Ron Wyden Seeks GAO Review of Federal Hacking and Spyware Use
Senator Ron Wyden asks the GAO to review federal hacking and spyware use, safeguards, warrant disclosures, misuse risks and tool security across four agencies.
Summary
On Friday, August 21, 2026, Democratic Senator Ron Wyden asked the U.S. Government Accountability Office, the federal auditor, to investigate how the FBI, Drug Enforcement Administration, ICE’s Homeland Security Investigations, and Secret Service use hacking tools and spyware against Americans. Wyden said that despite more than two decades of use, little public information exists about deployment frequency, purposes, scope, or safeguards. Unlike wiretaps and pen registers, hacking operations receive no annual public reports, while the Justice Department and FBI have ignored congressional transparency requests across multiple administrations. He requested an unclassified GAO report with findings and recommendations.
Wyden wants GAO to examine unauthorized or personal use, technical and oversight controls, acquisition, storage, security, leak prevention, and whether agencies submit exploited flaws to the government program that considers disclosure to technology companies. He also seeks review of warrant applications, including whether courts are warned about risks to unknown or innocent targets. His letter cited former L3Harris executive Peter Williams, who stole advanced hacking tools and sold them to a Russian broker; Russian spies later used them against Ukraine, while Chinese cybercriminals targeted cryptocurrency owners. The FBI’s earliest documented spyware use dates to 1999, when agents investigating Philadelphia mobster Nicodemo S. Scarfo for illegal gambling and loan sharking installed rudimentary keystroke recording malware to unlock a file encrypted with Pretty Good Privacy, or PGP.
Positives
- Wyden requested an unclassified GAO report containing findings and recommendations on federal hacking operations.
- Four agencies, the FBI, DEA, Homeland Security Investigations, and Secret Service, would face a comprehensive review.
- The proposed inquiry would examine technical controls, oversight measures, secure storage, leak prevention, and possible personal misuse.
- GAO would assess whether agencies warn courts about potential effects on unknown or innocent targets.
- The review would examine whether exploited security flaws enter the government’s process for possible disclosure to technology companies.
Risks & concerns
- Federal hacking operations receive no annual public reports despite more than two decades of government use.
- The Justice Department and FBI have ignored congressional transparency requests across multiple administrations, Wyden said.
- Hacking tools may be abused for unauthorized or personal purposes, while their acquisition and storage create leak risks.
- Warrant applications may not fully disclose risks to unknown or innocent devices and targets.
- Former L3Harris executive Peter Williams sold stolen tools that Russian spies and Chinese cybercriminals later used against victims.

