> daily_signal(2026_08_13)

ICE fed more than 900,000 DNA profiles to the FBI with no warrant, New York wanted your face to place a bet, ransomware took a city's 911 offline, and an AI blood test caught liver cancer early.

PickBits Daily Signal · Thursday, August 13, 2026

By Mark Pickering · 8 min read · August 13, 2026

// tl;dr

ICE has spent the year quietly turning civil immigration stops into permanent entries in the FBI's criminal DNA database, and it has grown into one of the biggest sources of new profiles going into that system. New York tried to make scanning your face the price of a legal bet, and got the loudest pushback its gaming commission has ever seen. We have watched this build all summer, ICE's face scanners heading into local police departments, border photos kept for years, a court keeping Apple on the hook for faceprinting millions through its Photos app. And then there is the ransomware one, a wave that took a California city's 911 offline in a week that hit four states. And the fourth is the good one. An AI blood test caught liver cancer early in Guatemala and Romania, the kind of place a US-only study skips, and it is the one today I am actually glad about.

Today: ICE fed about 920,000 DNA profiles into the FBI's CODIS in a year, New York's Gaming Commission drew a record 240-plus comments against face-scan betting, a ransomware wave took Suisun City's 911 offline across a four-state week, and Johns Hopkins validated its DELFI liver-cancer blood test in Guatemala and Romania.

1. No judge signed off, no council voted, and ICE still fed about 920,000 DNA profiles into the FBI's criminal database.

A civil immigration stop that files no criminal charge can now put your DNA, or your five-year-old's, in the FBI's permanent criminal database for life.

No warrant was signed and no hearing was held. Over a single year ICE still added roughly 920,000 DNA profiles to the FBI's CODIS database, the equivalent of more than 2,700 new profiles every day. That makes an immigration agency one of the biggest sources of new entries in the whole system. These come from civil immigration cases that carry no criminal charge. CBP submitted samples from 492 children under 14 between January 2025 and January 2026, including twenty-one five-year-olds, and ICE has begun criminally charging the adults who refuse to give a sample.

DNA taken during a civil detention does not stay in an immigration file. It lands in a criminal-search database and is kept there to run against future crime scenes. The people it is taken from were held on a civil matter and never accused of anything, and the courts are still sorting out whether that is even allowed. This is not new ground for us. We have tracked each piece of what they have been stacking up all summer, the face-scanning checks headed into local police departments, the border photos kept for years, the tax and location data bought from brokers. DNA is the most permanent piece of all of it. You can never change your genome, and it pulls in relatives who never consented to anything.

Screenshot of The New Republic's August 3, 2026 report on ICE building a DNA database inside the FBI's CODIS
newrepublic.com · August 3, 2026
Why this matters: A civil immigration stop files no criminal charge, but the DNA taken during it does not behave like an immigration record. It goes into CODIS, gets searched against future crime scenes, and reaches relatives who were never in the room, because a genome drags in anyone you share it with. We have covered each piece they have added this year on its own; DNA is the one nobody can ever take back. What gets me is that this was decided by a form, not a vote, so the only real check left on it is a court. Action this week: Watch whether groups like the EFF and ACLU take the CODIS expansion to court, and follow where that litigation goes, and if you work in civil liberties or handle health data, look up whether your state limits how long DNA collected for "identification" can be retained and searched. Ask for the retention schedule, because that is where you would find out whether a sample taken for "identification" has any end date at all, or no limit on how long it is kept.

newrepublic.com: ICE is building a massive DNA database inside the FBI's CODIS (August 3, 2026)
latintimes.com: ICE now the largest source of new DNA profiles in the FBI's criminal database (August 2026)
biometricupdate.com: Immigration enforcement drives surge in FBI DNA database (August 2026)

2. New York tried to make face-scanning the price of a bet, and for once the public got a comment window and used it.

New York wants you to scan your face just to place a bet, and the biometric record it takes can never be reset after the inevitable breach.

The New York State Gaming Commission proposed a rule that would require facial recognition or a fingerprint scan to open and access an online sports-betting account, in the largest legal wagering market in the country, and even weighed a face scan on every login to deter account-sharing with minors. And people showed up. The commission received more than 240 public comments, the most any proposal in its history has ever drawn, and the overwhelming majority opposed it. Executive Director Robert Williams said staff is now preparing a revised proposal for the commission's next meeting.

One line kept coming up in the comments: a face is not a password. When a betting operator is breached, and that is a matter of when and not if, you cannot reset your face or reissue a fingerprint, and that template is exposed for good. The rule was written by commission staff, and the only place the public gets a formal say is that comment window, which is why that many comments actually moved staff to redraft it. We have covered this creep all year, a court keeping Apple on the hook over faceprinting millions through its Photos app, the checkout-line push to pay with your face. A face scan to place a wager is the same thing reaching your Friday-night parlay.

Screenshot of SportsBettingDime's August 12, 2026 story on New York's record public comments against biometric betting rules
sportsbettingdime.com · August 12, 2026
Why this matters: The trouble is simple. You cannot get a new face, so a faceprint that leaks in a breach is gone for good. This rule came straight from commission staff, and the one place the public gets a say is the comment window, which is exactly why a record 240-plus comments actually moved staff to redraft it. Your face is the one credential you can never change once it leaks, and I would not hand it to a betting app to save a step at signup, not when an ID and a Social already do the job. Action this week: File a comment through the Sports Betting Alliance's take-action page before the commission's next meeting, while the rule is still being redrafted. If you hold a DraftKings or FanDuel account, ask the operator one question in writing, whether you can verify with an ID and Social instead of your face, and how long any biometric template would be stored and when it is deleted.

sportsbettingdime.com: New York receives hundreds of public comments on biometric data to access sports-betting accounts (August 12, 2026)
biometricupdate.com: New York proposes biometric checks for sports-betting apps (May 2026)
sportsbettingalliance.org: New York take-action page on the biometric betting rule (2026)

3. Local governments in four states got hit in a week, and whether 911 stayed up came down to who had a failover ready.

A ransomware wave took a city's 911 offline in a week that hit four states, and the small IT shops running your local government are exactly the kind of target getting picked off.

In one week, local governments in four states were knocked offline by cyberattacks. Suisun City, California declared a state of emergency after malware struck around 5:45 a.m. and took down 911 routing, police and fire dispatch, and records; emergency calls were rerouted to Solano County. Coweta, Oklahoma lost every city computer, its building permits, and in-person card payments to ransomware. Washburn County, Wisconsin shut down all county systems to contain the intrusion, while its 911 stayed up. None of these were federal targets or big-name companies.

These are small city and county IT teams with thin security budgets, which is most local government and a lot of small companies too. If that sounds like your shop, it should. Suisun City did not get fully knocked out, because it could still push those emergency calls to Solano County. The question for your own shop is whether you have a failover you can trigger fast, one kept off the network an attacker would encrypt, and backups clean enough to run permits and payments on paper. We flagged this earlier in the summer. The crews are getting more targeted, and small towns with almost no security budget are exactly the kind of target that keeps getting hit.

Screenshot of The Record's August 11, 2026 report on ransomware hitting local governments in four states
therecord.media · August 11, 2026
Why this matters: It is not about those three towns. Most local government and a lot of small companies run on the same thin budget, so the next one hit could just as easily be yours. What kept Suisun City's bad morning from becoming a full 911 blackout was being able to reroute those calls to Solano County at all. The question for your shop is whether you have a failover you can trigger in minutes, kept off the network an attacker would encrypt, with backups clean enough to run on paper. One thing we still do not know is the ransom demands, or whether anyone paid, and that shapes how the next city decides. I have watched too many incident plans sit unopened in a shared drive until the morning they were finally needed, and by then it is too late to start reading. Action this week: Get one question answered in writing before the next incident, not during it. Can we move emergency dispatch to a mutual-aid partner within minutes, and is that path segmented from the network an attacker would encrypt? Put the answer in the incident plan, send this to whoever owns that plan, and schedule the "disconnect everything to preserve evidence" tabletop this quarter, while you still can. You will not have the time to figure it out once it is your 911 going dark.

therecord.media: Local governments in four states dealing with cyberattacks that shut down services (August 11, 2026)
kqed.org: Suisun City declares a state of emergency after cyberattack (August 2026)
contracosta.news: Suisun City declares state of emergency after cyberattack disrupts public-safety services (August 9, 2026)

4. For someone in Guatemala or Romania, an AI blood test caught liver cancer early, at a stage doctors almost never reach in time.

An AI blood test caught early liver cancer in two hard-hit countries the medical world usually skips, at a stage doctors almost never reach in time.

Liver cancer is the kind the system usually finds too late, at a stage where survival is poor, and the people it hits hardest are often the ones a US-only study never enrolls. Researchers at Johns Hopkins Kimmel validated their AI liquid-biopsy platform DELFI, which reads genome-wide cell-free DNA fragmentation patterns in the blood instead of hunting specific mutations, in 377 people across two high-risk groups in Guatemala and Romania where the disease comes from very different causes. Paired with the standard AFP marker plus age and sex, it detected both early- and late-stage disease more accurately than AFP blood testing alone.

The coverage is going to blur this, so watch for it: this is a validation study, not an approved product your doctor can order, and the exact per-cohort sensitivity and specificity for this 2026 work are still being locked down in the primary paper, so older 2022 DELFI figures do not apply. Most early-detection tools are only ever proven in one tidy cohort at the lab that built them. This one held up in two populations where the disease has completely different underlying causes, which is what would make it useful somewhere other than a Baltimore research hospital.

Screenshot of Yahoo News's science report on the DELFI AI blood test detecting liver cancer early
yahoo.com · August 2026
Why this matters: Liver cancer is usually found too late, at a stage where survival is poor, and the people it hits hardest are often the ones a US-only study never enrolls. Nobody was cured this week and nothing was approved. What happened is a validation study: a locked DELFI classifier, reading cell-free DNA fragmentation, held up in 377 people across two very different high-risk groups in Guatemala and Romania and beat the standard AFP marker on its own. The exact per-cohort accuracy numbers are not even public yet, so nobody should be calling this a finished screening test. What sticks with me is that it worked somewhere other than the lab that built it, a cheap test that held up in the field, and it landed the same day AI breast-cancer tools were reported falling short of radiologists. Action this week: Watch whether this moves from a published paper toward something a clinic in Guatemala or Romania can actually run, and follow the Cell Press study for the locked sensitivity and specificity rather than reusing older DELFI figures. That is the number that will tell you whether early detection reaches the people this was built for.

yahoo.com (science wire): AI-powered blood test detects liver cancer earlier (August 2026)
clpmag.com: AI blood assay detects liver cancer, international validation (August 2026)
insideprecisionmedicine.com: Blood test boosts early detection of liver cancer (August 2026)

» What to watch this week

Tomorrow's signal lands here.