Pentagon gets secret power to destroy your stolen data—or manipulate it
S. 4230 — Protecting Stolen Encrypted Data Act of 2026 · Filed by Maggie Hassan (D-NH) · 1 cosponsor · Introduced Mar 26, 2026 · Referred to committee
Your members of Congress
Enter a ZIP to see where your representative and both senators stood on this bill.
Looked up on this device — your ZIP is never stored on our servers.
What it does
This bill directs the Secretary of Defense and Director of National Intelligence to develop strategies to identify stolen U.S. data (financial, medical, biometric, intellectual property, trade secrets) held by foreign entities—whether encrypted or decrypted—and authorizes them to jointly decide whether to destroy, manipulate, or recover that data if deemed in U.S. economic or national security interest. The agencies may attempt such operations and must report to Congress within one year.
Why we flagged it
The bill's core function is to grant executive agencies broad authority to identify, destroy, manipulate, and recover stolen encrypted data held by foreign entities. While framed as protective, it is fundamentally an authorization for covert data operations with minimal congressional or public oversight.
What the text implies
- The term 'manipulation' is undefined—it could mean altering, corrupting, or weaponizing stolen data without clear limits or safeguards.
- No requirement to notify affected U.S. persons BEFORE attempting destruction or manipulation, only 'when practicable' afterward—leaving individuals unaware their data is being targeted.
The full analysis lists 5 implications of this text.
Who it affects
Citizens benefit from potential recovery of stolen personal and financial data, but the bill grants broad, opaque authority to destroy or manipulate data without clear oversight, due process, or transparency about what 'manipulation' entails or how it protects ordinary people's privacy and rights.