HomeIntelligenceBrief
BREACH BRIEF🟠 High ThreatIntel

Texas Deploys Cognyte’s FalcoNet Mobile Cell‑Site Simulator, Raising Privacy and SOC 2 Concerns

Cognyte supplied Texas law‑enforcement with FalcoNet, a mobile cell‑site simulator that forces nearby phones to connect and captures metadata. The capability tests the adequacy of privacy controls under SOC 2 and data‑protection regulations, making audit‑ready evidence essential.

LiveThreat™ Intelligence · 📅 July 27, 2026· 📰 schneier.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
3 recommended
📰
Source
schneier.com

Texas Deploys Cognyte’s FalcoNet Mobile Cell‑Site Simulator, Raising Privacy and SOC 2 Concerns

What Happened – Cognyte, an Israeli‑origin surveillance firm, announced a contract with the State of Texas to supply “FalcoNet,” a mobile cell‑site simulator that can be mounted in a van, backpack, or helicopter. The device mimics a legitimate cellular tower, forcing any nearby phones to connect and allowing law‑enforcement to capture call‑metadata and location data from all devices in the vicinity, regardless of suspicion.

Why It Matters for Compliance & Audit Readiness

  • The technology creates a de‑facto “mass‑collection” point, directly testing the effectiveness of privacy‑by‑design controls required by SOC 2 CC6 (Privacy) and GDPR/CCPA obligations.
  • Continuous‑compliance programs must be able to demonstrate documented policies for lawful interception, data minimisation, and documented consent or legal basis for bulk data capture.
  • Verisq’s CookiePLUS privacy capability can provide the audit‑ready evidence (consent logs, DSAR response workflows, data‑flow maps) needed to prove compliance when such surveillance tools are in use or being evaluated.

Who Is Affected – State and local law‑enforcement agencies, telecom providers, and any individual whose mobile device is within range of the FalcoNet unit (broadly the general public in Texas).

Recommended Actions

  • Map the FalcoNet capability to SOC 2 CC6 privacy controls and document the legal basis for its use.
  • Implement a data‑flow inventory that captures any intercepted metadata and establishes retention, minimisation, and deletion policies.
  • Conduct a privacy impact assessment (PIA) and update DSAR procedures to handle bulk‑collection requests.

Source: Schneier on Security – Cognyte Sells a Mobile Cell Surveillance Van

Technical Notes – FalcoNet operates as an IMSI‑catcher (Stingray‑class) that forces phones to attach to its simulated base‑station, capturing IMSI, IMEI, signal strength, and potentially call‑metadata. No CVE or software vulnerability is disclosed; the risk stems from the technology’s inherent capability to intercept communications.

📰 Original Source
https://www.schneier.com/blog/archives/2026/07/cognyte-sells-a-mobile-cell-surveillance-van.html

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · PrivacyOps · CookiePLUS

Data exposure is where consent and DSAR readiness get tested.

When personal data leaks, regulators ask what consent you held and how fast you can answer a subject request. The Verisq AI Trust Operations platform, with CookiePLUS, keeps that posture audit-ready under GDPR and CCPA.

Explore the Verisq AI Trust Operations platform →