Senator asks NSA to update Americans about VPN spying risks

Sen. Ron Wyden, D-Ore., is seen during votes in the U.S. Capitol on Wednesday, June 17, 2026

Sen. Ron Wyden, D-Ore., is seen during votes in the U.S. Capitol on Wednesday, June 17, 2026 Tom Williams/CQ-Roll Call, Inc via Getty Images

A congressional analysis found foreign spies could trace users by comparing encrypted traffic entering and leaving a VPN server, according to the lawmaker’s office.

Sen. Ron Wyden, D-Ore., is pressing the National Security Agency to revise cybersecurity guidance to warn Americans that a standard commercial virtual private network service may not protect them from sophisticated foreign surveillance threats.

Foreign intelligence services monitoring large parts of the internet may be able to connect a VPN user to specific websites by matching the timing and amount of encrypted data entering and leaving the VPN server, according to a Congressional Research Service analysis requested by Wyden that his office released Wednesday.

The method, known as traffic analysis, does not require an adversary to break the service’s encryption and could expose a user’s online behavior even while the underlying data remains unreadable.

Major intelligence powers like the United States and China have sought sweeping visibility into global internet traffic through domestic legal authorities and covert access to the infrastructure carrying it, ranging from telecommunications networks to undersea fiber-optic cables.

“Encryption strength alone does not protect users from an advanced, persistent threat conducting bulk traffic collection,” CRS wrote. 

VPNs are commonly used to protect people on public Wi-Fi, conceal their internet addresses and prevent internet providers from directly viewing their online activity.

The concern is centered largely on single-hop VPNs, which route a user’s traffic through one provider’s server before sending it to its destination. Anyone capable of monitoring or compromising that server may be able to connect the traffic entering the VPN with the traffic leaving it, according to CRS. Wyden argues that dynamic should be made clear to government personnel, contractors, journalists and others who may be espionage targets.

“Americans facing advanced foreign threats … deserve clear, honest advice about how best to protect their communications from surveillance by foreign adversaries,” Wyden also wrote in a letter Wednesday to NSA Director Gen. Joshua Rudd.

Wyden asked the NSA to provide unclassified answers by Oct. 14. Nextgov/FCW has also asked the NSA for comment. The agency serves as the primary foreign electronic eavesdropping and hacking titan of the U.S. intelligence community.

CRS said services such as Tor, Nym and Apple’s iCloud Private Relay make traffic analysis harder by splitting information about a user and their destination across multiple servers, although Private Relay service does not cover all device traffic. None guarantee full anonymity. 

Current NSA and Cybersecurity and Infrastructure Security Agency guidance largely focuses on preventing hackers from exploiting vulnerabilities in remote-access VPN products to enter government or corporate networks. It recommends measures such as rapidly installing security updates, requiring multifactor authentication and reducing the number of exposed features.

The Office of the Director of National Intelligence offered another assessment in a July response that Wyden also released Wednesday. ODNI described VPNs as useful for basic cybersecurity and said consumers should examine a provider’s encryption, privacy and data-retention practices. 

The top intelligence office also noted that a VPN provider may know a customer’s identity and retain records of their activity. It’s not clear if ODNI examined whether a conventional VPN could expose users to spying, or if analysts compared single-hop services with other offerings.

Wyden’s request comes amid evidence that Chinese state-owned telecom providers retained U.S. network footholds that could facilitate the hacking and surveillance he wants NSA to address. A bipartisan House China Committee investigation first reported by Nextgov/FCW last month found three Chinese carriers kept equipment, data center space and network ties in the U.S., despite federal crackdowns.