Wyden demands GAO audit of federal hacking tool use
Senator Ron Wyden has called for an unclassified review of how federal agencies deploy spyware, citing a lack of public reporting on the scope and frequency of these digital surveillance operations.

US Senator Ron Wyden has requested the Government Accountability Office to conduct a comprehensive review of how federal law enforcement agencies utilise hacking tools and spyware. The senator sent a letter to the GAO on Friday, asking for an inquiry into the practices of the FBI, the Drug Enforcement Administration, ICE’s Homeland Security Investigations, and the Secret Service.
Wyden cited a significant lack of transparency regarding the scope, frequency, and operational safeguards of these tools. He noted that while the government publishes annual reports for wiretaps and pen registers, it does not do so for hacking operations. Consequently, Wyden requested that the GAO publish an unclassified report containing its findings and recommendations.
The letter highlights a history of opacity, stating that the US Department of Justice and the FBI have repeatedly ignored congressional requests for greater transparency across multiple administrations. Wyden pointed out that federal agents have used hacking tools and spyware for more than two decades, yet there remains little public information on how often these tools are deployed or for what reasons.
To illustrate the risks surrounding the acquisition of such technology, Wyden referenced the case of Peter Williams, a former executive at defence contractor L3Harris. Williams stole and sold advanced hacking tools to a Russian broker. According to the letter, these tools were subsequently used by Russian spies against Ukraine and by Chinese cybercriminals against cryptocurrency owners.
The historical use of these tools dates back further than commonly recognised. The earliest documented case of the FBI using spyware occurred in 1999 during an investigation into illegal gambling and loan sharking. Federal agents discovered that Philadelphia mobster Nicodemo S. Scarfo used the Pretty Good Privacy encryption program to secure a file containing key evidence.
To access the file, the FBI installed rudimentary malware designed to record keystrokes on Scarfo’s computer. This allowed agents to decrypt the file, marking one of the first instances of the agency using digital intrusion tools in a criminal investigation.


