Sen. Ron Wyden and Rep. Greg Casar have asked the U.S. Government Accountability Office to investigate how federal agencies use hacking tools and spyware against Americans, seeking an unclassified public report on the scope, frequency, safeguards, and legal processes behind those operations. The request targets agencies including the FBI, DEA, ICE Homeland Security Investigations, and the Secret Service, and argues that federal law enforcement has used such capabilities for more than 25 years with far less transparency than exists for traditional wiretap authorities.
The lawmakers asked the GAO to examine how agencies acquire and secure hacking tools, whether government personnel have misused them, what is disclosed to courts when warrants are sought, and how Rule 41 authorities are used for court-approved hacking. The push comes amid broader scrutiny of U.S. government spyware practices, including ICE's acknowledged work with spyware firm Paragon, and follows concerns that stolen government hacking tools have previously been repurposed by foreign adversaries against Ukraine and cryptocurrency users.

See the reporting duties and controls this puts on the clock.
2 events from the most recent confirmed update back to the earliest known activity.
Sen. Ron Wyden and Rep. Greg Casar sent a letter to the U.S. Government Accountability Office asking it to investigate how federal agencies use hacking tools and spyware against Americans and to produce a public, unclassified report. They asked the GAO to examine frequency of use, safeguards, procurement and protection of tools, possible misuse by personnel, and court disclosures including Rule 41 requests.
Wyden and Casar said federal law enforcement agencies have used hacking and spyware as investigative tools for more than 25 years, framing the long-running practice as lacking transparency and oversight.
See what this changes for your reporting obligations and which controls it puts on the clock.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.