Summary
- Witnesses and members highlighted that cyber-enabled fraud losses surpassed $20 billion in 2025, prompting calls to designate ransomware actors as terrorists and pursue homicide charges for hospital-related deaths.
- Cynthia Kaiser (Senior Vice President, Halcyon Ransomware Research Center) testified that ransomware attacks on hospitals doubled in 2025, while Josh Bercu (Senior Vice President, USTelecom) detailed the rise of industrial-scale scam compounds.
- Rep. Michael Guest (R, MS-3) pressed Kaiser on whether the Department of Justice currently possesses the authority to charge cybercriminals with felony murder when ransomware attacks result in documented patient fatalities.
- Rep. James Walkinshaw (D, VA-11) and other Democrats criticized the administration for cutting one-third of the CISA workforce, while Republicans focused on the role of Mexican cartels and Chinese money laundering.
- Congress must now consider codifying the March 2026 executive order, reauthorizing state cybersecurity grants, and establishing a "digital assets hold law" to allow exchanges to freeze illicit cryptocurrency funds.
Topics Discussed
Transcript
Opening Statements
The Committee on Homeland Security Subcommittee on Border Security and Enforcement will come to order. Without objection, the chair may declare the committee in recess at any point. The purpose of today's hearing is to examine how transnational criminal organizations are increasingly exploiting digital technologies, including cryptocurrency, online platforms, artificial intelligence, and global financial networks to conduct fraud, launder illicit proceeds, and target American citizens, businesses, and critical infrastructure. I would like to thank our colleagues from the Cybersecurity and Infrastructure Protection Subcommittee for partnering with us for this joint hearing. I would like to now recognize myself for a brief opening statement. Good morning and welcome to the Border Security and Enforcement and Cybersecurity and Infrastructure Protection joint subcommittee hearing examining how transnational criminal networks are increasingly targeting Americans in the digital world to expand their illicit activities and increase their profits through scams, fraud, and extortion. As technology has evolved and web-based services have crossed traditional borders, cyber-enabled financial crime has risen sharply. Transnational criminal networks from Mexican drug trafficking organizations to Southeast Asia scam operations are targeting Americans with an expanding arsenal of digital tools available in the public sphere. We must build and maintain a strong defense against cyber-enabled criminals. Most Americans have encountered some sort of scam enabled by technology. These scams often target our aging and elderly families and constituents, seeking to drain their life savings and retirement plans using emotional manipulative tactics. In 2025 alone, scammers stole more than $20 billion from Americans. Criminal networks use the digital domain to promote their illicit activities. The challenging nature of tracing cryptocurrency provides a landscape where Mexican drug cartels and other criminal organizations can launder their money by converting profits from illegal activity into digital currency, which can be accessed across the world in a matter of seconds. Through this digital marketplace, the Mexican cartels are utilizing Chinese money laundering networks as a piece of their business models. President Trump issued an executive order designating certain cartels and transnational criminal organizations as foreign terrorist organizations, or FTOs. This designation has created opportunities to use new authorities to combat drug cartels and organized criminal organizations. Cyber-enabled crime not only victimizes Americans, but also raises concern for national security interests. Just last week in his testimony before the House Appropriations Committee, Todd Lyons, the acting director of ICE and Customs Enforcement, spoke about a major Homeland Security investigation involving Chinese Communist Party actors committing gift card fraud and sending proceeds back to military units in China. Digital extortion, which is another form of cybercrime, has serious national security implications. These ransomware attacks often involve foreign actors targeting sensitive industries, such as education, government, and healthcare databases, holding data or systems hostage and demanding payment for its release. My home state of Mississippi just recently experienced a major ransomware attack, and I know that many of my colleagues' districts have experienced attacks as well. The severity and increasing frequency of these attacks is deeply concerning. Our critical infrastructure, our data, and our constituents must be protected. Congress must step up to secure our virtual border. President Trump's recent executive order identifying cyber-enabled crime as a priority and pushing an offensive approach on combating cybercrime is a positive step, but it must be built upon. Given the role of industry, public-private partnerships are critical to facing these threats head-on. It is important that Congress examine how transnational criminal organizations are exploiting digital technology and targeting Americans. Today we have with us experts who will share their insight on this growing issue and provide a valuable discussion on how Congress can work together to combat financial crime. I would now like to recognize the ranking member, the gentleman from California, Mr. Correa, for his opening statement.
Thank you, Mr. Chairman. I concur with you. Cyber, cyber defense in our country should not be a Democratic or Republican issue, but rather an issue of national importance for all of us. And that's the way it's been treated here in this committee, working across the aisle to make sure we protect everybody in our society, in all institutions in our society. Let me start out by telling you that I'm now a senior and now I get senior discounts, and I guess that also comes with an ass-kicking. Recently I was at home looking through my personal email and I got an email from the IRS. Got my attention. Looked legit. Had the IRS logo, everything on it. It also said, unless you call us today, we will come and seize your assets, including your bank account assets. So, you know, I picked up the telephone number and I called that 888 number, and the person on the other side answering the phone call said, get your credit card ready, you have to pay us $20,000 right away. We'll otherwise we will be on our way to your house, and they told me where I lived, to pick you up and have you arrested. Pretty interesting conversation, very convincing. And I thought to myself, okay, what will some of my other seniors in my district do when they get that telephone call, they call, how much money will they pay? And all of us know as seniors that you don't tell your children when you get whacked. You don't tell your children when you get suckered. You just live in peace. The other side of that sociodemographic bell curve are young children today that are essentially cyberbullied, young ladies who are essentially forced into doing things they shouldn't be doing, otherwise those pictures will be released to the world. Middle of that bell curve you have one of my accounting firms in my district who got hacked, ransomware. The head of that firm had a choice. Report it, have all of your customers know that you did not have the system in place so they will go to somebody else for services. And number two, you will be opened up for civil liability because somebody hacked your system. It's not a good place to be. And Mr. Chairman, today I'm hoping beyond learning more about what's going on, we can come up with some good solutions that we can work on moving forward. Cybercriminals, transnational organizations are no longer confined by borders. They're sophisticated, organized, leveraging corruption, cutting-edge technology, human trafficking. Especially those in China, Southeast Asia, they have built large scamming centers, very sophisticated, targeting our communities in the United States. Now according to the FBI, cyber-enabled fraud in 2025 led to over $17.6 billion worth of reported losses. Reported losses. Beyond that 20 billion, I bet you there's a lot more out there that will never go reported. Top of that, artificial intelligence helping these transnational organizations scale their operations and increase their success rates at the expense of our taxpayers and citizens of this country. Highly personalized messages, password cracking tools, deepfakes where you can't tell between what's real and what's not. This is what our citizens are facing on an every everyday basis back home. We all know about Colonial Pipeline. We all know about those big instances that are reporting in the newspaper. But I believe the small firms, the individuals, moms and pops back home never report this stuff. And when the threats are getting worse, my concern is this administration is failing to respond in many ways. Over the last year and a half, Cybersecurity Infrastructure, or CISA, has had a third of its workforce cut. And their efforts, CISA, instead of defending us against cyber, their efforts are now redirected towards immigration enforcement and not cybersecurity. The president's fiscal year 2027 proposed additional cuts that threaten again the defenses to defend our homeland and Main Street. Same way, Homeland Security Investigations, or HSI, those agents that have been dedicated to combating child exploitation, digital financial crimes, those efforts also redirected towards immigration enforcement. As I said earlier, Mr. Chairman, I hope we can look at these issues objectively, focus on the issues, the challenges that we have not only today but moving forward, and come up with some good solutions across the board, across the aisle here that we can all work together. Our constituents, our citizens are depending on us because at the end of the day, a chain is only as strong as its weakest link. And this chain is about government, private sector, platforms out there, and consumers working together under the leadership of the federal government. Mr. Chair, thank you very much.
Thank you, Mr. Correa. I would now like to recognize the chairman of the Subcommittee on Cybersecurity and Infrastructure Protection, the gentleman from the great state of Tennessee, Chairman Ogles, to deliver his opening statement.
Thank you, Mr. Chairman, for holding the joint hearing and for partnering with my subcommittee to examine what has become one of the most urgent and far-reaching threats to the American people today. The hearing we are convening this morning concerns a problem that touches every community in this country. It affects retirees in Tennessee and Florida, college students in Mississippi and New York, small business owners in the Midwest, veterans, teachers, and families who do nothing wrong other than answer a phone call, open an email, or respond to what appeared to be a trusted message online. What they encounter on the other end is not a legitimate contact. It is an organized criminal operation, often run from a fortified compound halfway around the world, designed from the ground up to steal their money, their personal information, and in many cases, their sense of safety and dignity. I want to be clear about what we're dealing with. What is happening to Americans right now is an industrial-scale criminal campaign coordinated by transnational criminal organizations that operate sophisticated fraud networks spanning multiple continents and targeting millions of victims simultaneously. These operations combine cyber fraud, money laundering, cryptocurrency manipulation, digital extortion, and in many documented cases, human trafficking and forced labor. The numbers released just weeks ago by the FBI confirm how rapidly this threat is accelerating. The FBI's Internet Crime Complaint Center received more than one million complaints in 2025, the first time that threshold has ever been crossed. Reported losses surpassed $20 billion for the first time, representing a 26 percent increase over the prior year. Americans over the age of 60 reported losing nearly $8 billion, a 59 percent increase in a single year. And for the first time, the FBI dedicated an entire section of its annual report to the role of artificial intelligence in enabling these crimes, documenting more than 22,000 complaints with AI-related components. Beyond these numbers are real people whose lives have been upended. Seniors who lost their retirement savings to a voice-cloned phone call from someone they believed was a grandchild in distress. Young people targeted by sextortion schemes designed to exploit fear and shame. Small investors lured into fraudulent cryptocurrency platforms through deepfake videos of trusted public figures. Business owners locked out of their own systems by ransomware and forced to choose between paying a ransom to criminals or watching years of work disappear. These networks are deeply connected to organized transnational syndicates, many run by organized crime groups with roots in the People's Republic of China and the Russian Federation. Hundreds of thousands of people have been trafficked into scam compounds across Southeast Asia, forced to carry out fraud under the threat of violence and death. Chinese nationals and PRC-linked triads operate the largest compounds, and Beijing has been slow to act against the networks that victimize Americans while generating billions along China's periphery. Artificial intelligence is making all of this worse. Criminal organizations are using AI to clone voices, produce deepfake videos, and automate the targeting of millions of victims simultaneously. And ransomware groups are integrating AI into their attack chains to launch attacks faster than defenses can respond. This administration recognizes the severity of the threat, and I want to commend President Trump for taking decisive action. On March 6, the President signed an executive order on combating cybercrime, fraud, and predatory schemes against American citizens. That order directs the Department of Homeland Security and other federal agencies to conduct a comprehensive review of existing operational and regulatory tools and to develop a coordinated action plan to identify, disrupt, and dismantle the transnational criminal organizations behind these schemes. That is exactly the kind of whole-of-government approach that this moment demands. The American people deserve a government that fights for them with the same intensity that these criminal networks use against them. Our witnesses today will help us understand the full scope of this threat and the tools we need to combat it. I look forward to your testimony. Thank you for being here. I yield back.
Thank you, Chairman Ogles. I would like other members of the committee to be reminded that opening statements may be submitted for the record. I would now like to formally introduce Thank you, Chairman Ogles. I would like other members of the committee to be reminded that opening statements may be submitted for the record. I would now like to formally introduce our panel of witnesses. First, Ms. Cynthia Kaiser is the Senior Vice President at Halcyon Ransomware Research Center. She previously served as Deputy Assistant Director of the FBI's Cyber Division, where she led policy, intelligence, and partnerships to support victims and disrupt cyber adversaries. Second is Mr. Ari Redbord. He is the Global Head of Policy at TRM Labs. Prior to joining TRM Labs, he was Senior Advisor to the Deputy Secretary and the Under Secretary for Terrorism and Financial Intelligence at the United States Treasury, where he used sanctions and other regulatory tools to effectively safeguard the financial systems from illicit use by terrorist financiers. Third is Mr. Josh Berkue. He is the Senior Vice President of Policy at USTelecom, the Broadband Association, and also serves as the Executive Director at Industry Traceback Group, where he works closely with government agencies to identify and mitigate scams and fraudulent calls. And finally is Ms. Megan Stifel. She is the Chief Strategy Officer at the Institute for Security and Technology. She previously held roles in both the private and public sector, including with the Department of Justice, where she served on details as a Policy Director for International Cyber Policy in the National Security Council at the White House. Again, ladies, gentlemen, thank you so much for being with us today. We look forward to hearing your testimony, to having you brief us so that we can craft policy to better protect our fellow American citizens. I would ask at this time all of our witnesses if they would please rise to allow me to administer the oath before testimony. If all of our witnesses would please raise their right hand and if you would please repeat after me. Do you solemnly swear that the testimony you will be giving before the Committee on Homeland Security of the United States House of Representatives will be the truth, the whole truth, and nothing but the truth, so help you God? Let the record reflect that our witnesses have answered affirmatively. Thank you and please be seated. I would now like to give each of our witnesses an opportunity to make an opening statement. I recognize Ms. Kaiser for five minutes to summarize her opening statement.
Witness Testimony: Cybercrime and Ransomware Trends
Thank you, Chairmen, Ranking Members, and members of the subcommittees. Thank you for the opportunity to appear before you today. My name is Cynthia Kaiser. I currently lead the Ransomware Research Center at Halcyon, a cybersecurity company whose mission is to defeat ransomware. Before that, I spent two decades at the FBI, and I've given my career to understanding the criminal networks that we're discussing today. And I'm here to tell you that what they're doing demands a response that matches the gravity of their crimes. I want to begin with a statement that I believe this committee and every American should hold in mind throughout this hearing. The people committing these crimes are not merely technical actors engaged in financial misconduct. They are predators. They are callous, and they are, in many cases, knowingly endangering and ending human lives, and they do not care. As you noted, FBI released its 2025 Internet Crime Report earlier this year. The picture it paints should make every American genuinely, viscerally angry. Angry that cybercriminals are stealing a generation of wealth from our country. Angry that more than 75,000 victims of sexual extortion were caught in a cycle of abuse. And angry that during just one FBI operation, 38 victims were referred for suicide intervention. That's 38 people so devastated by cybercrime that agents feared the victims would take their own lives. Since 2023, ransomware attacks have risen over 20 percent, and they're getting faster. Attacks that used to take weeks now take hours. AI has made it easier for attackers to gain initial access to company networks, and our team's data show that ransomware gangs target small and medium-sized businesses at nearly four times the rate of large organizations. Last year, healthcare overtook all other critical sectors to become the single most targeted industry for ransomware. Attacks against hospitals and medical facilities nearly doubled from 238 in 2024 to 460 in 2025. That is more than one ransomware attack on an American hospital or health system every single day. Make no mistake, this was a business decision. Ransomware actors, who are criminal entrepreneurs as much as they are hackers, have calculated that when lives are on the line, hospitals are more likely to pay. They looked at cancer patients, dialysis patients, newborns in NICUs, and decided these patients were acceptable leverage. Research from the University of Minnesota documented at least 47 deaths attributable to hospital ransomware attacks between 2016 and 2021. That number is almost certainly in the hundreds today. Earlier this year, when Mississippi's only level one trauma center in the state was down for nine days, we saw that when a hospital is taken offline, many patients are unable to access critical care. For a heart attack or stroke patient, even one hour's delay can mean death or permanent disability. The hackers responsible for these attacks know this. They have simply decided that these deaths are someone else's problem. Our grandparents, our small business owners, our doctors, none of them should live in fear about what someone might be doing on a keyboard thousands of miles away. I fully support the President's executive order on cybercrime and the new National Cyber Strategy, which are strong steps towards dismantling transnational criminal organizations. Building on these, the gap between the severity of these crimes and the consequences that follow needs to close. I urge the committee to champion three specific authorities to do it. First, the Departments of State, Justice, and Treasury could formally evaluate whether terrorism designation authorities under existing law apply to ransomware actors who knowingly and repeatedly target hospitals. The statutory definitions of terrorism fit what these groups do. Designations would unlock sanctions, enhanced intelligence collection, travel restrictions, and real diplomatic consequences for nations harboring these criminals. Our team has already done a lot of work exploring what is legally possible and collaborating with industry partners, and we are happy to share. Second, the Department of Justice should evaluate homicide charges when ransomware attacks on healthcare facilities cause documented patient deaths. The executive order directs the Attorney General to pursue the most serious provable offenses. Felony murder law does not require that a defendant pull a trigger, only that they commit a dangerous felony that results in death. Finally, fully fund and reauthorize the state and local cybersecurity grant program. Cutting this funding would be a gift to ransomware criminals. I've spent my career working alongside extraordinary experts in cyber defense, in government and now at Halcyon. All of us are doing everything we can with the authorities we have. But the worst of the worst, those targeting our hospitals, those who have caused documented deaths, those operating under the protection of hostile foreign governments, need to face consequences that match what they have done. This requires novel implementations of the law and the resources and mandate to do so. These hackers are counting on incremental responses. Working together, let's prove them wrong. Thank you, and I look forward to your questions.
Industrialization of Crypto Fraud and AI Threats
Thank you, Ms. Kaiser, for your opening statement. I now recognize Mr. Redbord for five minutes to summarize his opening statement.
Chairs Guest and Ogles, Ranking Member Correa, and distinguished members of both subcommittees. Today I'm going to talk to you about the greatest threat confronting American families today. My name is Ari Redbord. I am honored to appear before you on behalf of TRM Labs, where we work every day with law enforcement, financial institutions, and national security agencies to detect, investigate, and prevent illicit activity in the digital asset ecosystem and beyond. Before joining TRM, I spent more than a decade as a federal prosecutor at the U.S. Department of Justice and later as a U.S. Treasury official, confronting terrorist financiers, sanctions evaders, narcotics traffickers, and transnational criminal enterprises. I do not say this lightly. The industrialization of cyber-enabled fraud by transnational criminal organizations is the most pervasive, economically destructive, and dangerous financial crime threat that I have seen in my career. The consequences are immediate and they are personal. A grandmother in Ohio sends her retirement savings to a scammer. A veteran in Texas transfers his home equity to a fake investment platform. A family in North Carolina watches their life savings vanish. This is economic violence at industrial scale. We must respond with all our might, and we must do so together. Because these are not abstract losses, they are the futures of Americans, and the networks taking them are organized, relentless, and scaling faster than our response. The numbers underscore the urgency. TRM's 2026 Crypto Crime Report documented 158 billion in illicit crypto flows in 2025. That's 145 percent increase over 2024. Fraud and scams alone drove 35 billion, and with only about 15 percent of victims reporting, true global losses exceed $200 billion. These flows run through one interconnected ecosystem. Pig butchering compounds in Southeast Asia, many staffed by trafficked workers, generate fraud proceeds. Mexican cartels buy fentanyl precursors from Chinese suppliers with cryptocurrency. North Korea stole about two billion in cryptocurrency last year to fund weapons proliferation and destabilizing activity. Every one of those streams moves through the same plumbing, Chinese underground banking networks that processed over 103 billion last year alone. And artificial intelligence is accelerating these schemes. Through Chainabuse, TRM's global scam reporting platform, we have documented a more than 500 percent increase in AI-enabled scam activity over the past year. The solution to the criminal abuse of AI is not to ban or stifle the technology. It is to use it, and use it wisely. At TRM, we are already building those tools. Every innovation our adversaries turn against American families is one we can turn back against them, faster, smarter, and at greater scale. The threat is daunting, but it is also one we can solve, and solve together. We know what to do. The White House executive order on combating cybercrime names this threat for what it is, a national security threat, and creates a whole-of-government mandate. The DOJ's Scam Center Strike Force has exemplified that approach in action. But we live in an age where the private sector holds the data and the public sector holds the authorities. Neither can confront this threat alone. That is exactly what TRM's Beacon Network was built to bridge. Beacon is the largest public-private network for the interdiction of illicit proceeds and the seizure of stolen funds in the digital asset ecosystem, connecting every major cryptocurrency exchange with 70 law enforcement agencies across the U.S. and allied nations. When a victim reports a scam, Beacon can move actionable intelligence in real time to the exchanges and agents who can interdict and seize back those funds. That is the type of real-time public-private coordination the executive order envisions, already operating and ready to scale. Congress can codify that framework. Pass a digital assets hold law so exchanges can freeze illicit funds. Empower the private sector through cyber letters of marque or white hat hacking to disrupt criminal infrastructure. Create a victim compensation fund. Give federal, state, and local law enforcement the tools and training to fight back. We can protect American citizens by leveraging transformative technology for good, and we must do it together. The tools exist, the networks like Beacon prove what is possible when the public and private sectors move as one. Thank you, and I look forward to your questions.
Telecom Infrastructure and Scam Call Mitigation
Thank you, Mr. Redbord, and now recognize Mr. Bercu for five minutes to summarize his opening statement.
Chairman Guest, Ranking Member Correa, Chairman Ogles, and members of the subcommittees. Thank you for the opportunity to testify today and for your leadership on this critical issue. I'm Josh Bercu, executive director of the Industry Traceback Group and a senior VP at USTelecom. USTelecom leads the Traceback Group, which is designated by the FCC as the consortium for tracing illegal calls. I also served on the FTC's Scams Against Older Adults Advisory Group and on Aspen's National Task Force for Fraud and Scam Prevention. The telecom industry has been making progress to protect American consumers from illegal calls. We've deployed tools like call blocking, call authentication, and industry-led traceback, complemented by aggressive enforcement by our government partners. It used to take law enforcement months to determine who made an illegal call. Now with traceback, we often find those criminals within hours. We work closely with federal and state law enforcement, routinely tracing calls referred to us, including scams impersonating the Department of Homeland Security and providing actionable information to support enforcement. We know this works. Raids of illegal calling operations in India led to an 85 percent drop in IRS scam robocalls. FCC and state attorneys general action virtually eliminated an illegal auto warranty campaign. Today, scam robocall volume is 50 percent lower than its peak. The Traceback Group has worked with banks, tech companies, and others to identify the criminals behind these calls and support law enforcement action, including recent information sharing supporting HSI takedowns. Fraudsters have evolved from high volume to higher impact. The most sophisticated operations, as my colleagues have already discussed, are run by organized transnational criminal networks. A decade ago, the dominant illegal calling threat was concentrated in South Asia, especially India. Today, the most consequential development is the rise of industrial-scale scam compounds in Southeast Asia. Mexican drug cartels have built their own illegal calling operations targeting Americans as well. We now face a global fraud-as-a-service marketplace where tools, tactics, and infrastructure are rapidly shared and operationalized. The methods used to bring these schemes onto U.S. networks are evolving as well. We trace calls back to entities posing as U.S.-based providers, sometimes through shell companies, sometimes impersonating U.S. legitimate companies. We see growing instances of calling platforms compromised and used to deliver scam calls. SIM boxes are used to generate calls from within the United States, even if the callers themselves are located abroad. To put it simply, criminals have adapted to traceback enforcement by hijacking or deploying domestic infrastructure. These trends underscore the limits of what industry can do on its own. We cannot make arrests or prosecute the criminals even when we identify them. When I testified before Congress last year, I outlined areas where federal action could make a difference. The administration's March 2026 executive order is an important step. It reflects the whole-of-government approach that this problem demands and treats scams as what they are, crimes. Now the focus must be implementation. There are three areas where Congress can help. First, reinforce the EO and its enforcement mandate by providing resources to support investigative capacity, prosecution, and cross-border coordination. Prosecutors and investigators must be able to move with urgency and work with willing partners abroad. Our industry, including the Traceback Group, stands ready in support. Second, provide a safe harbor for information sharing for improved fraud prevention and detection. Emerging partnerships show real promise in identifying and disrupting scams. A safe harbor could unlock even deeper collaboration. Third, support and scale what works, including proven tools like traceback. Fraud continues to take a toll on American consumers. We are committed to being a constructive partner in this fight. Thank you, and I look forward to your questions.
National Security Implications and Policy Recommendations
Thank you, Mr. Bercu, for your opening statement. I would now like to recognize Ms. Stifel for five minutes to summarize her opening statement.
Chairman Guest, Chairman Ogles, Ranking Member Correa, thank you for the opportunity to testify today. I'm Megan Stifel, the chief strategy officer at the Institute for Security and Technology. We are a 501(c)(3) nonprofit critical action think tank focused on the implications of technology for our national security. In our work on cybersecurity, we address misaligned incentives in the technology ecosystem that leave our critical infrastructure vulnerable. At IST, I also serve as the executive director of the Ransomware Task Force. I'd like for you to think back to the spring of 2021. Five years ago next week, the Ransomware Task Force released its report with 48 recommendations for a comprehensive anti-ransomware campaign. Two weeks later, the Colonial Pipeline was shut down by Russian ransomware gang, endangering 40 percent of the gasoline supply east of the Mississippi. Government agencies were forced to warn Americans not to put gas in plastic bags, as gas lines in some states brought back memories of the 1970s. Since Colonial, we've seen attacks on the meat processor JBS, the LA Unified School District, CommonSpirit Health, Change Healthcare, CDK Global, and more. Ransomware rose to the level of an urgent national security threat that demanded our attention. Today, I'm pleased to report that we are making some progress in the fight against cybercrime. The national security threat posed by ransomware has decreased, thanks in part to the work of this committee. But we cannot rest on our laurels. Criminals are constantly evolving and so must we. Cyber fraud, from extortion-based intrusions to business email compromise, continues to cost our economy billions each year, with significant impacts on small businesses. Nation-state adversaries are leveraging the cybercrime ecosystem to target our critical infrastructure, and rapid advancements in artificial intelligence-enabled cyber tools threaten to erode many of the gains we've made in cybersecurity in the last few years. Recent actions by the administration have emphasized the importance of countering cybercrime. However, challenges with cuts to the federal workforce and funding, as well as organizational upheaval, all threaten to stall this progress. In addition, the administration's strategic approach risks leaning too heavily on disruption at the expense of shoring up our defenses at home. In fact, for the first time, we've seen material steps backwards when it comes to implementing recommendations from the Ransomware Task Force. This committee in particular should continue its bipartisan oversight of the administration to ensure that CISA is able to carry out its mission in the face of significant cuts to its workforce. Beyond the immediate changes needed, we must also look to the future. We will never achieve our strategic goals in cyberspace without moving upstream to make systems-level changes. This requires a firm foundation for efforts like the Common Vulnerabilities and Exposures, or CVE program, which helps the entire ecosystem understand and defend against cyber threats, and which is coming under increasing pressure from AI-discovered vulnerabilities. It demands more accountability for services like residential proxy networks that are regularly abused by criminals and nation-state adversaries. And it requires strengthening relationships among government agencies and between government and industry so that they are built on trust and emerge from truly collaborative engagements. Without these systems-level changes, we will remain vulnerable. I've several recommendations for the committee. First, the committee should pass legislation authorizing key programs, including the CVE program and the Critical Infrastructure Partnership Advisory Council, to ensure they are not interrupted. Second, members of the committee should work with your counterparts to pass long-term or permanent extensions of cybersecurity authorities, including the Cybersecurity Information Sharing Act of 2015 and the State and Local Cybersecurity Improvement Act of 2021. Third, the committee should also strengthen the ability of the private sector and government actors to work together to disrupt cyber threats by authorizing the Joint Cyber Defense Collaborative, or JCDC, and clarifying lawful defensive measures that private sector actors can take when countering ransomware or other cybercrime. And finally, I hope this committee will continue to conduct oversight and effective hearings, covering topics such as residential proxy networks, the Cyber Response and Recovery Fund, the rise of product security regimes, measures to disincentivize extortion payments, and the effect of AI on vulnerability disclosure. As leaders in cybersecurity in the House, I also hope you will work closely with other committees on cross-jurisdictional issues, including CISA funding, cyber insurance, expanding the E-Rate program to include cybersecurity, and additional oversight of the Salt Typhoon incidents carried out by the People's Republic of China, which target the telecom networks that form the backbone of our everyday communications. 2026 is a decisive moment. We can see the potential opportunities and dangers from AI on the horizon, but there is still time to act. As Americans, what we need more than anything today is leadership. When we move decisively, we can seize the initiative from adversaries and materially change the cybercrime landscape. I hope today's hearing is an opportunity to jumpstart a new wave of bipartisan, effective, and transformative cybersecurity policy. Thank you for the opportunity to testify, and I look forward to your questions.
Targeting Healthcare: Legal and Penal Consequences
Thank you, Ms. Stifel. Members will now be recognized by order of seniority for their five minutes of questioning. I now recognize myself for questioning. Ms. Kaiser, in your opening statement, you mentioned that healthcare facilities have become the single most targeted within the group. I think the number that I recall you said that in 2025, there were 460 attacks, doubled from the previous year. And you mentioned in your written opening statement, and you touched a little bit briefly in your oral opening statement, about an attack in my home state of Mississippi. And just for the benefit of the other members of this committee, I want to read a little bit about what's contained there in your opening statement about that attack. You say on February 19, 2026, when ransomware actors struck the University of Mississippi Medical Center, also known as UMMC, that it was not simply a large hospital, but it was the medical backbone of the entire state. It is Mississippi's only academic medical center, operating seven hospitals, 35 clinics statewide, and home of the state's only Level 1 trauma center, the state's only children's hospital, and the only organ and bone marrow transplant program. When attackers took down UMMC's network, knocking Epic, its electronic healthcare records system, fully offline and forcing clinical staff to revert to pen and paper, they did not merely disrupt a business, they degraded the emergency medical capacity of an entire state. Clinics closed across Mississippi, outpatient surgeries and cancer treatment appointments were cancelled. For nine days, the state's only facility equipped to handle the most severe trauma cases operated under manual downtime procedures with staff tracking patients, medication, and orders on paper. You then go on to say the hackers behind the UMMC attack knew exactly what they were targeting. They contacted the hospital afterwards with demands. They understood that they had taken down a system that Mississippi patients depended on for survival, and they used that leverage deliberately. Ms. Kaiser, I will tell you that I believe that there are no penalties too severe for individuals who would target our healthcare system. You in your report, you and also touched on this in your opening statement, you talk about a couple of different things. You talk about using terrorist designations for those individuals who would attack hospitals. You talk about individuals being charged with murder or manslaughter if those attacks led to the death of individuals. And I think you did say in your opening statement that there had been a number of deaths, 47 that had been documented with old information, we believe now that number to be in the hundreds. And so as it relates to the terrorist designation under 18 U.S.C. 2331 and under 8 U.S.C. 1182, do you believe that the Department of Justice currently has the authority to charge under those sections, or do you believe that Congress needs to specifically give the Department of Justice that authority?
So the law defines terrorism as acts dangerous to human life, intended to coerce a civilian population. I think that encrypting a hospital system and demanding ransoms while patients are being diverted meets that definition, but I'm not asking for a designation today. What I'm saying is that we need honest legal analysis towards that, looking at the existing law and determining if departments believe it meets those thresholds. I mean, those designations aren't a blunt instrument, they're a scalpel. There's a deliberative process behind that where they only designate the worst of the worst. But I agree completely with you, and I want to emphasize what you said, there's no penalty too strong for the individuals that are holding Americans' lives at risk. They're making calculated decisions to target these individuals, and that's why Halcyon is actually funding an update to that research I noted to see exactly how we quantify the risk today.
And are you aware of an example where the Department of Justice has ever used these code sections to seek criminal charges under the definition of terrorist for an attack on healthcare system?
I'm not aware of any, but with the new executive order, I think that opens a broader spectrum for the Attorney General to look at the most serious provable offenses and determine what weight they can bring to bear.
And one last question as it relates to murder and manslaughter as far as federal felony murder charges, kind of the same question, do you believe that Congress needs to give the Department of Justice additional authorities to charge under that section, or do you believe that they have the current authorities now and we just need to make that on a case-by-case basis?
Clarifying guidance would be helpful, but they likely have the authorities today under the current statute.
Thank you. At this time, I yield back and I recognize Mr. Correa for his five minutes of questioning.
Thanks, Mr. Chairman. Ms. Kaiser, I'm going to follow up on that line of discussion. Do we need clarifying language to redefine or expand the intent of the law to go after some of these individuals? Sounds like the language is there, it just has not been applied in these circumstances.
We've conducted legal analysis and have determined on our end that the language exists as it is now to be able to pursue this, but the process by which they conduct those types of activities is something that needs to be arbitrated across all of the departments. I'll emphasize one specific aspect there, it can be very difficult to prove an exact death at a hospital or medical facility in the middle of an attack. So we can look at Medicare data, Medicaid data, and say there's an excess number of deaths when there's a ransomware attack. But proving that one specific death is harder when you're going to paper and pen, when you don't have electronic records, when you're in the middle of a crisis. So the way in which a prosecutor needs to approach this...
Is this akin to the felony murder rule?
Yes.
And trying to think along those lines.
Federal Workforce Cuts and Agency Resources
Exactly.
Thank you. Very quickly to each and every one of you, is the federal government doing enough in its role, a leading role in this area, Ms. Kaiser?
I worked these issues for years at FBI and I believe...
Do we need to step up even more?
They need additional authorities and resources to be able to...
So the answer is we need to do more. Mr. Redbord.
We need more resources, we mean newer tools, we need more training across the government.
Mr. Bercu.
We continue to work well with the federal government, but more is something that we think continues to need more resources and prioritization.
Ms. Stifel.
The acting director of CISA has identified the need to rehire 300 individuals, so I would say yes, we definitely need additional...
Those 300 were laid off through...
There have been significant decreases in staffing across the federal government, particularly in the cybersecurity space, and we understand that about a third of CISA's workforce has left the agency.
Quick question each one of you, Ms. Kaiser, what keeps you up at night?
That Americans may not understand how much at risk and how many lives at risk these criminal groups are holding them at every...
Mr. Redbord.
That AI is supercharging the operations of our adversaries and we need to make sure that we're scaling at the same...
Mr. Bercu.
The daunting amount of work that we all need to put up our sleeves and do together.
So we're not there yet, far from it.
We're working on it, but yes.
Ms. Stifel.
The scope and scale of vulnerabilities across our critical infrastructure, and in particular thinking also about our state and local entities that have recently had resources removed from their ability to shore up their defenses against cyberattacks.
Finger pointing is easy to do up here. I think at the end of the day, we just got to step up and say the buck stops here. What is it, Ms. Kaiser, what are your recommendations that we in Congress can do to start fixing these challenges?
Championing the policies that I noted within my opening statement, the antiterrorism designations, examining that, examining the felony murder laws, but also ensuring that we are funding the state and local governments that are constantly under attack by these actors.
State, the locals as well. Mr. Redbord.
Empowering the private sector. The government has the authorities, the private sector has the data. The private sector needs the authorities as well to go after...
Strengthen the weakest link in the chain. Mr. Bercu.
I'll agree with my colleagues, there's a lot of work being done in the private sector, there's a lot of innovation investment, and we need to keep pushing forward with that in partnership with the government.
Ms. Stifel.
I would say looking to pass long-term or permanent extensions of cybersecurity authorities, including the Cybersecurity Information Sharing Act of 2015 and the State and Local Cybersecurity Improvement Act of 2021.
My last 28 seconds that I have, I would have an ask for you. Five minutes is very short for us to get to specifics, but I would ask each and every one of you to give me in writing later on your five top recommendations of what we here in Congress can do to move forward on these issues, not only protecting the future colonial pipelines, but protecting Main Street. Those are the folks that just have nowhere to turn other than really to suffer in silence. Thank you very much, Mr. Chairman, I yield.
Gentleman yields. The chair now recognizes Chairman Ogles for his questioning.
Thank you, Mr. Chairman, and thank you to the witnesses for being here. I mean, obviously we're in a new era, a new day when it comes to cyber and cyberattacks, etc., primarily driven by AI, and that's where I guess I want to start is what, when you look at AI and the tools that are being deployed and how quickly AI is advancing, what can these criminal networks do today that they couldn't do just months ago? Ms. Kaiser.
So we see predominantly adversaries using AI to gain that initial step into company networks. What I mean by that, it's easier to lie with AI. It's easier to make convincing emails with malicious links, it's easier to make these deepfakes, these fake videos or fake voice calls that trick companies into letting them on the network, and then it's easier to exploit vulnerabilities or find vulnerabilities that let them on. That being said, what we see today is the most benefit is going towards the wannabe cyber actors. Advanced adversaries are integrating AI, they're looking at it in a way in which businesses are today for efficiencies, but there's a world of people who couldn't do attacks yesterday. They can today, and even if they're noisy, even if they're not all that effective, going from zero percent to five percent is a big win for them, and what we're going to do is exhaust security teams and cause massive problems in how they develop these tools, how they develop their attacks, where it may render certain types of data or certain companies just unavailable for recovery.
Mr. Redbord.
There are two really important pieces to this. First, our adversaries are using it at scale. I mentioned a 500 percent increase in AI-enabled fraud and scams. We see ransomware actors using agents as affiliates really for the first time. We're seeing North Korea use it to launder the proceeds of billion-dollar crypto hacks. But the other part that sort of I'm most focused on at TRM, we're working with the Department of Justice, with the Treasury Department, with the FBI, IRS-CI, DEA, Secret Service to provide AI-enabled tools that allow us to move as fast. For me, that's the answer here, right? Bad actors are always early adopters of transformative technology, think automobiles, end-to-end encrypted messaging apps, crypto, and now AI. We need to move as fast as those bad actors, and the tools exist today.
Mr. Bercu.
Yeah, and you know, I'd echo a lot of the comments of my colleagues that it really enables the improvement of the quality of the scam and really helps that. It makes, you know, more people are able to do the scams now that they have the equipment, but it also increases the scale in what we see in the calling side. That said, you know, similarly, our folks are using AI. They've long used machine learning, automation, and so there's some things like it's easier in the calling networks to detect someone making millions of calls versus someone making five really bad ones. So some of our tools actually still work well in an AI world, but we're continuing to evolve as well.
Ms. Stifel.
AI is making it harder for victims to say no to making a payment. And one of the reasons for this is the shift that we've seen in the ransomware ecosystem, whereas previously ransomware actors encrypted data, meaning that they locked it up, they now take the data and use it to extort victims to force them to make a payment. So when they've copied records, whether it be from a hospital, intellectual property from a Fortune 500 company, or someone's private images as the ranking member described, they're now using AI to analyze that data to be better able to, they in fact in many cases know the victim's financial, for example, their financial capacity more than the victims do, and they're using that analysis capability to essentially have a response to every blockade that the victim tries to assert, making it harder for the victims to not make the payment and disclosing this information eventually jeopardizing both the long-term stability of that organization but also putting our ability as leaders in the global economy and innovators at risk.
Thank you, ma'am. Ms. Kaiser, you know, five years ago the Department of Justice made the decision to elevate ransomware investigations to the same priority level as terrorism cases. As we go forward, should it be not just a priority but actually classified as a terrorist attack when you're targeting critical infrastructure?
There are substantial benefits to what you're talking about. I mean, a designation doesn't just freeze assets, it changes the entire geopolitical equation. In particular, imagine telling a foreign government you have a designated terrorist living in your country. That changes safe haven conversations with these countries that are harboring all of these criminal groups. I think this will really have an effect, especially among the 60 nations whom we share a membership with the International Counter Ransomware Initiative, saying nation states that tolerate ransomware criminals, I mean, they need to feel that pressure.
And then real quickly, you know, obviously this is a problem at scale. I mean, prior to my current role, I was CEO of the county, the county executive. We had a regional hospital in my county, incredibly vulnerable, right? So what is more practical, making that type of designation and cutting the head off of the snake, so to speak, or trying to equip municipalities across the country? Either is difficult, but we've got to figure this out as we go forward because again, it's becoming more aggressive. Really quickly, and I'll yield back, Mr. Chairman.
I don't think I can choose. I think you have to have defense and offense to be able to block these attacks at their source. One note I'd make is that when we're equipping municipalities, when we're providing out those funds, we do need to make sure that we're equipping them with the knowledge as well of how to spend that money, how to arbitrate between the various aspects and ensuring to your earlier question on AI, we're looking not just at prevention, which is going to be really difficult in the age of AI, but like how do you detect it quickly? How do you kick them off your network? How do you really make sure you're resilient?
Thank you. I yield back, Mr. Chairman.
Gentleman yields back. The chair now recognizes the gentleman from Rhode Island, Mr. Magaziner, for his questioning.
Thank you, Mr. Chairman, and to my colleagues and to our expert witnesses here. Cyber scams are a tremendous and growing challenge. We see that in my home state of Rhode Island. We know that critical infrastructure is being targeted: water systems, power systems, hospital systems, businesses, organizations. I think the most tragic stories are when seniors are scammed, scammed out of their life savings that they worked their whole lives for and in some cases reduced to poverty as a result. So this is something that should be a priority of this Congress, and I thank my colleagues for convening this hearing. A few issues that I wanted to call attention to and ask our witnesses about. Mr. Bercu, in your written testimony you talked about SIM farms or SIM, I forget what you called the phrase you used, but SIM boxes. I think this is very important, and we had a few of us had a classified briefing on the topic not long ago. Could you just explain to all of us once again what these are and why they're so dangerous?
Yeah, absolutely. So it's where the criminal actors will get prepaid phones, prepaid SIM cards, they can plug it into technology, and then they are able to generate from the U.S. on our networks calls that really when the caller may sit or, you know, text messages and the like, may sit abroad. So it really is an enabler. It's not calls coming in through foreign gateways, they're actually starting in the U.S.
And crucially, some of these SIM boxes or SIM farms, you know, can generate thousands of calls, right? Thousands of calls essentially anonymously that can be used, you know, with real phone numbers to fraudulently scam people. Is that right?
Yes, one of the challenges is it doesn't look like an individual who's making, you know, hundreds of thousands of calls because it's individual numbers, individual SIMs making a handful of calls, but it is something the industry's been working on how to better identify it with traffic analytics and other things to take them down quickly.
That's what I wanted to ask about. I mean, to any of our witnesses, do you feel that the telecommunications industry is doing enough to identify where these SIM farms are located? Because as I understand it, if thousands and thousands of calls a day are being made from the same building, the same geography, that ought to be something that the companies themselves could track and potentially flag for the authorities. Is that not right?
So it's something the industry has been working on. There's, you know, it's a complex ecosystem. It's not just customers of the large carriers, it's sometimes their resellers. But it is something that we've been working, we've had a working group with the major carriers that we've been tracing back calls that we identify SIM farms, sharing information and figuring out how to do filtering and other things to take them down quickly.
Would anybody else like to weigh in on this? Is there more that the industry could be doing or that we could help the industry do to locate these SIM farms? All right. Let me ask a related question then. My understanding is that one of the things that these fraudulent numbers are used for is to open fake social media accounts, right? You can use a fake phone number from a SIM card to open a Facebook account or an X account or whatever. Once it has been identified that an account has been opened with a fraudulent number, why would a social media company keep those accounts active? Am I correct that the big social media companies are still keeping accounts active that they know were created with a fake phone number? That's my understanding. And so, you know, I think we have to have a conversation with our industry partners, not just in the telecommunications industry about locating these SIM farms, but also with the email companies, the social media companies. If there is an account, and I think there's millions of them, that we know were open fraudulently with fraudulent phone numbers, why are you keeping those accounts active? They're clearly being used for fraud. I just want to ask, I only have a moment left, so I just want to ask all of our witnesses. The CISA workforce has been absolutely decimated over the last year. I think close to half of the CISA employees have been eliminated. Does anybody think this is a good idea from a cybersecurity point of view? Okay. Second, the administration has approved the sale of advanced NVIDIA chips to China, to the Chinese Communist government that is in many cases a sponsor of cyber attacks against the United States. Does anybody think allowing the sale of these advanced chips is a good idea? Well, that's something that I think we ought to do something about as a Congress on a bipartisan basis. And with that, I'll yield.
Gentleman yields. The chair now recognizes the gentleman from Arizona, Mr. Crane, for his questioning.
Thank you, Mr. Chairman. I want to say thank you to you guys for showing up today to help us get a better handle on this issue on online scams, crypto fraud, and digital extortion. I actually had a constituent reach out to me probably about six months ago who had saw an ad on Fox News and it was for farming equipment, tractors, etc., used equipment. He actually ended up making the purchase and never received the product. So he reached out to me. We were able to get in touch with the, you know, federal agencies who looked into it. Thankfully, the bank worked with this gentleman and helped him get his money back, but then he continued to text me letting me know that he was still seeing this ad run on Fox News. So a lot of our constituents see something on Fox News or CNN or whatever channel they're watching and they see that having some integrity to it. We really haven't covered that I've heard in this hearing, what would you guys advise average Joe American to do? What, you know, operating procedures would you have them look at and avoiding even getting involved in any of these scams? I'm going to start with you, Ms. Kaiser.
So when I was at the FBI, one of the teams that I had responsibility for was the Internet Crime Complaint Center, so the group that does the report we talked about today. The question I got a lot is like, why do you put out these stats? Like, what do you hope to get out of this? And my number one answer was so that people don't feel alone, right? That individuals understand that this happens to a large swath of American citizens and that if they should believe, if they believe they have been scammed, if they believe they've been attacked, they should report it to local law enforcement, to the FBI, to the Internet Crime Complaint Center. They should contact their bank right away because oftentimes, and I'll defer to my colleague on some of these money flows, but oftentimes some of that money can be recouped if it's done quickly.
But before we even get to that point, Ms. Kaiser, where they're attacked, how do they avoid getting attacked in the first place? Does, you know, how do they notice or have their spidey senses go off that, hey, this doesn't exactly feel right? Does anyone want to help the average Joe American with that one?
So it's incredibly difficult, but what I would note is that if you feel under like urgent pressure, it's probably a scam. Take a beat, take a step, call someone in your family, contact and identify ways in which you can verify that company, but it's really when you're put under pressure, oftentimes that's the biggest indicator that something's wrong.
Go ahead, Mr. Redbord.
I would just add, and I think that was quite frankly beautifully said. I think what we need is a massive public service campaign at a federal level across all these different jurisdictions. A just say no, if you will, for scams and fraud. We need people to understand that to take a beat, as Ms. Kaiser said. At TRM, we run the largest reporting database for fraud and scams in the crypto ecosystem. It's called chainabuse.com. You can go on your phone and look at it right now, it's just open source. It provides victims an opportunity to report so other people are not ultimately scammed down the road. So I think it's a combination of things. You're right that we talk a lot about offense and how to go after these transnational groups, but really defense is a key part of this, and I think public service and awareness is absolutely critical here.
Of all the ways that these scammers can target Americans, whether it's text message, social media, phone calls, emails, of all of those, are you seeing these individuals target, you know, specifically or more predominantly through a certain means?
You know, it's through a whole host of different types of ways. Just to put a point on I think one more thing Ms. Kaiser said is that the FBI has been terrific in this area. It's not only through IC3, but they run a program called Level Up where they're literally doing hand-to-hand combat. They're going to reach out to victims directly, show up at your door and say, hey, don't go ahead and send those funds. Obviously, it's very hard for this to scale, but you marry technology with that type of initiative, and there's a lot of good work being done out there.
Absolutely. My office two weeks ago had FBI out at events in Payson, Arizona, and Overgaard to help residents identify and look at some of the ways that they could possibly be scammed or defrauded. So I want to say thank you to the FBI for doing that. Mr. Bercu or Ms. Stifel, with my remaining time, do you guys have any suggestions for Americans on how to avoid even getting entangled in any of these fraudulent schemes?
Yeah, I'd agree with my colleagues, especially the take a beat, but I think one is recognize that any of us could be a victim. I mean, I work on these issues and I was under the spell for a few seconds when I got a message that my account was accessed from Russia. So it can happen to any of us, so I think that's why the take a beat is really important. But take advantage of the tools that are out there. There's blocking, labeling, there's other things on the phone side, use those.
Thank you. I yield back.
The gentleman yields back. The chair now recognizes the gentlelady from Illinois, Ms. Ramirez, for her questioning.
Thank you, chair and ranking member, for this hearing today and for the witnesses also for being here as well. While the substance of this hearing is certainly very serious, we are back to Republican hearings dripping in unseriousness. And I'll tell you why. It's laughable that my Republican colleagues are trying to use this time to condemn fraud, extortion, and crime while one, supporting the most corrupt, scammy administration in U.S. history, and two, being completely unwilling to conduct oversight or rein in the scammer-in-chief. In preparing for today's hearing, it was noted profit-motivated transnational criminal organizations, they leverage corruption, intimidation, and advanced technologies so they can reach new markets and create income streams. Such organizations defraud U.S. citizens, businesses, and government agencies while at the same time moving billions of dollars in illegal earnings through global financial systems. Does this sound familiar to anyone else? The House Judiciary Committee Democrats released a report last year that documented how the president has used his office to enrich himself and his family with crypto holdings worth as much as $11.6 billion and income of more than $800 million from the sale of crypto assets in the first half of 2025 alone, while at the same time dismantling federal oversight and safeguards that once protected Americans from fraud, from scams, and financial exploitation. Profit-motivated transnational crime, corruption, and scamming, that's how the Trump administration operates. He uses all those tools to reward his loyalists and then to be able to remain in power. Look, while I agree we have to combat corruption, crime, and scams, and it has to be important for us to understand the U.S. economic and national security impact, we also have to understand that combating these threats require adequately resourcing and staffing these federal agencies, staffing critical infrastructure, and having checks and balances and policy solutions that make us all more secure. But my colleagues here are unwilling to do any of these things. How? They're decimating CISA, they're abdicating their oversight authority, and they're wasting our time instead of advancing policies that protect working people from today's crooks and con men in office or from buying seats in Congress. Look, my district is so tired of corruption, of self-dealing, and lack of accountability. And so I want to get to a quick question here. Ms. Stifel, it's my understanding that in March, the White House released President Trump's cybersecurity strategy for America. The document was just over three pages of substance around about six pillars. In your professional opinion, is a six-page document with three pages of substance sufficient to describe a comprehensive strategy for American cybersecurity?
The most recently released strategy does stand in contrast to the 2018 strategy, which laid out a number of key elements that would strengthen the country's cybersecurity posture, including establishing Cybersecurity and Infrastructure Security Agency.
Yeah, thank you for your response. The reality is, I'll say it more directly, it is not, because the 2018 strategy was a far more comprehensive than what we are seeing today, and it should concern every single member of this subcommittee. And it's because Trump and his cronies around the world are the most dangerous transnational criminal networks threatening us right now. They're swindling us, stealing our hard-earned dollars, waging a war in our cities, and committing war crimes abroad, all for private profit. It's not lost on me that Trump signed the legislation establishing CISA, but started attacking it the minute it became an obstruction to his criminal interest. If you ask Republicans, do you want to use the power of government to end hunger? Nope. Make housing more affordable? Nah. Bring the prices of gas down? No. But if you ask them, do you want to use the power of government to get rich and trick, cheat, and defraud the American people? Well, what we've seen here is why the response is yes, let's do that. That is despicable. That is not why we were sent to Congress, and it's why we have to address the issues of cybersecurity, but we also have to address the issues of corruption in the White House. With that, Mr. Chairman, I yield back.
The gentlelady yields back. The chair now recognizes the gentleman from North Carolina, Mr. Knott, for his questioning.
To the witnesses, thank you all for being here. I, this is an obviously a very important issue, one that's of great significance to all Americans. And Ms. Kaiser, let me just start with you. We've talked a lot about, you know, government personnel and resources that are in place and so forth, but given the dynamism of this threat, how important is it in not just a staffing component but also a systems component to address this issue, and is it even possible from a governmental standpoint alone?
In terms of systems, you're talking about the actual networks from a government system?
Yes.
So within the government itself, I was lucky enough to be able to be a part of the interagency weekly meetings that talked about, you know, threats to the U.S. government networks as well as threats to across our critical infrastructure. And what I can say is it's the same, right? The types of targeting that happens to the private sector happens to the government. The defenses are the same. It's ensuring that you've done basics, but now with AI, right, you have to do more, and it's really in that kind of you have to assume you could be compromised, so what do you do then? How do you kick them off?
But in terms of the threat itself, creating a defense for that threat is obviously going to require a whole lot of flexibility, a lot of creativity. These are adjectives that are not usually reserved for the government side of things. And so I'm asking from your standpoint, how can the government evolve with the threat that seems to change day over day, night after night?
So one aspect is when the government is looking at reauthorizing and allocating the funds, the cybersecurity grants that Congress has authorized, it's doing so in a really smart way. Like identifying the actual needs of the sector or government agencies that are receiving the funds, it's having a two-way conversation, not a one-way conversation, and it's moving fast. It's being able to allocate those funds because in cybersecurity, you know, time equals attacks.
Yeah. Mr. Redbord, I want the same chapter to you. I'm very skeptical of that when you look at the government bureaucracies, whether it's federal, state, or local. They're usually clumsy and very wasteful, and that's not the nature of this threat. From your perspective, how can we best align to defend the American people against this type of threat?
Thank you for the question. Look, over the last, you know, couple of years, I think we've seen a real willingness from the public sector to be working much more closely with the private sector. And part of this is because we move very, very fast. And whether that means ensuring that the government has the data that they need, we have it, or we can go out and get it and we provide it. So I think it's the real key here to solving this is working really, really closely together to ensure that the authorities and the data are all there to take on this threat.
And in terms of the ingredients that are needed to match the threat, from your perspective, what types of needs and progressions do we need to be sure that we're supporting in Congress?
It's really that every, I mean, you and I were both Assistant U.S. Attorneys, and I think it's really about the tools. It's that investigators have every single tool they need. And when bad actors are leveraging technology, we need to make sure that every investigator has the AI technology, the blockchain intelligence, the things that they need to investigate.
Well, that's never going to happen from the government side organically. So with the private sector side, how can we ensure that we have the necessary environment so that the private sector can develop the tools that will be used to protect Americans?
Absolutely. In my opening statement, I mentioned the Beacon Network. It's the largest public-private partnership in this space, and it's in large part because the private sector came together and said, hey, we need to stop bad actors in the wake of a North Korea hack from off-ramping funds to use for weapons proliferation. So we all came together, reached out to the public sector and said, let's do this together. And I think that's a really sharp model for the what is possible today.
And in terms of the posture of our country, it seems in many respects, I mean, we've mentioned China, Russia, North Korea, and certainly the Iranian folks, they're all attacking us. It seems to have exceeded law enforcement and moves into more of a national security component. How does that change the posture at all? I'll start with you, Ms. Kaiser.
It's absolutely a national security issue. I think that countering cyber threats from wherever they come is really the national security challenge of our lifetime. You mention the nation states and like one aspect I'd like to highlight here is nation states, so we've seen Iran, we've seen China, we've seen Russia, we've seen North Korea actually use these cybercriminal tactics, use the same infrastructure, use the same way in which the criminal groups are targeting us to actually conduct attacks on American networks. That's happened in the Iranian conflict right now. And so it's really important to look at this all as a connected system and understand that disrupting one component disrupts others.
It's the absolutely most important shift in the posture, you know, in recent history. Moving from law enforcement to national security. The reality is that wars are now fought in cyberspace and across blockchains, and we have to leverage every national security piece that we can, offensive and defensive.
Mr. Bercu?
You know, I just agree with my colleagues here.
Okay.
I would just add that I think we also as we're thinking about CISA is for the for Congress to authorize the Joint Cyber Defense Collaborative. We, as you have reiterated, depend on industry to help strengthen and defend America, and we at this point are not on our strongest footing with among other things also the lapse of the Critical Infrastructure Partnership Advisory Panel capability for the Secretary of DHS and the Director of CISA to have honest conversations with industry about the range of threats that they're facing and the capabilities they can bring to defeat them.
Great. Mr. Chairman, I yield back.
The gentleman yields back. The chair now recognizes the gentlelady from Texas, Ms. Johnson, for her questioning.
Thank you, Mr. Chairman. Thank you all for being here. I think this is a very critical and important discussion in our nation at this time. We've all experienced an extreme increase in spam texts and calls ranging from toll road payments and UPS package fees to solicitations for crypto investments or or even romantic relationships. In 2024 alone, Texans reported losing $1.35 billion to scams, with the most significant losses reported to those over 60 years old. WFAA, a local news outlet in Dallas, reported that scam reports increased in 2025 by 118 percent, doubling what was reported in 2024. These scams often target vulnerable communities and three in 10 Americans who lost money to scams say it has a significant impact on their finances. And in one case, a victim lost $47 million causing an entire bank to collapse and hundreds of people to lose their retirement savings. The truth is these sinister operations by profit-motivated transnational criminal organizations are operating at a never-before-seen scale, and our government is not equipped to address it right now. This is a self-inflicted wound thanks to the Trump administration's gutting of CISA, whose mission includes identifying and preventing these crimes. And I want to echo many of the concerns my colleagues have made and many of you on the panel have made concerning the defunding of CISA and that we need to absolutely invest in a robust CISA if we are going to address this problem. Ms. Stifel, my understanding is that these scams have accelerated in recent years to the proliferation of hundreds of large-scale compounds powered by forced labor across Southeast Asia, particularly in Burma, Cambodia, and Laos, as well as the Philippines. In Cambodia, for example, corrupt officials allow scam centers to operate in the open where scamming now generates $12 billion annually, over half of that country's GDP. Why is international collaboration so critical in addressing these scam centers, and how have recent cuts in the reorganization of the State Department put those efforts of collaboration at risk?
We are, as the ranking member mentioned in his opening statement, only as strong as our weakest link. And the examples that you gave are representative of issues that we see as we also explore ransomware, including the willingness of safe havens to harbor criminals and not respond to requests for assistance or to deny, bury their head in the sand. We depend on a whole-of-government, as my colleagues have mentioned, response to the threats that this country faces that are emanating through information and communications technologies or the internet. That means that we need to have not only a deep bench at CISA, but we also, as you mentioned, need to have a deep bench at State. And among other things, the State Department is now our lead in something called the Counter Ransomware Initiative, which is now in its fourth year with now over 70 countries and organizations participating in it. And it is the one place where these governments and multilateral organizations have come together to identify a priority, exchange best practices, identify policy objectives, build investigative capacity to counter, in this case, the ransomware threat. But that type of leadership that that emanated from the United States, the Counter Ransomware Initiative, is something that the United States started and the State Department has taken on the responsibility to carry the mantle in this administration. We need to continue to show that leadership, and we have to do so with a full bench around the interagency, both at State, FBI, CISA, elsewhere.
Right. I am very concerned about the diminished bench that we have at this time. And just to the general panel, what suggestions do you have for this committee to how we can improve collaboration between Department of Homeland Security and the State Department to address this issue in particular? Do you all have any specific recommendations other than what Ms. Stifel was just talking about?
I would just say over the last several months, year, we have seen more and more sort of interagency approach to these issues. It is not going to just be the State Department, it is not going to be just DHS or law enforcement agencies or national security agencies. It is really all coming together. A couple great examples I think that exist today, the DOJ started a Scam Center Strike Force about six months ago. There was a takedown of one of these large scam compounds in Cambodia called Prince Group that involved the largest forfeiture action in U.S. history, about $15 billion of proceeds from this type of illicit activity. There is a model in place, but there is also 10 more, 15 more Prince Groups across Southeast Asia, and we have to leverage every authority from offensive cyber to public-private work in order to go after these bad actors.
Unfortunately, I am out of time. But Mr. Chairman, thank you for this conversation. I do think responding to scams in this country is one of the most critical things that we can be doing, and I applaud the work. Thank you.
Gentlelady yields back. The chair now recognizes the gentleman from Virginia, Mr. Walkinshaw, for his questioning.
Thank you, Mr. Chairman, and thank you for holding this hearing on an important topic. We want the bureaucrats to be dramatically affected. When they wake up in the morning, we want them not to want to go to work because they are increasingly viewed as the villains. We want their funding to be shut down. We want to put them in trauma. That was Russ Vought, President Trump's OMB Director, talking about, among others, the 1,000 federal workers who worked at CISA who were fired, pushed out, or driven out. So while we have an executive order, words on paper that says we take this issue seriously, we have a lot of language at the dais today about how important this is, this administration is not taking cybersecurity seriously. Because when you treat the experts who are doing the work, and they are creative, I will talk about that, when you treat the experts that way, you are not taking the issue seriously. I want to just cite some of what you wrote in your written testimony, Ms. Stifel. The Critical Infrastructure Partnership Advisory Council, a core mechanism for coordinating cyber policy across government industry, has yet to restart since being shuttered. If the Secretary of Homeland Security decides to convene sector-specific advisory committees, coordination will be a challenge given cuts. Budget cuts to the FBI's Cyber Division expected to reduce personnel by half. The acting commander of U.S. Cyber Command testified that the effect on the command's ability to carry out its mission would be impactful because of budget cuts. We have talked about the State and Local Cybersecurity Grant Program, which proved, quoting Ms. Stifel, effective in marshaling resources to help state, local, tribal, and territorial governments improve their defenses, yet it has been zeroed out in the administration's budget. Shared cybersecurity services provided at subsidized rates for state and local governments, especially small rural state and local governments that do not have the resources through the Multi-State Information Sharing and Analysis Center, have been canceled, leaving states and local governments, especially in rural communities, to scramble for protection. That is what has happened. Ms. Stifel, one that you did not, I do not think, note in your written testimony, and I apologize if I missed some of what you said, is CISA's Pre-Ransomware Notification Initiative. Can you tell us what that is or perhaps what it was?
Thank you. It is a really critical program that currently is not operating to my knowledge. The individual who ran the program is no longer at the agency. And the program essentially received indications of warning from industry in many cases, in part supported by the Cybersecurity Information Sharing Act and the incentives that that legislation offers to industry, the liability protection it affords to share information with the government that the government can then leverage to defend the homeland. So this program, run by actually basically one individual, would call, receive these tips and call victims who either already had a threat actor in their networks or were known to be soon to be targeted by these threat actors and gave them notice that they were about to become a victim and in many cases worked with those victims and with their counsel to try and mitigate the risk that this they knew that they were about to face.
Would you describe that work as creative and nimble?
Quite. It is also, I think I want to underscore that it is really driven on trust. The ability for this particular individual to notify over 4,000 organizations and prevent them from beginning from becoming victims and preventing billions of dollars in losses to the economy does not come from three weeks on the job. It comes from, I think he was at the department for over a decade.
I will put a finer point on it. $9 billion. $9 billion in damages that initiative prevented, in large part because of the work, to use the term Director Vought likes to use, of one bureaucrat. And I guess we succeeded in making him not want to go to work because he left. And that program is no longer functioning. So ransomware is occurring today because this administration drove out the expert, the federal employee who was helping to prevent it to the tune of $9 billion. We are shooting ourselves in the foot. We have to stop attacking the experts who serve our nation because we have a political agenda. If this administration does not stop doing that, we will continue to lose this cyber war. I yield back.
Gentleman yields back. The chair now recognizes the gentleman from Texas, Mr. Green, for his questioning.
Cryptocurrency Regulation and Financial Oversight
Thank you, Mr. Chairman. Thank the ranking member as well, and I welcome the witnesses. Mr. Chairman, we understand that cryptocurrency fraud is something that has to be dealt with by way of regulation. Currently, using digital methodologies and unregulated currencies, TCOs can remain anonymous and evade law enforcement. This ability to be pseudonymous, pseudonymity, is a problem, pseudonymity. It is a problem because we have allowed a system to develop that allows people to transfer unlimited amounts of funds without identifying themselves. Ms. Stifel, how do you propose we regulate such that we can deal with the pseudonymity aspect of the transference of large sums of money, which, by the way, may go to terrorist organizations, used for ransom purposes, extortion? How do we deal with that?
Congressman, when we established the Ransomware Task Force, one of its core recommendations was to ensure that know-your-customer and anti-money laundering capabilities were required of exchanges that transmit these currencies. In addition, we think that similar due diligence measures can also be taken in other aspects of the ecosystem, for example, in the domain registration space, that would also help us take a more scaled approach to combating a range of illicit activity online.
Now, pseudonymity exists and is efficacious because you have peer-to-peer transfer of money, cryptocurrency. In the banking system, you have a central bank. Goes to the central bank, then to a person. We still have this problem of peer-to-peer transference. By the way, we can catch many of the culprits, but it is difficult. And some of the culprits get away because of peer-to-peer business. And the crypto industry is spending millions upon millions of dollars to make sure Congress has people within it who are going to support the peer-to-peer transfers. They place privacy above the ability to prevent extortion, to prevent avoiding paying taxes on money. This pseudonymity has to be dealt with such that we, as you said, know your customer. But you can't know your customer if you don't have a customer to know. So again, I'm not pressing you. I understand you understand the problem. But the problem is actually bigger than simply saying we'd like to regulate when millions upon millions are being spent to buy the best Congress that money can buy to support the crypto industry's insatiable appetite to maintain pseudonymity. I welcome your comment if you have one.
The ability to investigate illicit activity is central to the government's ability to defend the nation. And so I would assert that there is definitely a need to have greater visibility into a range of activity online, which is one of the reasons why in my written testimony I reiterated the need to reauthorize the Cybersecurity and Information Sharing Act of 2015.
I have 11 seconds. Yes, I read body language quite well.
Thank you so much. I spent my career as a prosecutor investigating cases involving bulk cash smuggling and networks of hawalas and shell companies and high-value art. There was no ability to trace those things on an open public ledger. We work very closely with law enforcement today to be able to combat fraud and financial crime in crypto because we actually have the ability to watch every transaction in real time, and there's a lot of benefit there. Thank you.
And every transaction is more than just a few thousand transactions. Do you agree?
Every transaction is more than a few thousand transactions. I'm so sorry. I'm not...
You said you have the ability to watch every transaction.
Every transaction in real time on an open public ledger where crypto moves.
Right. And what I'm saying to you, that that is an awesome number of transactions.
It's an awesome number of transactions. We can now see more transactions on blockchains than we can in the traditional world.
And in so doing, you have to also not only see them, now you've got to look into each one of them so as to ascertain whether or not this is a part of some illicit trade.
Absolutely. And we can now do that on blockchains where you never could do that in the traditional financial system, right, through networks of wire transfers and bulk cash. Now we can see every transaction move on an open public ledger in real time and track and trace to build investigations.
Are you saying that all transactions are on the open public ledger?
All transactions on public blockchains, so Bitcoin, Ethereum.
And public blockchain.
Public blockchain.
Okay. Do you agree that there are blockchains that you are not monitoring?
We monitor every blockchain.
Every blockchain in history? I mean, every blockchain that exists?
When you lose visibility on financial transactions in the cryptocurrency world, it's often because it moves into a cryptocurrency exchange or off the blockchain. Certainly there are privacy tools, and we are getting very, very good at being able to track those.
Permit me to ask this as a follow-up. The people who engage in extortion, the people who engage in extortion and succeed with the extortion, explain how they elude the transparency that you're speaking of.
It's really become a race. It's a race between law enforcement and bad actors. Bad actors are trying to off-ramp their funds as fast as they can. So a ransom payment is made in Bitcoin, for example, the FBI and others are using tools like TRM to track and trace. But it's this cat-and-mouse game that has always existed, and that's why we have to shut down those off-ramps. And just real quickly, those off-ramps are highly regulated. They're required to have in the United States today, they're required to have compliance controls.
I'm in agreement with you. That's why I mentioned the awesome number, because of the number and the speed at which these transactions take place and the pseudonymity associated with it, it makes it difficult to catch the culprit who's moving quickly before you can get to him.
And that's why it's so important that law enforcement and regulators have the tools to move as fast as these bad actors.
I agree with you. Thank you. Thank you.
Closing Remarks
Gentleman yields back. I would like to again thank our witnesses for being here. Just to show the frequency of these attacks, as we were here addressing this very important topic, my good friend and the ranking member received an email scam just moments ago. So this is another one, as he would say. So this is an ongoing issue that we will continue to address. Again, your testimony, your insight into these topics help us as we try to shape policy and try to make sure that we are legislating to protect the American public. In closing, the members of this committee may have additional questions for the witnesses. We would ask that witnesses respond to any additional questions in writing pursuant to committee rule 7E. The hearing record will be held open for a period of 10 days. And with that, without any objection, this committee stands adjourned. Thank you again.
Same-day access
Read every hearing transcript the day it happens
Paid seats unlock fresh transcripts immediately, including synced video and clear summaries.



