Senator asks US government watchdog to review how feds use hacking tools
US Senator Ron Wyden has asked the Government Accountability Office (GAO) to investigate how federal law enforcement agencies use hacking tools and spyware against Americans, arguing there is a serious lack of transparency around the practice. In a letter sent on Friday, he called for a comprehensive review of the FBI, the Drug Enforcement Administration, Homeland Security Investigations (part of ICE) and the Secret Service, noting that although such tools have been used for more than two decades, little is publicly known about their scope, frequency or safeguards.
Unlike wiretaps, hacking operations are not covered by annual public reporting requirements, and Wyden said the Justice Department and FBI have repeatedly rebuffed congressional calls for greater openness. He wants the GAO to examine possible misuse of these tools for unauthorised or personal purposes, how agencies acquire and secure them to prevent leaks, and how courts are informed of the risks to innocent parties when warrants are sought. He cited the case of former L3Harris executive Peter Williams, who sold stolen hacking tools to a Russian broker later used against Ukraine and cryptocurrency users, as well as the FBI's first known use of spyware in a 1999 mafia investigation.
- Senator Wyden wants GAO to audit federal agencies' use of hacking tools
- Cites lack of transparency compared with wiretap reporting requirements
- References L3Harris leak case and FBI's 1999 spyware use
New here? Start with this
Federal law enforcement in the US has quietly used hacking tools and spyware for more than 20 years to gather evidence in investigations, alongside more familiar methods like wiretaps. Agencies including the FBI, the Drug Enforcement Administration, Homeland Security Investigations and the Secret Service can deploy this technology, but unlike wiretaps, there is no legal requirement for them to publicly report how often it is used or against whom.
Ron Wyden is a Democratic US Senator from Oregon who sits on committees overseeing intelligence and finance, and has a long record of pressing federal agencies on digital privacy and surveillance practices. The Government Accountability Office, which he has now asked to investigate this issue, is a non-partisan body that audits and reviews the work of federal agencies on behalf of Congress.
The broader concern is oversight: because hacking tools operate differently from traditional surveillance, it is harder for courts, Congress and the public to know how they are acquired, secured, and used, and what risks they pose to people who are not the actual targets. This matters because the tools can be powerful and invasive, and past cases have shown they can also be stolen or misused.
Both sides, in good faith
The strongest fair case each way — we don't pick a winner.
The case for
Advocates of Senator Wyden's push argue that hacking tools and spyware are far more invasive than traditional wiretaps, capable of accessing cameras, microphones and stored data on a device, yet they escape the annual public reporting that Congress long ago decided wiretaps require. They contend that without independent oversight from a body like the GAO, there is no way for lawmakers, courts or the public to know how often these tools are used, whether innocent people are swept up, or whether safeguards exist to prevent leaks or misuse such as the case of stolen tools reportedly sold to a Russian broker. For these advocates, basic democratic accountability and protection of civil liberties demand that powerful surveillance capabilities not operate in the shadows indefinitely.
The case against
Those more sympathetic to how agencies currently operate would argue that hacking tools are often deployed against serious criminal and national security targets, including organised crime and terrorism, where premature disclosure of methods and capabilities can compromise ongoing investigations and give sophisticated adversaries a roadmap to evade detection. They would note that these operations already require judicial warrants and are subject to internal Justice Department controls, and that agencies have legitimate reasons to guard operational details the way they protect other sensitive law enforcement techniques. From this perspective, a broad public review risks tipping off criminals and foreign actors even as it aims to serve transparency, so any oversight should be carefully calibrated to avoid undermining investigations that keep communities safe.
Americas Cybersecurity Geopolitics Government Politics Technology World