Technology

Senator Wyden Asks Federal Watchdog to Audit U.S. Law Enforcement Use of Hacking Tools

Martin HollowayPublished 6d ago6 min readBased on 2 sources
Reading level
Senator Wyden Asks Federal Watchdog to Audit U.S. Law Enforcement Use of Hacking Tools
Photo by US Congress / Public domain

Senator Ron Wyden has asked the U.S. Government Accountability Office to conduct a comprehensive inquiry into how the FBI, the Drug Enforcement Administration, ICE's Homeland Security Investigations, and the Secret Service use hacking tools and spyware in criminal investigations. TechCrunch

Wyden's letter, dated August 21, 2026, cites a persistent lack of public information about the scope, frequency, and safeguards surrounding federal hacking tools, which have been in use for more than two decades. The senator asked the GAO to publish an unclassified report with its findings and recommendations.

The request targets an oversight gap that Wyden identified explicitly. Unlike wiretaps and pen registers (devices that record dialed phone numbers), for which the government publishes annual statistical reports, there is no comparable public accounting for hacking operations. Wyden stated that the Department of Justice and the FBI have repeatedly ignored congressional requests for greater transparency across multiple administrations.

The letter asks GAO to investigate several specific areas. Wyden requested a review of whether federal agents have abused hacking tools for unauthorized or personal purposes, and an assessment of the technical and oversight measures in place to prevent such misuse. He also asked GAO to examine how agencies acquire, store, and secure hacking tools to avoid leaks, and whether they submit discovered vulnerabilities — security flaws in software that could be exploited — to a U.S. government program designed to determine whether those flaws should be reported to tech companies for patching rather than kept for exploitation.

Wyden further asked GAO to assess how federal agencies inform courts when requesting warrants for the deployment of hacking tools, and whether they disclose to judges the risk that such operations may affect unknown or innocent third parties. Remote exploitation of a computing device, unlike a targeted wiretap on a known phone line, can produce collateral access to systems and data belonging to people who are not subjects of an investigation.

The letter pointed to the case of Peter Williams, a former executive at defense contractor L3Harris, who stole advanced hacking tools and sold them to a Russian broker. Those tools were subsequently used by Russian intelligence services against Ukraine and by Chinese cybercriminals against cryptocurrency owners. The case illustrates the consequences of inadequate controls around offensive cyber tools held by government contractors.

The earliest documented FBI use of spyware dates to 1999, when the bureau installed keystroke-recording malware on the computer of Philadelphia mobster Nicodemo S. Scarfo during an investigation into illegal gambling and loan sharking. The malware captured a PGP passphrase — the password used to unlock encrypted files — allowing investigators to decrypt files they could not otherwise access. That operation established a precedent for law enforcement hacking that has continued for over a quarter-century with little public visibility into its scale or oversight.

Wyden's request to the GAO is not legislation and carries no binding authority. It is a call for an audit that, if undertaken, would produce findings and recommendations rather than enforceable rules. The GAO operates at the direction of Congress but independently determines how to scope and prioritize its reviews.

What gives the request particular weight is the convergence of concerns it raises. The letter simultaneously targets operational transparency, judicial process, internal abuse safeguards, vulnerability disclosure policy, and supply-chain security for the tools themselves. Each of these dimensions has been a subject of debate among privacy advocates, security researchers, and law enforcement agencies for years, but they have rarely been framed as a single integrated oversight question.

The vulnerability disclosure question is especially consequential. When federal agencies discover or acquire zero-day exploits — flaws in software that the vendor does not yet know about and has not yet patched — the decision to disclose them to affected vendors rather than retaining them for operational use is governed by the Vulnerabilities Equities Process. Critics have long argued that the process lacks transparency and tilts toward retention. Wyden's letter asks GAO to examine whether agencies that acquire hacking tools are submitting discovered flaws to that process at all.

The collateral-damage concern raised in the warrant context also touches on a live legal debate. Federal Rule of Criminal Procedure 41, amended in 2016, permits magistrates to issue warrants for remote access to computers located outside their jurisdiction when the location is concealed through technology. Privacy advocates have argued that these warrants are routinely approved without adequate disclosure of the technical methods involved or their potential impact on non-target systems.

Wyden's letter effectively asks the GAO to consolidate these threads into a single unclassified accounting. Whether the GAO takes up the review, and on what timeline, remains within the agency's discretion.

The broader context here is that federal hacking tools have operated in a transparency void for over 25 years. Traditional surveillance methods like phone wiretaps are subject to public statistical reporting and judicial scrutiny with a long paper trail. Network intrusion tools, by contrast, sit in a regulatory grey zone where the rules exist but the public record of how they are applied does not. Wyden's letter does not change that on its own, but if the GAO takes it up, the resulting unclassified report could give lawmakers and the public a first systematic look at how often these tools are deployed, against whom, and with what safeguards — or whether those questions can even be answered with the records agencies currently keep.