Security1 distinct publisher3 min readUpdated
Wyden and Casar want a public review of federal hacking, spyware purchases and Rule 41 warrants. Wiretaps produce an annual report; 25 years of hacking has never produced one.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
A wiretap application ends, eventually, in a published annual report. A Rule 41 warrant to install code on someone's phone ends in a court file and nothing aggregate at all, which is the asymmetry the letter puts at the center of its case [3].
That asymmetry sets the terms of every argument about government hacking. When Immigration and Customs Enforcement acknowledged working with Paragon, the follow-up question from lawmakers was whether that was the full extent of federal spyware use after the Biden administration largely avoided it [4]. There is no series to place the contract in, so the disclosure sits alone. On the letter's own timeline of more than 25 years of investigative hacking, no year in that period has a published count attached to it [13].
Note what the two are and are not alleging. On misuse, they ask GAO to review documented cases of federal law enforcement turning hacking capabilities to personal or otherwise unauthorized ends, and to describe the safeguards agencies keep against that [6]. The supporting argument is by analogy: they write that there are countless documented examples of government employees abusing other sensitive surveillance databases and tools for unauthorized personal purposes [9]. So the finding could come back empty, and an empty finding would still be the first public one. That is the shape of a baseline request rather than an accusation.
The procurement half of the ask is the part likely to get less attention and may be the harder question. The letter reaches how agencies buy and protect sophisticated hacking tools, and it points at the former senior L3Harris official sentenced this year for stealing and selling capabilities developed for the federal government [5][7]. Counting operations tells you how often a capability was pointed at an American. Auditing custody tells you how many copies exist and who else can point them. The L3Harris case is evidence that the second number is not automatically small.
Add it up and the request runs to at least four separate lines of inquiry: scope and frequency, misuse and internal safeguards, acquisition and protection of tools, and how agencies bring Rule 41 requests to courts [12]. GAO reviews rarely arrive as one number, and a four-part scope invites a four-part answer of uneven depth, with the operational detail most likely to be withheld.
The leverage here is thin but not nothing. Casar is the top Democrat on the House Oversight Subcommittee on Federal Law Enforcement, and Wyden has spent a career pulling on federal surveillance practice [10]. The letter is a request, sent Friday, asking that the resulting report be delivered to the public [1]. TechCrunch reported it first [11]. Nothing in it obliges an agency to publish anything on a schedule; what it can produce is one document that later years can be measured against, and an absence that becomes conspicuous if no one asks again. The lawmakers' own framing is that little public information exists on the scope, frequency or operational safeguards of a tool in use since the 1990s [2].
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
Sen. Ron Wyden, D-Ore., and Rep. Greg Casar, D-Texas, wrote to the Government Accountability Office on Friday to request a review of how the federal government hacks Americans, including with the use of spyware, and to have a report delivered to the public.
The lawmakers wrote: "While federal law enforcement agencies have used hacking and spyware as an investigative tool for more than 25 years, there exists little public information regarding its scope, frequency, or operational safeguards."
The lawmakers wrote: "Unlike traditional surveillance authorities, such as wiretaps or pen registers, the government does not publish annual reports for hacking operations."
Immigration and Customs Enforcement has acknowledged working with spyware firm Paragon, and lawmakers have been asking whether that is the full extent of U.S. government reliance on spyware after the Biden administration largely shunned it.
The letter is broader than spyware and also touches on federal acquisition of hacking tools, including the case of a former senior official at defense contractor L3Harris who was sentenced this year for stealing and selling capabilities developed for the federal government, as well as Rule 41 hacking powers.
The two asked GAO to review documented cases of federal law enforcement misusing hacking capabilities for personal or otherwise unauthorized reasons, and what kind of safeguards agencies have against hacking abuses.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Single-source but directly quoted
The factual core — who wrote, to whom, when, and what was asked — is supported by extensive direct quotation from the letter in the one supplied source, and the source itself credits TechCrunch with the original report. There is no second supplied publisher, no primary document link, and no response from GAO or any named agency or vendor, which caps evidentiary strength.
No adoption signal
This is an oversight request, not a released product or deployed capability. The supplied source records no GAO acceptance, no scheduled review, no agency policy change, and no measurable usage or uptake, so no adoption value can be assigned without inventing facts.
Slightly overstated
Reporting is restrained and quote-driven, but the framing invites readers to treat a letter as a forthcoming accounting: the request is described in detail while GAO's willingness, timeline, and authority to produce the public report are unaddressed. The letter's own rhetorical claim of 'countless documented examples' of surveillance-tool abuse is asserted rather than enumerated in the supplied material, which tilts the gap mildly positive.
Clear oversight and partisan positioning
The supplied source itself establishes the requesters' institutional stake: Casar is the ranking Democrat on the House Oversight Subcommittee on Federal Law Enforcement and Wyden has a long record of scrutinizing federal surveillance, and the article situates the letter against spyware use in the current administration after the prior administration largely shunned it. Those are visible, on-the-record positioning incentives; the cluster supplies no financial or vendor incentive facts.
Facts firm, consequences unknown
Confidence in what was asked and by whom is high because the source quotes the letter at length; confidence in what follows is low because no GAO response, agency reply, or primary document is supplied, and the cluster has a single publisher that is itself following another outlet's scoop.
build
The Crypto Wars Ended, And The Prize Went To Whoever Owns Your Endpoint1 distinct publisher
security
Courts Will Finally Count Government Hacking, But Only The Kind That Listens Live1 distinct publisher
product
US courts turn government hacking into a line item, starting with 2028 wiretap data1 distinct publisher
invest
Tiny corp wants Etched's numbers. Jane Street led $700M at $21B without publishing any1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 21, 2026