Security2 publishersIndependently confirmed3 min readPublished
Two Democrats ask GAO to count the thing nobody counts: federal hacking of Americans
Wyden and Casar want a public review of federal hacking, spyware purchases and Rule 41 warrants. Wiretaps produce an annual report; 25 years of hacking has never produced one.
The Watch · Security desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened
- Wyden and Casar wrote to GAO on Friday asking the watchdog to review how federal agencies hack Americans, spyware included, and to publish the result.
- Their letter notes that wiretaps and pen registers get annual government reports while hacking operations get none.
- The ask splits into four areas: scope and frequency, documented misuse and safeguards, how tools are bought and protected, and Rule 41 warrant practice.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- capability If GAO answers the frequency question in public, oversight gains a figure it can compare year over year, which case-by-case disclosures have never allowed.
- exposure The procurement leg puts contractors and their custody of government-funded capabilities inside the review, not just the agencies that deploy them.
- precedent Once one public accounting of hacking exists, its absence the following year becomes something an agency has to explain rather than the default state.
- constraint This arrives as a request rather than a reporting mandate, so the depth, timing and classification of any answer are decided outside the two requesters' control.
A wiretap application ends, eventually, in a published annual report. A Rule 41 warrant to install code on someone's phone ends in a court file and nothing aggregate at all, which is the asymmetry the letter puts at the center of its case [3].
That asymmetry sets the terms of every argument about government hacking. When Immigration and Customs Enforcement acknowledged working with Paragon, the follow-up question from lawmakers was whether that was the full extent of federal spyware use after the Biden administration largely avoided it [8]. There is no series to place the contract in, so the disclosure sits alone. On the letter's own timeline of more than 25 years of investigative hacking, no year in that period has a published count attached to it [13].
Note what the two are and are not alleging. On misuse, they ask GAO to review documented cases of federal law enforcement turning hacking capabilities to personal or otherwise unauthorized ends, and to describe the safeguards agencies keep against that [5]. The supporting argument is by analogy: they write that there are countless documented examples of government employees abusing other sensitive surveillance databases and tools for unauthorized personal purposes [10]. So the finding could come back empty, and an empty finding would still be the first public one. That is the shape of a baseline request rather than an accusation.
The procurement half of the ask is the part likely to get less attention and may be the harder question. The letter reaches how agencies buy and protect sophisticated hacking tools, and it points at the former senior L3Harris official sentenced this year for stealing and selling capabilities developed for the federal government [4][6]. Counting operations tells you how often a capability was pointed at an American. Auditing custody tells you how many copies exist and who else can point them. The L3Harris case is evidence that the second number is not automatically small.
Add it up and the request runs to at least four separate lines of inquiry: scope and frequency, misuse and internal safeguards, acquisition and protection of tools, and how agencies bring Rule 41 requests to courts [12]. GAO reviews rarely arrive as one number, and a four-part scope invites a four-part answer of uneven depth, with the operational detail most likely to be withheld.
The leverage here is thin but not nothing. Casar is the top Democrat on the House Oversight Subcommittee on Federal Law Enforcement, and Wyden has spent a career pulling on federal surveillance practice [11]. The letter is a request, sent Friday, asking that the resulting report be delivered to the public [1]. TechCrunch reported it first [7]. Nothing in it obliges an agency to publish anything on a schedule; what it can produce is one document that later years can be measured against, and an absence that becomes conspicuous if no one asks again. The lawmakers' own framing is that little public information exists on the scope, frequency or operational safeguards of a tool in use since the 1990s [2].
What to watch
- Whether GAO accepts the request and how narrowly it scopes the frequency question, which determines if any number reaches the public at all.
- Whether the misuse portion produces documented cases inside federal law enforcement or comes back empty, since both outcomes are firsts.
- Whether agencies beyond ICE disclose spyware or hacking-tool contracts while the review is pending.