Democratic Senator Ron Wyden is pressing the U.S. government to scrutinize how federal law enforcement agencies deploy hacking tools and spyware against American citizens, citing persistent concerns about the lack of transparency regarding the frequency and justification of such operations.
On Friday, Wyden sent a letter to the U.S. Government Accountability Office (GAO)—the independent agency that audits federal operations—requesting a comprehensive investigation into how the FBI, the Drug Enforcement Administration (DEA), ICE's Homeland Security Investigations (HSI), and the Secret Service employ hacking and spyware in their investigative activities. The letter, shared with TechCrunch, underscores a long-standing oversight gap.
Wyden noted that these tools have been in use for over two decades, yet “there exists little public information regarding its scope, frequency, or operational safeguards.” Unlike traditional surveillance methods such as wiretaps and pen registers—which require annual reporting—the government does not publish similar disclosures for hacking operations. To address this, Wyden is asking the GAO to produce an unclassified report with findings and recommendations.
Federal agencies have periodically used hacking tools and spyware, but as Wyden highlighted, the Department of Justice (DOJ) and the FBI “have repeatedly ignored congressional requests for greater transparency across multiple administrations.” This pattern has fueled bipartisan concern about civil liberties and the potential for misuse.
Wyden's letter outlines three primary requests for the GAO:
- Investigate misuse risks: Determine whether agents have used hacking tools or spyware for unauthorized or personal purposes, and evaluate the technical controls and oversight mechanisms in place to prevent such abuse.
- Review tool management: Assess how agencies “acquire, store, and secure” these tools to prevent dangerous leaks, including whether they properly submit vulnerabilities to the U.S. government's Vulnerabilities Equities Process (VEP), which decides whether to disclose security flaws to technology companies for patching.
- Evaluate judicial oversight: Examine how federal agents inform courts when seeking warrants for hacking operations, and whether they adequately disclose the potential impact on innocent or unknown third parties whose devices might be compromised.
To illustrate the urgency, Wyden referenced the case of Peter Williams, a former executive at defense contractor L3Harris, who stole and sold advanced hacking tools to a Russian broker in 2026. Those tools later resurfaced in attacks by Russian spies against Ukrainian targets and by Chinese cybercriminals targeting cryptocurrency holders—demonstrating the grave risks of inadequate security and oversight.
The use of spyware by federal agents is not new. The earliest documented case dates to 1999, during an investigation into illegal gambling and loan sharking. Federal agents discovered that Philadelphia mobster Nicodemo S. Scarfo was using Pretty Good Privacy (PGP) to encrypt a file on his computer, which they believed contained key evidence. In response, the FBI installed rudimentary keystroke-logging malware on Scarfo's machine to capture his password and access the decrypted file—an early example of government hacking that sparked legal and ethical debates that continue today.
As Wyden's request moves forward, the GAO's findings could reshape how federal law enforcement balances investigative power with constitutional protections, particularly in an era of rapidly evolving digital threats.
via TechCrunch
