Outdated VPNs have allowed Chinese and Russian spies to hack federal networks; Wyden demands a two-year deadline to phase out legacy systems.
Washington, D.C. — U.S. Sen. Ron Wyden, D-Ore., today called on the Trump administration to phase out and replace insecure Virtual Private Network (VPN) technology, which foreign adversaries repeatedly exploit to steal sensitive government data.
In a letter to the Office of Management and Budget (OMB), Cybersecurity and Infrastructure Security Agency (CISA), and National Institute of Standards and Technology (NIST), Wyden urged executive agencies to set mandatory security standards and ban government agencies and defense contractors from buying outdated remote-access tools.
“Federal agencies and government contractors have suffered devastating cyberattacks due to their reliance on legacy, insecure, internet-facing VPN servers to grant employees remote access,” Wyden wrote. “The federal government has become trapped in an endless game of “whack-a-mole” in responding to widespread compromises of legacy remote access technologies.”
Legacy VPNs act like an exposed digital front door that hackers can easily scan and compromise. Recent breaches targeting major vendors—including Cisco, Fortinet, Ivanti, and Check Point—highlight the risk, with industry data showing 85% of ransomware-related insurance claims stem from exploited VPNs. Chinese and Russian state-sponsored hackers have repeatedly used these exact flaws to break into U.S. networks.
Modern alternatives eliminate this entry point entirely, making remote servers invisible to online attackers and using modern, memory-safe code to prevent common hacks.
“It is no longer acceptable for agencies to use insecure, decades-old technology,” Wyden wrote. “Instead of leaving an open door accessible from the public internet, modern solutions provide remote access without broadcasting their presence.”
Specifically, Wyden called on CISA and the National Security Agency (NSA) to establish a strict two-year deadline for civilian, military, and intelligence networks to completely sunset legacy public-facing VPN entry points. He also urged OMB and the Department of Defense to update the Federal Acquisition Regulations and Defense Federal Acquisition Regulation Supplement to prohibit agencies and defense contractors from purchasing remote access technology that fails to meet modern zero-trust standards.
“The federal government must stop paying vendors for security tools that act as open invitations to foreign adversaries,” Wyden added.
The entire letter is here.
A web version of this release is here.
###
