Espionage and theft, from people whose job is to stop it
A Bastille Networks webinar this year brought together the company's CTO, Dr. Brett Walkenhorst, and Scott Stapp, a retired Air Force brigadier general and former Northrop Grumman CTO now running technology at DEFCON AI. Their framing was direct: smart glasses are a covert surveillance device fully capable of espionage, personal data leakage, and violations of NDAs, corporate policy, and consent law, and the US Air Force banned them outright for uniformed personnel in January for exactly that reason.
The mechanics they described explain why this reads differently from a privacy complaint. A phone pointed at a document or a whiteboard gets caught, because someone has to be seen holding it up. Glasses remove the tell. Capture can be a tap on the frame, and the footage can leave the device over a cloud connection with nothing stored locally to seize afterward. The same wireless radios that make this possible also do more than record: the presenters described a real incident in which a hotspot-carrying device entered a data hall, connected to a client over Wi-Fi, and exfiltrated server data over cellular, the exact capability a pair of glasses carries natively. Oracle is now deploying continuous wireless monitoring across its AI data centers in response. With roughly 2.5 million people holding security clearances in the US alone, the presenters noted, even a fractional bad-actor rate is a population in the thousands.
None of this stayed theoretical. In April, Toronto police announced arrests in a $500,000 organised retail fraud scheme that used smart glasses, alongside other tools, to distract staff and capture employee login credentials on the spot. That is alleged data theft tied to criminal charges, in our own province.
Extortion, with a named victim
The clearest documented case of the third word came out of London this year. A woman, identified only as Alice, says a stranger recorded her covertly with camera glasses near a shopping centre; the footage reached tens of thousands of views before she even knew it existed. When she asked the account holder to remove it, he told her taking it down was a paid service. She refused and went to police, who told her they lacked enough information to open an investigation. The clip kept resurfacing under new accounts after platforms took the first one down.
Bribery is the one word we cannot back with a case yet
We looked for a documented incident matching the fourth word directly and did not find one. We would rather say that plainly than stretch the other three cases to cover it. The mechanism is not hard to imagine, discreet recording as proof that an illicit exchange happened, or as leverage afterward if one side wants out, but imagining a mechanism is not the same as reporting one, and we are not going to present speculation as documented fact in an article about people being careful with facts.
A claim worth correcting on the record
In the same webinar's Q&A, asked whether consumer devices exist to detect this, the presenters said no. They are right about what they mean. Nothing at consumer scale matches software-defined radio arrays localising a device to one to three metres across Wi-Fi, Bluetooth, ZigBee, and cellular inside a secured facility, and nobody should pretend otherwise. But a narrower question, is a compatible device broadcasting nearby at all, does have a consumer answer, and NearLens is one of them. We built it for a bystander in a coffee shop, not a data hall protecting model weights, and we would rather be precise about that gap than let an accurate expert statement stand as a broader claim it was never making.
What connects all four words back to this series is the pace. Enterprise security built a monitored response, an Oracle rollout, an Air Force ban, months before most legislatures finished drafting a bill. The bystander in a coffee shop still has neither.