> daily_signal(2026_07_01)
Madison Square Garden kept a file on the activists who criticized its facial recognition, and Google is suing over an AI phishing ring that used its own Gemini model to hit 100,000 people.
PickBits Daily Signal · Wednesday, July 1, 2026
// tl;dr
- A 45GB hack of Madison Square Garden leaked a file called Facial Recognition Activists.docx. It compiled the tweets and public comments of people who'd criticized MSG's facial-recognition program, including EFF privacy lawyer Adam Schwartz. MSG has used the same technology since 2022 to keep out lawyers whose firms sued the venue.
- Google sued a Chinese cybercrime network called Outsider Enterprise for building phishing infrastructure on Gemini, Google's own AI. The RICO-and-Lanham-Act suit, backed by the FBI and all three major carriers, says the ring detected 1.59 million malicious URLs and 9,000 fake sites, defrauding more than 100,000 people.
- Virginia became the first state to write a tax on data centers' own electricity use directly into law. Its $205 billion budget adds a $0.011-per-kilowatt-hour charge on data-center power, a fiscal answer to a fight that's so far mostly landed on ratepayers.
- Portugal signed a nationwide contract with Sword Health for AI-supervised physical therapy covering all 10 million residents. A tablet and sensor correct exercise form in real time while a licensed therapist sets and adjusts the plan; Portugal reports roughly a 97% cut in wait times.
We've spent the past few weeks watching two arcs build in parallel: who gets to point AI at people who can't push back, and who actually pays for the infrastructure underneath it. Both moved hard this week. Madison Square Garden's leaked dossier and Google's own lawsuit against a scam ring built on its model both show a tool built for one purpose getting pointed at critics or victims the moment it's useful there, and it took a hack in one case and a lawsuit in the other to surface it. The power-cost fight is further along and more concrete. FERC ordered grid operators in June to speed up data-center hookups, and a shuttered West Virginia coal plant got restarted to feed one, both cases where the bill drifted to ordinary ratepayers by default. Virginia's per-kilowatt-hour tax is the first time a state legislature has intervened in that drift directly, in a budget bill rather than a utility docket. Portugal's AI-supervised physical therapy is the same always-on monitoring technology aimed at a waitlist instead of a watchlist, with a clinician still holding the judgment calls. Stronger this week: state and federal pushback on who bears AI's costs and who it gets pointed at. Weaker: the idea that a tool stays confined to the job it was built for.
This week AI got compiled into a corporate watchlist on its own critics, sued over a phishing ring that hit 100,000 people, taxed directly in a state budget for the first time, and put to work cutting a national physical-therapy wait list by 97%.
1. A hack leaked the file Madison Square Garden kept on people who criticized its facial recognition.
A watchlist built for strangers turns out to have your name on it if you complain loud enough.
Hackers stole roughly 45GB of internal data from Madison Square Garden Entertainment and posted it online this month. Inside was a file titled Facial Recognition Activists.docx, a compiled record of specific people who had publicly criticized MSG's use of facial-recognition scanning at its venues — their tweets and public comments, gathered and circulated inside the company. One of the names in the file is Adam Schwartz, privacy litigation director at the Electronic Frontier Foundation, who told 404 Media he found his own criticism sitting in the surveillance program's own paperwork. It isn't the first documented use of this technology against MSG's critics: since June 2022, MSG (controlled by James Dolan) has used facial recognition to bar attorneys from its venues if they work at law firms suing the company, a policy state legislators including Senator Liz Krueger have been fighting for years.
2. Google sued a Chinese phishing ring for building its fraud operation on Google's own AI.
The model that speeds up legitimate work speeds up fraud just as well.
Google filed suit against a cybercrime network it calls the Outsider Enterprise, alleging the ring built a subscription phishing platform: roughly $88 a week bought 290 pre-built templates impersonating banks, carriers, shipping companies, and government portals, no coding required. Subscribers then prompted Gemini to customize the HTML for each target, turning a generic toll-payment page into one matching a specific state's real DMV branding. Google says it detected 1.59 million malicious URLs between November 2025 and April 2026, 9,000 fake websites, and 2.5 million fraudulent texts in a single two-week span in May, defrauding more than 100,000 people. The suit combines RICO and Lanham Act claims, filed in the Southern District of New York with the FBI and all three major carriers — AT&T, T-Mobile, and Verizon — coordinating, and it secured an emergency worldwide restraining order. Google's own filing states plainly that its AI was used to industrialize the fraud it's now suing to stop.
engadget.com: Google seeks injunction against Chinese AI scam network (July 2026)
helpnetsecurity.com: Google sues China-based cybercrime network over AI-powered phishing (June 2026)
3. Virginia is the first state to put a price on data centers' own electricity use, in law.
The fight over who pays for the AI buildout moved from utility dockets into a state budget bill.
Virginia's $205 billion two-year budget includes a new tax of just over $0.011 per kilowatt-hour charged directly to data centers for the electricity they consume — the first time any state has written that cost allocation into law rather than leaving it to a utility commission's discretion. It arrives on top of a running arc we've been tracking since FERC issued show-cause orders in June pushing grid operators to speed up large-load interconnection for AI data centers, and since a shuttered coal plant in West Virginia was restarted specifically to feed one. In nearly every prior case, the near-term answer to "who pays" has defaulted to ratepayers: Dominion Energy customers in Virginia have watched projected residential bills more than double over the next 15 years, largely attributed to data-center load growth, even as residential demand itself has flatlined. Organized ratepayer opposition now exists in dozens of states, citing higher bills as the top complaint.
4. Portugal signed 10 million residents up for AI-supervised physical therapy.
A narrow, supervised AI job aimed at an actual bottleneck, with a number attached you can check.
Portugal's national health service, SNS, signed a nationwide contract with Sword Health to provide AI-guided physical therapy to all 10 million residents. The system is narrower than "AI does physical therapy": a tablet and motion sensor watch a patient perform prescribed exercises at home and correct form in real time, while a licensed physical therapist sets the treatment plan and checks in remotely. The AI's job is limited to real-time movement correction under that clinician's supervision. Portugal reports the approach is cutting physical-therapy wait times by roughly 97%. We haven't covered Sword Health specifically, but this sits on the same health-AI pattern we flagged with AI breast-screening triage on June 25 and bowel-screening risk detection on June 29: the useful deployment is not "AI replaces the clinician," it is "AI watches the queue, flags the next step, and lets a clinician spend time where judgment is actually needed." For Sword, the consumer asterisk is real too. A US patient using the same product through insurance described real convenience and direct access to a therapist through the app, alongside a limitation: the pre-set exercises felt generic rather than tailored to his specific injury. That is exactly the kind of gap a supervising clinician is there to catch and adjust.
statnews.com: Sword Health signs Portugal deal for AI-supported physical therapy (June 2026)
» What to watch this week
- Whether the Manhattan DA or the state liquor authority act on MSG's facial-recognition dossier. The breach exposed the practice; whether it exposes MSG to real consequences depends on findings that haven't landed yet.
- Whether more of the 100,000+ Outsider Enterprise victims come forward, and whether Google's seven legislative proposals for cross-platform fraud coordination get any traction. Civil suits and telecom coordination are filling a gap statutes don't yet cover.
- Whether any other AI-boom state follows Virginia's per-kilowatt-hour structure into its own budget. The industry's likely response is to steer the next data center toward a state that doesn't charge it; watch whether that actually happens or whether the tax holds regionally.
- Whether Portugal's 97% wait-time number holds up as the program scales past its early rollout, and whether any other national health system follows with its own supervised-AI contract.
Tomorrow's signal lands here.