Your VPN Might Be Turning You Into a Surveillance Target: The Alarming Legal Loophole Congress Wants Answers About

A bipartisan group of senators is demanding DNI Tulsi Gabbard warn Americans that VPN use may subject their communications to warrantless surveillance under Section 702, exposing a fundamental contradiction in government security advice.
Your VPN Might Be Turning You Into a Surveillance Target: The Alarming Legal Loophole Congress Wants Answers About
Written by Emma Rogers

Americans who use virtual private networks to protect their online privacy may be inadvertently painting a target on their own backs — one that invites the very government surveillance they’re trying to avoid.

That’s the stark warning embedded in a letter sent by a bipartisan group of U.S. senators to Director of National Intelligence Tulsi Gabbard, urging her to publicly inform Americans about a little-understood consequence of using VPNs and certain encrypted messaging tools. The problem isn’t theoretical. It stems from how the intelligence community interprets Section 702 of the Foreign Intelligence Surveillance Act — and the answer should unsettle anyone who assumed their VPN subscription was a straightforward privacy upgrade.

The senators’ concern is precise and technical, but its implications are sweeping. When a U.S. person connects to a VPN, their internet traffic is routed through servers that may be located overseas. To intelligence agencies conducting surveillance under Section 702, that overseas routing can make domestic communications appear foreign. And foreign-appearing communications are fair game.

How a Privacy Tool Becomes a Surveillance Invitation

Section 702, reauthorized by Congress in April 2024 with expanded provisions, permits the NSA and other agencies to collect communications of non-U.S. persons located abroad without a warrant. The law explicitly prohibits targeting Americans. But here’s the catch: the determination of whether a communication is “domestic” or “foreign” often hinges on where the data appears to originate — not on the nationality or location of the person sending it.

VPNs work by encrypting a user’s traffic and routing it through an intermediary server, often in another country. Millions of Americans use them daily for entirely mundane reasons: accessing region-locked content, securing connections on public Wi-Fi, or simply asserting a baseline level of digital privacy. The global VPN market exceeds $50 billion and continues to grow. Yet the intelligence community’s collection practices may treat VPN-routed traffic as though it belongs to a foreigner abroad, simply because the data packets exit from a foreign IP address.

As Techdirt reported, the senators’ letter specifically asks Gabbard to declassify and release information about how Section 702 collection treats VPN traffic, and to issue a public advisory so that Americans can make informed decisions about the tools they use. The letter argues that citizens have a right to know if their choice of privacy software could subject them to warrantless intelligence collection.

This isn’t a fringe concern raised by civil liberties absolutists alone. The letter’s signatories include Sen. Ron Wyden of Oregon, a longtime surveillance critic, alongside colleagues who have historically supported intelligence authorities. The bipartisan nature of the request signals that the issue has moved beyond ideological battle lines.

The underlying legal architecture makes the problem almost inevitable. Section 702 operates through two main collection programs: PRISM, which compels U.S. tech companies to turn over data on foreign targets, and what’s known as “upstream” collection, which taps into the internet backbone to capture communications in transit. Upstream collection is where VPN traffic is most vulnerable. When the NSA intercepts data flowing through fiber-optic cables, it uses selectors — like email addresses or IP addresses — to filter for foreign intelligence targets. A communication that appears to originate from a server in, say, Amsterdam or Singapore could be swept up even if the person who sent it is sitting in a living room in Ohio.

The intelligence community has long maintained that “incidental collection” of U.S. persons’ communications is an unavoidable byproduct of targeting foreigners. But critics argue that when a known technical behavior — VPN usage routing traffic abroad — systematically converts domestic communications into foreign-appearing ones, the collection isn’t incidental at all. It’s structural.

And the scale is not small. Estimates from various industry trackers suggest that roughly a third of American internet users have used a VPN at some point. Among younger demographics and remote workers, the figure is higher. If even a fraction of that traffic is being swept into Section 702 collection pipelines, the volume of improperly collected domestic communications could be enormous.

The Section 702 Reauthorization Made Things Worse

The timing of the senators’ letter is no accident. When Congress reauthorized Section 702 in April 2024, it did so over the objections of privacy advocates who warned that the new law expanded surveillance authorities rather than constraining them. One of the most controversial provisions broadened the definition of “electronic communications service provider” — a change that critics said could conscript a far wider range of businesses and individuals into assisting with surveillance.

That expansion compounded existing concerns about how the law treats encrypted and VPN-routed traffic. During the reauthorization debate, Wyden and others pushed for amendments that would have required a warrant before querying Section 702 databases for information about U.S. persons. Those amendments failed. The result is a system where Americans’ communications can be collected without a warrant, stored in government databases, and then searched by FBI agents — again without a warrant — using identifiers like names, phone numbers, or email addresses.

The FBI’s querying practices have already drawn sharp criticism. A 2023 court opinion revealed that the bureau had conducted hundreds of thousands of improper queries of the Section 702 database, including searches related to January 6 suspects, Black Lives Matter protesters, and a sitting member of Congress. The Foreign Intelligence Surveillance Court imposed new compliance requirements, but the fundamental authority to query without a warrant remained intact after reauthorization.

Now add VPN traffic to the equation. If Americans’ VPN-routed communications are being collected under Section 702, they’re sitting in databases that FBI agents can search with minimal oversight. The senators want Gabbard to tell the public about this risk. So far, the Office of the Director of National Intelligence hasn’t publicly responded to the letter.

Privacy and security researchers have flagged this issue for years with limited traction. Riana Pfefferkorn, a research scholar at the Stanford Internet Observatory, has written extensively about how technical realities collide with legal frameworks designed for a different era. The assumption baked into Section 702 — that geographic location of data is a reliable proxy for the nationality and location of the communicant — was questionable when the law was first enacted in 2008. In 2026, with widespread VPN adoption, cloud computing, and globally distributed infrastructure, it’s flatly wrong.

The intelligence community’s response has generally been to point to minimization procedures — rules that govern how collected data involving U.S. persons must be handled. Under these procedures, analysts who encounter U.S. person information during a foreign intelligence investigation are supposed to mask the identity and limit how the data is used. But minimization is an after-the-fact remedy. The collection still happens. The data still enters government systems. And as the FBI querying scandals have shown, the protections that are supposed to kick in downstream don’t always work.

There’s also a deeper irony at play. The U.S. government, through agencies like CISA and the FBI, has actively encouraged Americans to use VPNs and encrypted communications to protect themselves from hackers, foreign espionage, and cybercriminals. In December 2024, following the massive Salt Typhoon breach of U.S. telecommunications networks attributed to Chinese state-sponsored hackers, senior officials publicly urged Americans to use encrypted messaging apps. The implicit message: protect yourself. The unspoken caveat, according to the senators’ letter: that same protection might expose you to your own government’s surveillance apparatus.

That contradiction is what makes this more than a technical footnote in surveillance law. It strikes at the basic trust relationship between citizens and government agencies that are supposed to serve them. If using a government-recommended security tool can trigger government surveillance, the advice becomes self-defeating — and the public’s willingness to adopt good security practices erodes.

Commercial VPN providers are watching this debate carefully. Companies like NordVPN, ExpressVPN, and Mullvad have built their businesses on the promise of privacy. Some operate under strict no-logs policies and have undergone independent audits to prove they don’t retain user data. But none of that matters if the collection happens at the network level, before the traffic reaches the VPN provider’s server or after it leaves. Upstream collection intercepts data in transit on the internet backbone — a point where neither the user nor the VPN provider has any visibility or control.

What Happens Next

The senators’ request puts Gabbard in an uncomfortable position. Acknowledging that VPN use can trigger domestic surveillance would be a significant public admission — one that could undermine confidence in both the intelligence community and the commercial privacy industry. But refusing to address the issue, or offering only classified reassurances, would confirm the suspicion that the government is content to let Americans remain uninformed about risks it fully understands.

There’s precedent for this kind of public disclosure. In the wake of the Snowden revelations in 2013, the intelligence community was forced to declassify significant portions of its surveillance programs and legal interpretations. The result was painful but ultimately productive: it led to the USA FREEDOM Act of 2015, which ended the NSA’s bulk collection of domestic phone records. Whether the current political environment supports a similar moment of transparency is an open question.

Congress could also act legislatively. A warrant requirement for U.S. person queries of Section 702 data — the reform that failed during reauthorization — would address part of the problem. So would a statutory clarification that VPN-routed traffic originating from a U.S. person cannot be treated as foreign communication regardless of its apparent geographic origin. Neither fix is technically complicated. Both are politically heavy.

For now, the millions of Americans who subscribe to VPN services are operating in a gray zone. They’re using a legal, commercially available tool that the government itself recommends — and that same tool may be converting their private communications into intelligence collection targets. The senators want the DNI to say so plainly. The silence, so far, speaks volumes.

Whether Gabbard responds publicly, the letter has already accomplished something: it has forced the question into the open. The intersection of consumer privacy technology and foreign intelligence law is not a subject that lends itself to simple answers or clean narratives. But the core question is simple enough. Should Americans know that their VPN might be working against them? The senators think yes. The intelligence community, characteristically, hasn’t said.

Subscribe for Updates

CybersecurityUpdate Newsletter

The CybersecurityUpdate Email Newsletter is your essential source for the latest in cybersecurity news, threat intelligence, and risk management strategies. Perfect for IT security professionals and business leaders focused on protecting their organizations.

By signing up for our newsletter you agree to receive content related to ientry.com / webpronews.com and our affiliate partners. For additional information refer to our terms of service.

Notice an error?

Help us improve our content by reporting any issues you find.

Get the WebProNews newsletter delivered to your inbox

Get the free daily newsletter read by decision makers

Subscribe
Advertise with Us

Ready to get started?

Get our media kit

Advertise with Us