Key facts
- Senator Ron Wyden has asked the U.S. Government Accountability Office (GAO) to review federal law enforcement agencies' use of hacking tools and spyware.
- The request stems from a perceived lack of transparency regarding the scope, frequency, and operational safeguards of these tools.
- Wyden specifically asked the GAO to investigate potential abuse of these tools for unauthorized or personal purposes.
- The review will also assess how agencies acquire, store, and secure these tools, and how they inform courts when requesting warrants.
- Wyden referenced a case where stolen hacking tools were used by Russian spies and Chinese cybercriminals.
Senator Ron Wyden has formally requested that the U.S. Government Accountability Office (GAO) conduct a comprehensive review into the use of hacking tools and spyware by federal law enforcement agencies. The Democratic senator cited a significant lack of transparency concerning the deployment, scope, and oversight of these powerful surveillance technologies.
In a letter addressed to the GAO, Wyden highlighted that despite these tools being in use for over two decades, there is minimal public information available about their application and the safeguards in place. He noted that, unlike traditional wiretaps, hacking operations do not have a requirement for annual public reporting, prompting his request for an unclassified GAO report.
The senator's inquiry aims to determine if agents have abused hacking tools and spyware for unauthorized or personal reasons, and to assess the effectiveness of existing technical and oversight measures designed to prevent misuse. Wyden also seeks a review of how these tools are acquired, stored, and secured to prevent leaks, and whether they are submitted to programs that identify security flaws for potential reporting to tech companies.
Furthermore, the request includes an examination of how federal agents inform courts when seeking warrants for the use of such tools, specifically questioning whether the risk to unknown or innocent targets is disclosed. Wyden pointed to the case of Peter Williams, a former executive at defense contractor L3Harris, who allegedly stole and sold advanced hacking tools that were subsequently used by Russian intelligence and Chinese cybercriminals.
The letter also referenced historical instances of federal agencies employing spyware, including an FBI case from 1999 involving malware used to record keystrokes on a mobster's computer to decrypt evidence.
