← Deleted Dispatch
Deleted Dispatch
redditopenaigooglesnowflake

Deleted Dispatch

A face match sent federal agents to the wrong man

By deletedby · August 20, 2026 · 5 min read

Deleted Dispatch is a weekly read on security, OSINT and privacy news. This week runs on one thread: the things you put in public, or thought were long gone, keep getting turned into something else. A face becomes a match. A comment becomes training data. A medical record becomes a breach notice.

A face match sent agents to the wrong man

A 3D wireframe render of a human face with glowing eyes on a black background, representing facial recognition
A face reduced to points for matching. Photo: A Chosen Soul / Unsplash.

A discovery motion filed on August 13 in Minneapolis, on behalf of Isaac Sant, one of fifteen people charged with impeding a federal immigration operation, put the government's own surveillance records on the docket. Among them were at least two Clearview AI search reports. One did not return Sant. It returned photos of a different man as possible matches, and pulled in Facebook images of that man's wife and child. The filings describe the facial recognition as one part of a larger intelligence file that also drew on vehicle records and social media, alongside undercover agents sitting in on community meetings, recording conversations at churches and union halls, and an agent using an alias to enter an encrypted Signal chat.

Primary source: Minnesota Reformer. Corroborating: Biometric Update. Confidence: confirmed, from a court filing and multiple independent outlets.

Clearview works by matching a face against billions of images scraped from public websites and social media. When the match is wrong, it does not fail quietly. It hands investigators a name, a family and a set of photos that belong to someone else. Everything anyone has posted in public is in that pool, and being the wrong match is its own kind of exposure.

Your posts are a $43 million line item

Close-up of a phone home screen showing the Reddit, Facebook, TikTok and Instagram app icons
The apps whose posts get licensed for training. Photo: Ralph Olazo / Unsplash.

Reddit's second-quarter results, covered on August 17, put its data licensing revenue at $43 million for the quarter, up 24 percent on the year and about 5 percent of $805 million in total revenue. The two largest buyers named are Google and OpenAI, which license the posts and comments people write and feed them to language models. It is a small slice of the business, but it is a growing one, and it runs on user-generated content rather than anything Reddit makes itself.

Primary source: The Motley Fool. Corroborating: Crypto Briefing. Confidence: reported, from earnings coverage rather than a single breaking event.

This is the quiet half of the deleted-content problem. Delete a post later and you remove the copy on the site, but the copy that was already licensed and folded into a model is out of your hands. The words were public by design. What is new is that they now carry a per-quarter price and two very large buyers.

A records vendor lost 3.75 million people

Hands typing on a laptop with a stethoscope resting in front of it
Records that pass through one vendor reach many patients. Photo: National Cancer Institute / Unsplash.

CareCloud, a New Jersey firm that stores electronic medical records for healthcare providers, confirmed in a filing with the Department of Health and Human Services on August 18 that a March intrusion exposed data on more than 3.75 million people. Attackers reached one of its cloud storage environments and had access for about six days. What they took is close to a full identity file: names and addresses, Social Security numbers, medical and health information, passports and driver's licenses, and banking and financial details. The count was revised up sharply from a much smaller early estimate, and notifications began in late July.

Primary source: TechCrunch. Corroborating: SecurityWeek and BleepingComputer. Confidence: confirmed, from the company's own filing.

Health data is the category you cannot rotate. You can change a password or a card number, but not a diagnosis or a Social Security number. When one vendor sits between you and dozens of providers, a single breach reaches far more people than any one clinic ever could. That is the shared-vendor pattern again, and it is the one that keeps producing these seven-figure counts.

An AI agent found the bug. Who wrote it is the argument

A code editor and terminal running tests, with an AI assistant log panel in the sidebar
An AI-assisted coding session, the kind of automation at issue. Photo: Bernd Dittrich / Unsplash.

Security firm Wiz disclosed a flaw on August 17 in Snowflake's public snowflake-connector-net repository. A GitHub Actions workflow dropped an attacker-controlled issue title straight into a shell command, so anyone who opened an issue could run commands on the build runner and reach a Jira token that covered engineering, security compliance and bug bounty projects. Wiz found it with an autonomous agent it calls Red Agent, reported it through HackerOne on June 23, and Snowflake fixed it the same day and rotated the token. Snowflake says its logs show no sign the token was used.

Primary source: The Hacker News. Corroborating: Wiz and Cybernews. Confidence: confirmed for the flaw and the fix; the claim about who wrote the line is disputed.

The headline that traveled was that GitHub Copilot's Autofix wrote the vulnerable line. That part is contested. Follow-up reporting notes Copilot's clear authorship was in a different file, not the change that introduced this flaw, so treat "an AI tool wrote a critical vulnerability" as unproven for now. Two things are true at once here. An AI agent really did find a supply-chain bug in a major vendor's automation, which is a fair preview of where this work is heading. And the catchier claim, that an AI wrote it, is the one to check before you repeat it.

See how removed and deleted content plays out on any subreddit, or look up a Reddit user.