Featured Article

NSA is buying Americans’ internet browsing records without a warrant

Spy agency argues the practice is entirely legal — until a US court says otherwise

Comment

an exterior view of the National Security Agency in Ft Meade, Maryland
Image Credits: Brooks Kraft LLC / Corbis / Getty Images

The U.S. National Security Agency is buying vast amounts of commercially available web browsing data on Americans without a warrant, according to the agency’s outgoing director.

NSA director Gen. Paul Nakasone disclosed the practice in a letter to Sen. Ron Wyden, a privacy hawk and senior Democrat on the Senate Intelligence Committee. Wyden published the letter on Thursday.

Nakasone said the NSA purchases “various types” of information from data brokers “for foreign intelligence, cybersecurity, and authorized mission purposes,” and that some of the data may come from devices “used outside — and in certain cases, inside — the United States.”

“NSA does buy and use commercially available netflow data related to wholly domestic internet communications and internet communications where one side of the communication is a U.S. Internet Protocol address and the other is located abroad,” Nakasone said in the letter.

Netflow records contain non-content information (also known as metadata) about the flow and volume of internet traffic over a network, which can reveal where internet connections came from and which servers passed data to another. Netflow data can be used to track network activity traffic through VPNs and can help identify servers and networks used by malicious hackers.

The NSA did not say from which providers it buys commercially available internet records.

In a responding letter to the Office of the Director of National Intelligence (ODNI), which oversees the U.S. intelligence community, Wyden said that this internet metadata “can be equally sensitive” as location data sold by data brokers for its ability to identify Americans’ private online activity.

“Web browsing records can reveal sensitive, private information about a person based on where they go on the internet, including visiting websites related to mental health resources, resources for survivors of sexual assault or domestic abuse, or visiting a telehealth provider who focuses on birth control or abortion medication,” said Wyden in a statement.

Wyden said he learned of the NSA’s domestic internet records collection in March 2021 but was unable to share the information publicly until it was declassified. As a member of the Senate Intelligence Committee, Wyden is allowed to receive and read classified materials but cannot share them publicly. The NSA lifted the restrictions after Wyden put a hold on the nomination of the next NSA director, the senator said.

The practice of the U.S. intelligence community buying large sets of commercially available data from private data brokers, while not new, was only publicly disclosed in June 2023. The ODNI did not disclose which U.S. spy agencies were buying the data, or say if it knew. By its own admission, the ODNI said at the time that commercially purchased data “clearly provides intelligence value,” but “raises significant issues related to privacy and civil liberties.”

The NSA is not the only U.S. government agency relying on commercially bought data for intelligence gathering or investigations. Previous reporting shows the Defense Intelligence Agency bought access to a commercial database containing Americans’ location data in 2021 without a warrant. The Internal Revenue Service also used location data it bought from a data broker to identify suspects, as did the Department of Homeland Security to track undocumented migrants, without warrants in both cases.

But the use of commercial data by the U.S. intelligence community raises questions about the legality of the practice, at a time when the NSA is facing congressional scrutiny of its expiring legal surveillance powers and indirect admonishment from within the federal government.

In his letter to the ODNI, Wyden cited the Federal Trade Commission’s recent enforcement action against data brokers as raising “serious questions about the legality” of government agencies buying access to Americans’ data.

Earlier this month, the FTC banned X-Mode, a prolific data broker that shared the location data of Muslim prayer app users with military contractors, from selling phone location data and ordered the company to delete the data that it has collected. A week later, the FTC brought similar action against InMarket, another data broker, saying the company did not obtain users’ explicit consent before collecting their location data, and banned the data broker from selling consumers’ precise location data.

That puts government departments and agencies that use commercially obtained data, like the NSA, in a legal gray space.

When reached by email Friday, FTC spokesperson Juliana Gruenwald Henderson said the regulator had no comment on the NSA’s use of commercial data.

Government agencies typically have to secure a court-approved warrant before obtaining private data on Americans from a phone or a tech company. But U.S. agencies have skirted this requirement by arguing they do not need a warrant if the information, like precise location records or netflow data, is openly for sale to anyone who wants to buy it — though this legal theory remains untested in U.S. courts.

For its part, the NSA said in its letter to Wyden that it was “not aware of any requirement in U.S. law or judicial opinion . . . that [the Department of Defense] obtain a court order in order to acquire, access or use information, such as [commercially available information], that is equally available for purchase to foreign adversaries, U.S. companies and private persons as it is to the U.S. government.”

Wyden called on the ODNI to implement a policy that only allows U.S. spy agencies to purchase data about Americans that meets the FTC’s standard for legal data sales; otherwise the agency should delete the data. Wyden said that if a U.S. spy agency has a specific need to retain the data, it should at least inform Congress, if not the wider public.

It remains unclear if the NSA also purchases access to location databases, as other federal government agencies have done.

Nakasone said in his letter to Wyden that the NSA does not buy and use location data collected from phones or vehicles “known to be located in the United States,” leaving open the interpretation that NSA could acquire commercially available data if it was not known to originate from U.S. devices.

When reached by email, NSA spokesperson Eddie Bennett confirmed the NSA collects commercially available internet netflow data, but declined to clarify or comment on Nakasone’s remarks.


You can contact Zack Whittaker by Signal on +1 646.755.8849 or by email. You also can share files and documents with TechCrunch via our SecureDrop.

US intelligence confirms it buys Americans’ personal data

More TechCrunch

India’s mobile payments regulator is likely to extend the deadline for imposing market share caps on the popular UPI payments rail by one to two years, sources familiar with the…

India weighs delaying caps on UPI market share in win for PhonePe, Google Pay

Line Man Wongnai, an on-demand food delivery service in Thailand, is considering an initial public offering on a Thai exchange or the U.S. in 2025.

Thai food delivery app Line Man Wongnai weighs IPO in Thailand, US in 2025

The problem is not the media, but the message.

Apple’s ‘Crush’ ad is disgusting

Ever wonder why conversational AI like ChatGPT says “Sorry, I can’t do that” or some other polite refusal? OpenAI is offering a limited look at the reasoning behind its own…

OpenAI offers a peek behind the curtain of its AI’s secret instructions

The federal government agency responsible for granting patents and trademarks is alerting thousands of filers whose private addresses were exposed following a second data spill in as many years. The…

US Patent and Trademark Office confirms another leak of filers’ address data

As part of an investigation into people involved in the pro-independence movement in Catalonia, the Spanish police obtained information from the encrypted services Wire and Proton, which helped the authorities…

Encrypted services Apple, Proton and Wire helped Spanish police identify activist

Match Group, the company that owns several dating apps, including Tinder and Hinge, released its first-quarter earnings report on Tuesday, which shows that Tinder’s paying user base has decreased for…

Match looks to Hinge as Tinder fails

Private social networking is making a comeback. Gratitude Plus, a startup that aims to shift social media in a more positive direction, is expanding its wellness-focused, personal reflections journal to…

Gratitude Plus makes social networking positive, private and personal

With venture totals slipping year-over-year in key markets like the United States, and concern that venture firms themselves are struggling to raise more capital, founders might be worried. After all,…

Can AI help founders fundraise more quickly and easily?

Google has found a way to bring a variation of its clever “Circle to Search” gesture to iPhone users. The new interaction, launched in January, allows Android users to search…

Google brings a variation on ‘Circle to Search’ to iPhone users

A new sculpture going live on Wednesday in the Flatiron South Public Plaza in New York is not your typical artwork. It combines technology, sociology, anthropology and art to let…

Always-on video portal lets people in NYC and Dublin interact in real time

Apple’s iPad event had a lot to like. New iPads with new chips and new sizes, a new Apple Pencil, and even some software updates. If you are a big…

TechCrunch Minute: When did iPads get as expensive as MacBooks?

Autonomous, AI-based players are coming to a gaming experience near you, and a new startup, Altera, is joining the fray to build this new guard of AI agents. The company announced…

Bye-bye bots: Altera’s game-playing AI agents get backing from Eric Schmidt

Google DeepMind has taken the wraps off a new version of AlphaFold, their transformative machine learning model that predicts the shape and behavior of proteins. AlphaFold 3 is not only…

Google DeepMind debuts huge AlphaFold update and free proteomics-as-a-service web app

Uber plans to deliver more perks to Uber One members, like member-exclusive events, in a bid to gain more revenue through subscriptions.  “You will see more member-exclusives coming up where…

Uber promises member exclusives as Uber One passes $1B run-rate

We’ve all seen them. The inspector with a clipboard, walking around a building, ticking off the last time the fire extinguishers were checked, or if all the lights are working.…

Checkfirst raises $1.5M pre-seed to apply AI to remote inspections and audits

Close to a decade ago, brothers Aviv and Matteo Shapira co-founded a company, Replay, that created a video format for 360-degree replays — the sorts of replays that have become…

Controversial drone company Xtend leans into defense with new $40 million round

Usually, when something starts to rot, it gets pitched in the trash. But Joanne Rodriguez wants to turn the concept of rot on its head by growing fungus on trash…

Mycocycle uses mushrooms to upcycle old tires and construction waste

Monzo has raised another £150 million ($190 million), as the challenger bank looks to expand its presence internationally — particularly in the U.S. The new round comes just two months…

UK challenger bank Monzo nabs another $190M as US expansion beckons

iRobot has announced the successor to longtime CEO, Colin Angle. Gary Cohen, who previous held chief executive role at Timex and Qualitor Automotive, will be heading up the company, marking a major…

iRobot names former Timex head Gary Cohen as CEO

Reddit — now a publicly-traded company with more scrutiny on revenue growth — is putting a big focus on boosting its international audience, starting with francophones. In their first-ever earnings…

Reddit tests automatic, whole-site translation into French using LLM-based AI

Mushrooms continue to be a big area for alternative proteins. Canada-based Maia Farms recently raised $1.7 million to develop a blend of mushroom and plant-based protein using biomass fermentation. There’s…

Meati Foods bites into another $100M amid growth to 7,000 retail locations

Cleaning the outside of buildings is a dirty job, and it’s also dangerous. Lucid Bots came on the scene in 2018 with its Sherpa line of drones to clean windows…

Lucid Bots secures $9M for drones to clean more than your windows

High interest rates and financial pressures make it more important than ever for finance teams to have a better handle on their cash flow, and several startups are hoping to…

Israeli startup Panax raises a $10M Series A for its AI-driven cash flow management platform

The European Union has deepened the investigation of Elon Musk-owned social network, X, that it opened back in December under the bloc’s online governance and content moderation rulebook, the Digital Services Act…

EU grills Elon Musk’s X about content moderation and deepfake risks

For the founders of Atlan, a data governance startup, data has always been at the heart of what they do, even before they launched the company. In fact, co-founders Prukalpa…

Atlan scores $105M for its data control plane, as LLMs boost importance of data

It is estimated that about 2 billion people, especially those in lower and middle-income countries, lack access to quality and affordable essential medicines. The situation is exacerbated by low-quality or even killer…

Axmed raises $2M from Founderful to streamline drug supply chains in underserved markets

For decades, the Global Positioning System (GPS) has maintained a de facto monopoly on positioning, navigation and timing, because it’s cheap and already integrated into billions of devices around the…

Xona Space Systems closes $19M Series A to build out ultra-accurate GPS alternative

Bankruptcy lawyers representing customers impacted by the dramatic crash of cryptocurrency exchange FTX 17 months ago say that the vast majority of victims will receive their money back — plus interest. The…

FTX crypto fraud victims to get their money back — plus interest

On Wednesday, Google launched its digital wallet in India with local integrations, nearly two years after the app was relaunched as a digital wallet platform in the U.S. As TechCrunch exclusively reported last month,…

Google Wallet is now available in India