotated more than five thousand credentials. On Thanksgiving Day a nation-state actor walked into its Atlassian environment anyway — through the four machine identities the rotation missed: a Moveworks service token, a Smartsheet account with admin rights to Jira, a Bitbucket account reaching source code, an AWS credential. Every one a non-human identity nobody believed was theirs. This is Part II of the cross-cutting threat analysis: a vulnerability is a property of a component, a threat is a property of the system, and the actors crossing your organisation are now overwhelmingly not human. Machine identities outnumber people by as much as eighty to one, nearly half hold privileged access, and OWASP now publishes a separate Top Ten for them. A service account is a seam with permissions — connective tissue that spans the boundaries human silos are built around, held by an account no team owns. And the seam has begun to act: AI agents are non-human identities that reason, hold credentials across every silo at once, and can be redirected by a planted instruction at machine speed. The fix is the same operating model from Part I, extended to actors that are not people: every machine identity and every agent needs a named owner, a defined scope, an expiry, and a decommissioning trigger. Run the removal test this afternoon — pick any service account or agent and ask who owns it, what it can do, and when it expires.
On 12 January 2024, a Russian state actor read the email of Microsoft's senior leadership. Not through a zero-day — through a forgotten legacy test tenant with no MFA, an over-permissioned OAuth app, and an elevated consent grant nobody owned. The path crossed four domains; not one team owned the route. Every control was green. Storm-0558 was the same shape: a consumer signing key accepted as valid for enterprise mailboxes — a seam between two identity planes. This is the failure the industry refuses to name. A vulnerability is a property of a component; a threat is a property of the system. We have spent two decades building frameworks that make each silo defensible in isolation and almost no time building the thing that lets a defender reason across them the way an attacker already does. The fix is not another framework. It is an operating model — decision rights, intake, prioritisation, governance, delivery engagement — the connective tissue that owns the seams. Run the removal test: if your security function vanished tomorrow, would any business decision change? Part I of two. Part II continues on ARIA.
National PKIs are the cryptographic substrate of every modern state — tax filing, healthcare records, qualified electronic signatures, eID cards, government TLS, and the diplomatic identity that authenticates inter-state messages. They were architected for an adversary who could not yet exist. The first post-quantum PKI migration is now under way, at scale, in the history of the discipline. NIST finalised FIPS 204 (ML-DSA), FIPS 205 (SLH-DSA), and the stateful hash-based track in SP 800-208. The BSI’s TR-02102-1 update of 23 January 2026 names end-of-2031 and end-of-2035 as the migration floors. The German V-PKI assessment is the public canary. The deeper reality is that every national PKI on the planet faces the same trade — and every candidate signature scheme loses on something that matters. The algorithm is the visible decision. The portfolio is the operational decision. The systemic cascade across HSM firmware, X.509, TLS, OCSP, smart cards, eIDAS QSP regime, browser stores, mail clients, code signing, and eID issuance is the actual project. Ten jurisdictions mapped against the convergent 2031–2035 calendar, with three original diagrams and the practitioner frame for the migration the regulators have only begun to describe.
China was first. The EU is third. Singapore governs what neither directly reaches. China’s CAC Measures + GB 45438-2025 took effect 1 September 2025, with audits since October and enforcement actions from January 2026. Singapore’s IMDA Agentic AI framework launched at Davos on 22 January 2026 — non-binding in form, procurement-binding in practice. EU AI Act Article 50 activates 2 August 2026; existing GenAI systems get until 2 December for the marking requirement specifically. California’s SB 942 / AB 853 has been binding for two years. Three different enforcement postures. One convergent architectural requirement: AI-generated content and AI agent actions need to carry a verifiable, machine-readable record of their provenance. The strategic read for builders shipping into global markets, and the architecture that satisfies all four regimes when built once correctly.
ServiceNow’s third authentication bypass in eight months — and the first where attackers reached customer data before a patch was applied. The June 2026 REST endpoint shipped with requires_authentication=false. IP 51.159.98.241 queried tenant tables on June 2–3. The patch landed silently on June 5. Public disclosure on June 9, gated behind a customer support login. October 2025 (BodySnatcher impersonation), January/February 2026 (AI sandbox RCE), and now this. Three components. Three mechanisms. One consistent root cause category. ServiceNow is the system the organisation tells everything to. In this framing, it is not the target — it is the map. The ITSM blind spot in enterprise security architecture, and the question every security team should be asking about every platform that knows about everything else.
Part I of the Governance Gap trilogy. The Chokepoint Doctrine series’ central finding, stated as its central thesis for the first time: no institution has the mandate, the expertise, and the authority to govern the full threat surface of any critical system simultaneously, and the adversary’s operational architecture is specifically designed to exploit the space between the institutions that cannot coordinate fast enough. The three wrong questions Western institutions are asking — What is the adversary doing? Which institution is responsible? How do we deter the adversary? — and the right questions that should replace them. The governance gap is the chokepoint. Everything the series has documented is a symptom.
Inaugural DSI Intelligence Brief. Mike Yeagley — the government contractor named in Senator Wyden’s 28 May 2026 letter, the person who in 2016 tracked US special operations forces from Fort Liberty to a covert Lafarge cement factory in Syria using commercially purchased advertising data — has now responded to Wyden in a formal congressional letter. The response advances the argument in three directions: the inference layer (“You no longer carry a name. You carry a pattern. Behaviour is your identity.”), the ambiguity doctrine (privacy as the standing condition of the operator’s life, maintained by architecture, not as a setting), and a decision-forcing body with a 90-day deadline to set technical standards for what applications may collect on a Department of War–managed device. Also: the EU age-verification piece concludes the regulatory series; the connected vehicle piece arrives later in the week.
Smart-TV ACR (Automatic Content Recognition) fingerprints the screen every 500 milliseconds, captures every HDMI input — work laptops, consoles, paired phones — ties the fingerprint to the household IP, and sells. Samsung admitted the architecture out loud in 2015 (in writing, in its privacy policy, transmitting plaintext audio to a third party). The Vizio FTC settlement was 2017. The Texas Attorney General sued five manufacturers in December 2025; Samsung settled on 26 February 2026; Sony, LG, Hisense and TCL are still fighting. The European Union has GDPR and the ePrivacy Directive and has not enforced. This is the fourth node of the DSI commercial-surveillance mosaic after adtech, connected vehicle, and the Handala OSINT convergence. Orwell got the architecture right and the operator wrong: the modern telescreen works for whoever pays.
130,000 UK Mercedes records on a cybercrime forum. Toyota's decade-long location-data exposure across 2.15 million customers. VW feeding driver location to law enforcement. The Mercedes breach is the visible surface rupture; the architecture beneath is a surveillance contract you signed when you bought the car.
Atlassian terminated sixteen hundred employees on the eleventh of March 2026. Six weeks later an eight-year veteran of the edge infrastructure team uploaded a thirty-eight-minute YouTube video walking through the company's entire production architecture. Some viewers called it the best free system design lesson on the platform. They were also describing, in different words, a complete operational security disclosure for any actor that wanted to attack the company. The AI replacement doctrine has produced the largest involuntary supply of high-context insider threats in the history of the industry, and the demographic concentration is in the cohort that holds the most institutional memory. The DSI reading of what comes next.
France’s national identity agency — the system managing every passport, ID card, and driver’s licence in the country — was breached by a 15-year-old exploiting an IDOR vulnerability so basic the attacker called it “really stupid.” 11.7 million records confirmed exposed. France was one of six EU member states rated “high preparedness” for the EUDI Wallet. The wallet that 450 million Europeans will use from December 2026 depends on these same government identity APIs for its initial provisioning. The certification standard does not yet exist. Part 4 of the EU Regulatory Landscape series.
The United States is demanding access to European biometric data under threat of revoking visa-free travel for 450 million EU citizens. HIPAA protects American health data from any foreign government. The GDPR was supposed to do the same for Europeans. The asymmetry of this arrangement is the question nobody in Brussels is answering.
ENISA has confirmed in writing that no security standard for the EU Digital Identity Wallet is available or foreseen to be available by the deployment deadline. The first generation of wallets will be certified against national schemes of varying robustness, not a unified European standard. The weakest wallet in the EU becomes the entry point for every service provider required to accept it.
Within twenty days in March and April 2026, the EU rejected mass surveillance of private messages by a single vote and launched a government age verification app built on the same infrastructure as the EU Digital Identity Wallet. The two decisions are not contradictory in intent. They are contradictory in architecture. This is Part 1 of the DSI EU Regulatory Landscape series.
In 2012, Iran hit 46 US banks with 140 Gbps DDoS attacks in response to SWIFT sanctions. In March 2026, the IRGC publicly named US and Israeli-linked banks as military targets. Citi, Goldman, Standard Chartered, and HSBC evacuated Gulf offices. Sixty hacktivist groups are active. Handala deploys wiper malware that permanently destroys data. The Bangladesh Bank precedent shows 32 days to restore SWIFT access. AI-generated deepfakes target the human authentication layer above every technical control. The financial chokepoint is where a successful attack disrupts the trust architecture the entire global economy depends on.
The EU AI Act demands conformity assessments. Nigeria's AI bill requires mandatory registration. Kenya just forced Worldcoin to delete all biometric data. India chose no risk classification at all. For organisations deploying AI across African markets, the regulatory fracture is not a governance challenge — it is a barrier to existence.
Series Manifesto. On a Tuesday morning in Malmö, Sweden's digital identity system went dark. That same week, an Iranian ballistic missile test demonstrated range to reach Berlin. A cable ship declared force majeure. None of these are the same story. All of them are the same story.
Digital Identity: The Battle for Your Digital Soul — Part 3.75. Someone stole the architectural blueprints to Sweden's digital home. Not a break-in — something far more dangerous. The CGI breach exposed source code and credentials for systems integrating with BankID, used by 8.6 million Swedes.
Digital Identity: The Battle for Your Digital Soul — Part 3.5. Three million citizens signed a petition overnight — not for something, but against something. Against the transformation of their smartphones into digital leashes. This represents the first major defeat of WEF-style digital identity frameworks.
Digital Identity: The Battle for Your Digital Soul — Part 2. You're standing in a Copenhagen train station in 2004, about to become an unwitting witness to one of the most significant social experiments in human history: the voluntary surrender of an entire population's privacy.
Digital Identity: The Battle for Your Digital Soul — Part 1. Imagine waking up to find your smartphone has become your ankle bracelet. After two decades in Scandinavia, I've seen how quickly digital infrastructure becomes invisible once it's normalised.