> daily_signal(2026_07_07)

A hacking group notified 3.8 million Medtronic patients their data was stolen, while the FCC closed the four-year-old loophole that let old Huawei and ZTE gear keep entering US networks.

PickBits Daily Signal · Tuesday, July 7, 2026

By Mark Pickering · 9 min read · July 7, 2026

// tl;dr

A pacemaker gets engineered to the highest safety bar in medicine. The corporate database sitting next to it, tracking who owns one and why, runs on ordinary IT security, and ordinary IT security is exactly what a hacking group found a way into: Medtronic is notifying 3.8 million patients that their Social Security numbers went with it. The FCC has a similar gap story: its 2022 Huawei and ZTE ban covered new equipment only, and the older gear it left alone stayed a live national-security risk for four more years until this week's expansion finally closed that door. Money moved differently in the other two stories. Anthropic's $1.5 billion settlement has been paying authors about $3,000 a title since last month, and a hundred of them just decided a federal judge might value their case at fifty times that. And after three real fire seasons of data, California's AI-watched wildfire camera network posted a number worth trusting: more than half of last year's 3,600 incidents caught before anyone dialed 911.

Today: a hacking group notified 3.8 million Medtronic patients, the FCC banned decades-old Huawei and ZTE gear outright, a hundred authors sued Anthropic individually over book piracy, and California's AI wildfire cameras beat half of last year's 911 calls.

1. A hacking group threatened to leak 9 million Medtronic patient records. The company is now notifying 3.8 million people it happened anyway.

The device is engineered obsessively. The database next to it wasn't.

Medtronic, the world's largest medical device maker, confirmed on April 24 that an unauthorized party accessed data in its corporate IT systems sometime between April 13 and 19. The extortion group ShinyHunters claimed responsibility, listing Medtronic on a dark-web extortion portal and threatening to publish roughly 9 million records unless paid by April 21. Medtronic didn't pay; the listing was later removed, and the company says there's no evidence the stolen data has been published or exposed online as of this reporting. Notification letters went out starting in late June, and on July 6 Medtronic disclosed the confirmed total: 3.8 million people, with names, contact information, dates of birth, Social Security numbers, and health-related information tied to their device use all taken.

This is the second med-tech company hit this year; in March, device maker Stryker disclosed that Iran-linked hackers wiped systems that fed emergency medical services in Maryland. Neither attack touched how the devices themselves function, which is worth holding onto: a pacemaker or insulin pump is a closed, obsessively tested system. The corporate database sitting next to it, tracking who owns which device and why, runs on ordinary IT security, and ordinary IT security is exactly what an extortion crew found a way into.

Why this matters: If you or someone you love uses a Medtronic device, this notification is real, not spam, and the danger isn't the device, it's what a hacking group can do with your Social Security number and diagnosis history sitting in a spreadsheet somewhere. Action this week: Check your mail and email for a Medtronic breach notification and enroll in the free 24-month credit and dark-web monitoring it offers, even if you've seen nothing surface yet. Freeze your credit with Equifax, Experian, and TransUnion, since a freeze is free and blocks new-account fraud regardless of whether ShinyHunters ever publishes what it took. Share this with anyone you know running a Medtronic device; five minutes now is the difference if this data ever moves.

therecord.media: Medical device maker notifies nearly 4 million of breach (July 6, 2026)
securityweek.com: Medtronic data breach impacts 3.8 million people (July 2026)

2. The FCC's 2022 Huawei and ZTE ban had a four-year-old hole in it. This week the agency finally closed it.

Four years, the loophole was the whole ban.

Since 2022, the FCC has blocked new Huawei, ZTE, and other Chinese-made networking and surveillance equipment from getting US authorization, citing national security. But that rule only covered models submitted for approval after November 2022; anything already approved stayed legal to import and deploy. On June 26, 2026, the FCC closed that gap, revoking authorization outright for legacy routers, base stations, and video-monitoring gear from Huawei, ZTE, Hytera, Hikvision, and Dahua. The new rule takes effect in July 2026; anyone who already owns the affected equipment isn't required to remove it, though the FCC's own language calls continued use of it an "unacceptable risk to national security."

The gap wasn't an oversight; it was the compromise that got the original ban passed, and it sat there for four years because closing it meant asking schools, city governments, and small telecom carriers to rip out gear that was legal when they bought it. This expansion doesn't force that removal either, it just makes clear the FCC now considers that gear dangerous, not just outdated. The distance between "flagged as a risk" and "required to replace it" is where this actually lands for anyone still running the older hardware.

Why this matters: If your business, school, or local government still runs older Chinese-made networking or camera equipment, the federal government just told you in writing that it's a live security risk, not a settled compliance question you can ignore. Action this week: If you manage IT or network infrastructure, audit your inventory for pre-2022 Huawei, ZTE, Hikvision, Dahua, or Hytera hardware against the FCC's Covered List. Share this with whoever runs that infrastructure where you work or where your kids go to school, since most people are still assuming the 2022 ban already covered it.

benzinga.com: FCC tightens screws on Huawei, ZTE, and other Chinese telecom giants (June 26, 2026)
techstory.in: FCC expands Chinese tech import ban to cover legacy equipment from July 2026 (June 2026)

3. A hundred authors turned down Anthropic's record $1.5 billion settlement. They're betting a judge will give them more.

Getting caught cost Anthropic $3,000 a book. A hundred writers just bet they're worth more.

Anthropic already agreed to pay roughly $1.5 billion to settle mass claims that it pirated more than 7 million digitized books to train Claude, the largest copyright settlement in US history; distribution to the roughly 500,000 eligible titles, at a minimum of $3,000 each, began last month. But more than 100 authors and rights holders — including Nolan Bushnell, Laura Esquivel, Tiffany Aliche, and Donna Barba Higuera — opted out of that settlement entirely. Filed June 17 in the Northern District of California, their suit seeks more than $75 million, at up to $150,000 per work in statutory damages. Their legal theory is sharper than the original case: they allege Anthropic didn't just download their books from shadow libraries Library Genesis and Pirate Library Mirror, it redistributed copies to other BitTorrent users in the process, a piracy-and-redistribution claim courts have treated more harshly than straightforward unlawful training. Anthropic hadn't issued a public response as of this reporting.

This is a live experiment in what a copyright settlement is actually worth once real authors get to choose their own number. The class deal paid a flat rate regardless of a book's individual value or how it was obtained; this suit argues that redistributing pirated copies is worse than merely training on them, and prices each book at fifty times the class rate. If a judge agrees, every AI company weighing a class settlement against per-book exposure just got a number to do that math against.

Why this matters: If a company's AI ever touched your creative work without asking, this case is testing whether an opt-out lawsuit can be worth dramatically more than a class settlement check, real money, not a symbolic gesture. Action this week: If you're an author or rights holder, search "Anthropic copyright settlement claims" to check whether your titles are in the Bartz v. Anthropic class list, since opting out to sue individually is now a live, real financial choice with case law forming around it in real time. If you write or publish more broadly, check your titles against Library Genesis and Pirate Library Mirror listings, the same shadow-library infrastructure named in both this suit and the original settlement.

letsdatascience.com: Authors sue Anthropic seeking more than $75M (July 4, 2026)
authorsguild.org: Opting out of the Anthropic settlement, what authors need to know (2026)

4. California's AI-watched wildfire cameras caught over half of last year's fires before anyone called 911.

Three real fire seasons of data are already in the books.

ALERTCalifornia, a program run out of UC San Diego by geologist Neal Driscoll, now operates more than 1,200 high-definition, pan-tilt-zoom, near-infrared cameras feeding real-time wildfire alerts to all 21 of California's emergency command centers. In 2025, the AI-augmented network, deployed with CAL FIRE since 2023 on a program running since 2017, informed CAL FIRE of roughly 3,600 wildfire incidents, and in more than half of those cases the alert went out before a single 911 call came in. "We can fight fires in the incipient phase before they get too large," Driscoll told Route Fifty. The program is funded jointly by the state of California, the US Geological Survey, utilities, and CAL FIRE.

This AI-for-good story comes with three fire seasons of real detections measured against real 911 call logs behind it. The program took nine years to reach this scale, from the camera network's 2017 start to AI detection joining in 2023 to today's statewide coverage. The same pattern-matching capability at the center of today's other three stories, the kind that can also be pointed at a corporate network or a pile of pirated books, is here pointed at a mountainside, and it's buying firefighters the minutes that decide whether a fire stays small.

Why this matters: If you live somewhere fire-prone, a system that's already catching more than half of nearby wildfires before anyone dials 911 might already be watching your area, and that's minutes that can be the whole difference in whether a fire stays small. Action this week: If you live in a wildfire-prone part of California, check cameras.alertcalifornia.org to see if your area is covered. If you manage emergency response or infrastructure in another fire- or disaster-prone region, look at ALERTCalifornia's funding model, state government plus a federal science agency plus utilities, as a template worth copying, understanding it took years, not months, to build.

route-fifty.com: What California has learned from its AI-enabled early wildfire detection system (July 1, 2026)
lasvegassun.com: Statewide camera network and AI advance early wildfire detection (June 23, 2026)

» What to watch this week

Tomorrow's signal lands here.