
Federal law enforcement has been using hacking tools and spyware against Americans for over two decades. There are no annual reports. No public disclosures. And repeated requests from Congress have been ignored. That’s the problem Senator Ron Wyden is trying to force into the open.
According to TechCrunch, Wyden sent a letter to the U.S. Government Accountability Office on Friday, asking it to launch a formal inquiry into how the FBI, the Drug Enforcement Administration, ICE’s Homeland Security Investigations, and the Secret Service use hacking tools and spyware in their investigations. The GAO audits the federal government, and Wyden wants it to produce an unclassified report with its findings and recommendations.
The core complaint is a transparency gap that Wyden spelled out directly in the letter: while wiretaps and pen registers require the government to publish annual reports, hacking operations face no such requirement. Agents can deploy tools that compromise a suspect’s device, intercept communications, or log keystrokes, and the public gets essentially nothing. No numbers. No scope. No oversight data. Wyden called this out clearly, writing that despite these tools being in use for more than two decades, “there exists little public information regarding its scope, frequency, or operational safeguards.”
That’s not an accident. It’s a policy choice, and one the Justice Department and FBI have actively protected by, as Wyden put it, repeatedly ignoring congressional requests for transparency across multiple administrations.
Wyden’s letter asks the GAO to look at several specific areas:
- Whether agents have abused hacking tools for unauthorized or personal purposes, and what controls exist to prevent that
- How agencies acquire, store, and secure these tools, and whether they’re submitted to the government’s vulnerability disclosure process so tech companies can fix the flaws being exploited
- How federal agents inform courts when seeking warrants to use these tools, and whether they disclose the risk of hitting innocent or unintended targets
The vulnerability disclosure question is particularly important. When the government buys or builds a hacking tool, it’s exploiting a security flaw, often in software that millions of people use. If that flaw is never reported, it stays open. And as Wyden’s letter illustrates, that’s not a theoretical risk. He specifically cited the case of Peter Williams, a former executive at defense contractor L3Harris, who stole advanced hacking tools and sold them to a Russian broker. Those tools ended up being used by Russian intelligence against Ukraine and by Chinese cybercriminals targeting cryptocurrency users. Hacking tools leak. That’s just what happens.
The history here goes back further than most people realize. The earliest documented FBI use of spyware dates to 1999, when agents investigating Philadelphia mobster Nicodemo Scarfo planted rudimentary malware on his computer to capture keystrokes and break his PGP encryption. That was 25 years ago. The tools are dramatically more powerful now, and the legal framework governing their use hasn’t kept pace.
So what Wyden is asking for isn’t radical. He wants the same basic reporting that already exists for wiretaps. He wants courts to be properly informed. He wants to know whether agents are misusing tools that can turn a phone into a surveillance device. These are reasonable questions, and the fact that they’ve gone unanswered for this long is the real story. The GAO audit, if it happens, won’t fix the underlying problem on its own. But it would at least force some numbers into daylight, and right now that’s more than the public has.