The FBI conducted 7,413 U.S. person queries of data collected under Section 702 of FISA between December 2024 and November 2025, up about 35% from 5,518 the prior year, according to a March 11 letter from acting Assistant Director Ted Groves to congressional judiciary and intelligence leaders. Section 702 allows the government to collect foreign intelligence communications involving non-U.S. persons overseas, but Americans’ communications can be incidentally swept into the same databases and later searched by analysts using selectors such as names, phone numbers, or email addresses.
The increase lands as Congress again debates reauthorization of the surveillance authority, which is scheduled to expire on April 20, and as civil-liberties concerns remain central to the policy fight. The FBI did not publicly explain the rise in searches, but the letter said the share of queries that returned either content or non-content Section 702 information fell from 38% in 2024 to 28% in 2025, underscoring ongoing questions about the scope, utility, and oversight of warrantless access to incidentally collected Americans’ data.

See the reporting duties and controls this puts on the clock.
3 events from the most recent confirmed update back to the earliest known activity.
A senior FBI official informed Congress that FBI searches of Americans' data under FISA Section 702 increased by roughly 35% in 2025. The disclosure surfaced as Section 702 neared its April 20 expiration and debate intensified over whether renewal should include stronger privacy safeguards such as a warrant requirement.
From December 2024 through November 2025, the FBI conducted 7,413 U.S. person queries of Section 702-collected data, about a 35% increase over the previous year. The share of queries returning Section 702-acquired information fell to 28%, according to the FBI's reporting to Congress.
For the prior reporting period, the FBI reported 5,518 U.S. person queries of data collected under FISA Section 702. About 38% of those queries returned Section 702-acquired information.
See what this changes for your reporting obligations and which controls it puts on the clock.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.