“While federal law enforcement agencies have used hacking and spyware as an investigative tool for more than 25 years, there exists little public information regarding its scope, frequency, or operational safeguards,” Sen. Ron Wyden and Rep. Greg Casar wrote in a letter to the Government Accountability Office. They want a public accounting — and they want the GAO to deliver it.
Wyden and Casar ask the Government Accountability Office to investigate
A pair of lawmakers formally asked the Government Accountability Office (GAO) to conduct a review into how the federal government hacks Americans, including the use of spyware, and to publish its findings. The letter requests the watchdog examine the scope and frequency of hacking operations and the operational safeguards in place. TechCrunch first reported the letter. The request was sent by Sen. Ron Wyden, D-Ore., and Rep. Greg Casar, D-Texas. Casar is the top Democrat on the House Oversight Subcommittee on Federal Law Enforcement, and Wyden has “a long career of scrutinizing federal intelligence and surveillance efforts,” the record notes.
Spyware, Paragon, and the question raised during President Donald Trump’s second term
The lawmakers singled out spyware as an urgent component of the review. The issue “has grown in prominence in President Donald Trump’s second term,” the letter says, after Immigration and Customs Enforcement (ICE) acknowledged working with spyware firm Paragon. The pair noted lawmakers have been asking whether ICE’s acknowledgment represents the full extent of U.S. government reliance on spyware “after the Biden administration largely shunned it.”

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we buildAcquisition of hacking tools, Rule 41, and the L3Harris insider case
The request to GAO reaches beyond commercial spyware to include federal acquisition and protection of hacking capabilities and the way agencies seek court permission to conduct searches under Rule 41. The lawmakers asked GAO to review documented cases in which federal law enforcement acquired hacking tools, to assess how agencies protect those capabilities, and to examine how agencies make Rule 41 hacking requests to courts. The letter also cites a specific integrity concern: a former senior official at defense contractor L3Harris was sentenced this year for stealing and selling capabilities developed for the federal government — an example the letter raises while urging review of procurement and protection practices.
Concerns about misuse and internal safeguards
Wyden and Casar framed their request around the potential for abuse. “Spyware and other hacking tools grant expansive access to personal devices, including webcams, location data, stored files, and encrypted communications,” they wrote. They warned that “unrestricted access to such invasive surveillance capabilities invites abuse by rogue agency personnel,” and pointed to “countless documented examples of government employees abusing other sensitive surveillance databases and tools for unauthorized personal purposes.” The letter asks GAO to catalog documented cases of federal law enforcement misusing hacking capabilities for personal or otherwise unauthorized reasons, and to evaluate what safeguards agencies maintain to prevent such abuse.
What this means for technologists, policymakers, and the public
- Technologists and security teams will likely follow the GAO review’s findings on how agencies buy and protect sophisticated hacking tools, since the letter specifically asks the watchdog to examine procurement and protection practices.
- Policymakers and oversight officials — including those on the House Oversight Subcommittee on Federal Law Enforcement — will receive a public report that could inform future legislative or oversight actions; the letter explicitly seeks a public accounting of scope, frequency, and safeguards.
- The general public may gain new visibility into how often federal law enforcement uses hacking and spyware and what internal controls exist, answering the lawmakers’ stated concern that “there exists little public information” about these practices.
The GAO is now the named recipient of a broad examination: acquisition practices, Rule 41 requests, misuse cases and internal safeguards, all framed by recent disclosures such as ICE’s work with Paragon and the L3Harris sentencing. The letter sets a clear, public-facing bar — a GAO report to explain how and how often federal agencies turn to invasive hacking capabilities, and what prevents them from being misused.




