▶ 0:11:16The Committee on Homeland Security Subcommittee on Border Security and Enforcement will come to order. Without objection, the chair may declare the committee in recess at any point. The purpose of today's hearing is to examine how transnational criminal organizations are increasingly exploiting digital technologies, including cryptocurrency, online platforms, artificial intelligence, and global financial networks to conduct fraud, launder illicit proceeds,
▶ 0:11:47and target American citizens, businesses, and critical infrastructure. I would like to thank our colleagues from the sub Cybersecurity and Infrastructure Protection Subcommittee for partnering with us for this joint I would like to now recognize myself for a brief opening statement.
▶ 0:12:07Good morning and welcome to the Border Security and Enforcement and Cybersecurity and Infrastructure Protection Joint Subcommittee Hearing examining how transnational criminal networks are increasingly targeting Americans in the digital world to expand their illicit activities and increase their profits through scams, fraud, and extortion.
▶ 0:12:31As technology has evolved and web-based services have crossed traditional borders, cyber-enabled financial crime has risen sharply. Transnational criminal networks from Mexican drug trafficking organizations to Southeast Asia scam operations are targeting Americans. With an expanding arsenal of digital tools available in the public sphere, we must build and maintain a strong defense against cyber-enabled criminals.
▶ 0:13:01Most Americans have encountered some sort of scam enabled by technology. These scams often target our aging and elderly families and constituents seeking to drain their life savings and retirement plans using emotional, manipulative tactics. In 2025 alone, scammers stole more than $20 billion from Americans. Criminal networks use the digital domain to promote their illicit activities.
▶ 0:13:29The challenging nature of tracing cryptocurrency provides a landscape where Mexican drug cartels and other criminal organizations can launder money by converting profits from illegal activities into digital currency, which can be accessed across the world in a matter of seconds. Through this digital marketplace, the Mexican cartels are utilizing Chinese money laundering networks as a piece of their business models.
▶ 0:13:56President Trump issued an executive order designating certain terrorist, excuse me, certain cartels and transnational criminal organizations as foreign terrorist organization or FTOs. This designation has created opportunities to use new authorities to combat drug cartels and organized criminal organizations. Cyber-enabled crime not only victimizes Americans, but also raises concern for national security interests.
▶ 0:14:25Just last week in his testimony before the House Appropriations Committee, Todd Lyons, the acting director of ICE and Customs Enforcement, spoke about a major Homeland Security investigation involving Chinese Communist Party actors committing gift card fraud and sending proceeds back to military units in Digital extortion, which is another form of cybercrime, has serious national security implications.
▶ 0:14:52These ransomware attacks often involve foreign actors targeting sensitive industries such as education, government, and healthcare databases holding data or systems hostage and demanding payment for its release. My home state of Mississippi just recently experienced a major ransomware and I know that many of my colleagues' districts have experienced attacks as The severity and increasing frequency of these attacks is deeply concerning.
▶ 0:15:23Our critical infrastructure, our data, and our constituents must be protected. Congress must step up to secure our virtual border. President Trump's recent executive order identifying cyber-enabled crime as a priority and pushing an offensive approach on combating cybercrime is a positive step, but it must be built Given the role of industry, public-private partnerships are critical to facing these threats head-on.
▶ 0:15:53It is important that Congress examine how transnational criminal organizations are exploiting digital technology and targeting Americans. Today, we have with us experts who will share their insight on this growing issue and provide a valuable discussion on how Congress can work together to combat financial crime.
▶ 0:16:21I would now like to recognize the ranking member, the gentleman from California, Mr. Correa, for his opening statement. Thank you, Mr. Chairman. Um I can concur with you. Cyber, cyber defense in our country should not be a Democratic or Republican issue, but rather an issue of national importance for all of us, and that's the way it's been treated here in this committee. Um Working across the aisle to make sure we everybody in our society and all institutions in our society.
▶ 0:16:52Let me start out by telling you that I'm now a senior, and now I get senior And I guess that also comes with a nice Um recently, I was at home looking through my personal email, and I got an email from the IRS. Got my attention. Looked legit. Had the IRS logo, everything on it.
▶ 0:17:11It also said, "Unless you call us today, we will come and seize your assets, including your bank account assets." So, you know, I picked up the telephone number, and I called that 888 number, and person on the other side answering the phone call said, "Get your credit card ready.
▶ 0:17:30You have to pay us $20,000 right away, or otherwise, we will be on our way to your house." And they told me where I lived, "to pick you up and have you Pretty interesting conversation, very And I thought to myself, "Okay, what will some of my other seniors in my district do when they get that telephone call?
▶ 0:17:57They call, how much money will they pay?" And all of us know as seniors that, you don't tell your children when you get whacked. You don't tell your children when you get suckered. You just live in The other side of that social democratic uh bell curve are young children today that are essentially cyberbullied, young ladies who are essentially forced into doing things they shouldn't be doing, otherwise those pictures will be
▶ 0:18:27released to the world. Middle of that bell curve, you have one of my accounting firms in my district who got hacked, ransomware. The head of that firm had a choice.
▶ 0:18:42Report it, have all of your customers know that you did not have the system in place, so they will go to somebody else for and number two, you will be opened up for civil liability because somebody hacked your system. It's not a good place to be. Uh and Mr. Chairman, today I'm hoping beyond learning more about what's going we can come up with some good solutions that we can work on moving forward.
▶ 0:19:10Cybercriminals, transnational are no longer confined by borders. They're sophisticated, organized, leveraging corruption, cutting-edge technology, human trafficking. Especially those in China, Southeast they have built large scamming centers, very sophisticated, targeting our communities in the United States.
▶ 0:19:38Now, according to the FBI, cyber-enabled fraud in 2025 led to over $17.6 billion worth of reported losses. Reported Beyond that 20 billion, I bet you there's a lot more out there that will never go reported.
▶ 0:19:58Top of that, artificial intelligence helping these transnational organization scale their operations and increase their success rates at the expense of our taxpayers and citizens of this country. Highly personalized messages, password cracking tools, deep fakes where you can't tell between what's real and what's not.
▶ 0:20:25This is what our citizens are facing on every everyday basis back home. We all know about Colonial Pipeline. We all know about those big incidences that are reporting in the newspaper. But I believe the small firms, the individuals, moms and pops back home, never report this stuff.
▶ 0:20:49And when the threats are getting worse, my concern is this administration is failing to respond in many ways. Over the last year and a half, cybersecurity infrastructure or CISA, has had a third of its workforce cut. And their efforts, CISA, instead of defending us against cyber, their efforts are now redirected towards immigration enforcement and not cybersecurity.
▶ 0:21:20The president's fiscal 2027 proposed additional cuts that threaten, again, the defenses to defend our homeland and Main Street. Same way, Homeland Security Investigations or ICE HSI, those agents that have been dedicated to combating child exploitation, digital financial crimes, those efforts also redirected towards immigration enforcement.
▶ 0:21:49As I said earlier, Mr. Chairman, I hope he can look at these issues objectively, focus on the issues, the challenges that we have not only today, but moving forward, and come up with some good solutions across the board, across the aisle here, that we can all work together. Our constituents, our citizens, are depending on us because at the end of the day, a chain is only as strong as its weakest link.
▶ 0:22:18And this chain is about government, private sector, platforms out there, and consumers working together under the leadership of the federal government. Mr. Chair, thank you very much. Thank you, Mr. Correa. I would now like to recognize the chairman of the subcommittee on cybersecurity and infrastructure protection, the gentleman from the great state of Tennessee, Chairman Ogles, to deliver his opening statement. Thank you, Mr.
▶ 0:22:48Chairman, for holding this the joint hearing for partnering with my subcommittee to examine what has become one of the most urgent and far-reaching threats to the American people today. The hearing we are convening this morning concerns a problem that touches every community in this country.
▶ 0:23:04It affects retirees in Tennessee and Florida, college students in Mississippi and New York, small business owners in the Midwest, veterans, teachers, and who do nothing wrong other than answer a phone call, open an email, or respond to what appeared to be a trusted message What they encounter on the other end is not a legitimate contact.
▶ 0:23:27It is an organized criminal operation often run from a fortified compound halfway around the world, designed from the ground up to steal their money, their personal information, and in many cases, their sense of safety and dignity. I want to be clear about what we're dealing with.
▶ 0:23:44What is happening to Americans right now is an industrial scale criminal campaign coordinated by transnational criminal organizations that operate sophisticated fraud networks spanning multiple continents and targeting millions of victims These operations combine cyber fraud, money laundering, cryptocurrency manipulation, digital extortion, and in many and in and in many documented cases, human trafficking and forced The numbers released just weeks ago by the
▶ 0:24:14FBI confirm how rapidly this threat is accelerating. The FBI's Internet Crime Complaint Center received more than 1 million complaints in 2025, the first time that threshold has ever been crossed. Reported losses surpassed $20 billion for the first time, representing a 26% increase over the prior year. Americans over the age of 60 reported losing nearly $8 billion, a 59% increase in a single year.
▶ 0:24:41And for the first time, the FBI dedicated an entire section of its annual report to the role of artificial intelligence and in and in enabling the crimes these crimes, documenting more than 22,000 complaints with AI-related components. Behind these numbers are real people whose lives have been upended.
▶ 0:25:00Seniors who lost their retirement savings to a voice-cloned phone call from someone they believed was a grandchild in Young people targeted by sextortion scheme designed to exploit fear and shame. Small investors lured into fraudulent cryptocurrency platforms through deepfake videos of trusted public figures. Business owners locked out of their own systems by ransomware and forced to choose between paying a ransom to criminals or watching years of work disappear.
▶ 0:25:27These networks are deeply connected to organized organized transnational syndicates, many run by organized crime groups with roots in the People's Republic of China and the Russian Hundreds of thousands of people have been trafficked into scam compounds across Southeast Asia for so carry out fraud under the threat of violence and Chinese nationals and PRC-linked triads operate the largest compounds and Beijing has been slow to act against the networks that victimize Americans while generating billions along China's
▶ 0:25:59Artificial intelligence is making all of this worse. Criminal organizations are using AI to clone voices, produce deepfake videos, and automate the targeting of millions of victims simultaneously. And ransomware groups are integrating AI into their attack chains to launch attacks faster than defenses can respond. This administration recognized the severity of the threat and I want to commend President Trump for taking decisive action.
▶ 0:26:23On March 6th, the president signed an executive order on combating cybercrime, fraud, and predatory schemes against American citizens. That order directs the home Department of Homeland Security and other federal agencies to conduct a comprehensive review of existing operational and regulatory tools and to develop a coordinated action plan to identify, disrupt, and dismantle the transnational criminal organizations behind these schemes. That is exactly the kind of whole-of-government approach that this moment demands.
▶ 0:26:52The American people deserve a government that fights for them with the same intensity that these criminal networks use against them. Our witnesses today will help us understand the full scope of this threat and the tools we need to combat it. I look forward to your testimony. Thank you for being here. I yield back. Thank you, Chairman Ogles. I would like other members of the committee to be reminded that opening statements may be submitted for the I would now like to formally introduce our panel of witnesses. First, Ms.
▶ 0:27:22Cynthia Kaiser is the senior vice president at Halcom Ransomware Research Center. She previously served as deputy assistant director of the FBI's Cyber Division, where she led policy, intelligence, and partnerships to support victims and disrupt cyber and Excuse me, to disrupt cyber adversaries. Second is Mr. Ari Redboard. He is the global head of policy at TRM Labs.
▶ 0:27:53Prior to joining TRM Labs, he was senior advisor to the deputy secretary and the under secretary for terrorism and financial intelligence at the United States Treasury, where he used sanctions and other regulatory tools to effectively safeguard the financial systems from illicit use by terrorist Third is Mr. Josh Berkus.
▶ 0:28:16He is the senior vice president of policy at US Telecom, the broadband association, and also serves as the executive director at Industry Traceback Group, where he works closely with government agencies to identify and mitigate scams and fraudulent calls. And finally is Ms. Megan Stifel. She is the chief strategy officer at the Institute for Security and Technology.
▶ 0:28:43She previously held roles in both the private and public sector, including with the Department of Justice, where she served on details as a policy director for international cyber policy in the National Security Council at the White Again, ladies and gentlemen, thank you so much for being with us today. We look forward to hearing your testimony, to having you brief us so that we can craft policy to better protect our fellow American citizens.
▶ 0:29:12I would ask at this time all of our witnesses if they would please rise to allow me to administer the oath before testimony. If all of our witnesses would please raise their right And if you would please repeat after me. Do you solemnly swear that the oath testimony you will be given before the Committee on Homeland Security of the United States House of Representatives will be the truth, the whole truth, and nothing but the truth, so help you God?
▶ 0:29:40Let the record reflect that our witnesses have answered affirmatively. Thank you, and please be seated. I would now like to give each of our witnesses an opportunity to make an opening statement. I recognize Ms. Kaiser for 5 minutes to summarize her opening Thank you, chairmans, ranking members, and members of the subcommittees. Thank you for the opportunity to appear before you today. My name Cynthia Kaiser.
▶ 0:30:09I currently lead the ransomware research center at Halcyon, a cybersecurity company whose mission is to defeat ransomware. Before that, I spent two decades at the FBI, and I've given my career to understanding the criminal networks that we're discussing today. And I'm here to tell you that what they're doing demands a response that matches the gravity of their crimes. I want to begin with a statement that I believe this committee and every American should hold in mind throughout this hearing.
▶ 0:30:37The people committing these crimes are not merely technical actors engaged in financial misconduct. They are predators. They are callous, and they are, in many cases, knowingly endangering and ending human lives, and they do not care. As you noted, FBI released its 2025 Internet Crime Report earlier this year. The picture it paints should make every American genuinely, viscerally angry. Angry that cybercriminals are stealing a generation of wealth from our country.
▶ 0:31:08Angry that more than 75,000 victims of sexual extortion were caught in a cycle of abuse. And angry that during just one FBI operation, 38 victims were referred for suicide intervention. That's 38 people so devastated by cybercrime that agents feared the victims would take their own lives. Since 2023, ransomware attacks have risen over 20%, and they're getting faster. Attacks that used to take weeks now take hours.
▶ 0:31:38AI has made it easier for attackers to gain initial access to company networks, and our team's data show that ransomware gangs target small and medium-size businesses at nearly four times the rate of large Last year, healthcare overtook all other critical sectors to become the single most targeted industry for ransomware. Attacks against hospitals and medical facilities nearly doubled from 238 in 2024 to 460 in 2025.
▶ 0:32:08That is more than one ransomware attack on American hospital or health system every single day. Make no mistake, this was a business decision. Ransomware actors, who are criminal entrepreneurs as much as they are hackers, have calculated that when lives are on the line, hospitals are more likely to pay.
▶ 0:32:26They looked at cancer patients, dialysis patients, newborns and NICUs, and decided these patients were acceptable Research from the University of Minnesota documented at least 47 deaths attributable to hospital ransomware attacks between 2016 and 2021. That number is almost certainly in the hundreds today.
▶ 0:32:47Earlier this year, when Mississippi's only level one trauma center in the state was down for 9 days, we saw that when a hospital is taken offline, many patients are unable to access critical For a heart attack or stroke patient, even 1 hour's delay can mean death or permanent disability. The hackers responsible for these attacks know this. They have simply decided that these deaths are someone else's problem.
▶ 0:33:11Our grandparents, our small business owners, our doctors, none of them should live in fear about what someone might be doing on a keyboard thousands of miles I fully support the president's executive order on cybercrime and the new national cyber strategy, which are strong steps towards dismantling transnational criminal organizations. Building on these, the gap between the severity of these crimes and the consequences that follow needs to close. I urge the committee to champion three specific authorities to do it.
▶ 0:33:39First, the departments of state, justice, and treasury could formally evaluate whether terrorism designation authorities under existing law apply to ransomware actors who knowingly and repeatedly target hospitals. The statutory definitions of terrorism fit with these groups do. Designations would unlock sanctions, enhanced intelligence collection, travel restrictions, and real diplomatic consequences for nations harboring these criminals.
▶ 0:34:04Our team has already done a lot of work exploring what is legally possible and collaborating with industry partners, and we are happy to share. Second, the Department of Justice should evaluate homicide charges when ransomware attacks on healthcare facilities cause documented patient deaths. The executive order directs the attorney general to pursue the most serious provable offenses. Felony murder law does not require that a defendant pull a trigger, only that they commit a dangerous felony that results in death.
▶ 0:34:33Finally, fully fund and reauthorize the state and local cybersecurity grant Cutting this funding would be a gift to ransomware criminals. I've spent my career working alongside extraordinary experts in cyberdefense, in government, and now at Halcyon. All of us are doing everything we can with the authorities we have, but the worst of the worst, those targeting our hospitals, those who have caused documented deaths, those operating under the protection of hostile foreign governments, need to face consequences that match what they have done.
▶ 0:35:04This requires novel implementations of the law and the resources and mandate to do These hackers are counting on incremental responses. Working together, let's prove them wrong. Thank you, and I look forward to your questions. Thank you, Ms. Kaiser, for your opening statement. I now recognize Mr.
▶ 0:35:21Redburn for 5 minutes to summarize his opening Chairs Guest and Ogles, ranking member and distinguished members of both Today, I'm going to talk to you about the greatest threat confronting American families today. My name is Ari Redboard.
▶ 0:35:40I'm honored to be to appear before you on behalf of TRM where we work every day with law enforcement, financial institutions, and national security agencies to detect, investigate, and prevent illicit activity in the digital asset ecosystem and beyond.
▶ 0:35:59Before joining TRM, I spent more than a decade as a federal prosecutor at the US Department of Justice, and later at the US Treas- and later as a US Treasury official, confronting terrorist financiers, sanctions evaders, narcotics and transnational criminal enterprises. I do not say this lightly.
▶ 0:36:21The industrialization of cyber-enabled fraud by transnational criminal organizations is the most pervasive, economically destructive, and dangerous financial crime threat that I've seen in my career. The consequences are immediate, and they are personal. A grandmother in Ohio sends her retirement savings to a scammer. A veteran in Texas transfers his home equity to a fake investment platform.
▶ 0:36:49A family in North Carolina watches their life savings vanish. This is economic violence at industrial We must respond with all our might, and we must do so together, because these are not abstract losses. They are the futures of Americans, and the networks taking them are organized, relentless, and scaling faster than our The numbers underscore the urgency.
▶ 0:37:20TRM's 2026 Crypto Crime Report documented 158 billion in illicit crypto flows in 2025. That's a 145% increase over 2024. Fraud and scams alone drove 35 billion. And with only about 15% of victims reporting, true global losses exceed 200 billion dollars.
▶ 0:37:43These flows run through one interconnected Pig-butchering compounds in Southeast many staffed by trafficked workers, generate fraud proceeds. Mexican cartels buy fentanyl precursors from Chinese suppliers with cryptocurrency.
▶ 0:38:03North Korea stole about 2 billion in cryptocurrency last year to fund weapons proliferation and destabilizing Every one of those streams moves through the same plumbing. Chinese underground banking networks that processed over 103 billion last year alone. And artificial intelligence is accelerating these schemes.
▶ 0:38:27Through Chainabuse, TRM's global scam reporting platform, we have documented a more than 500% increase in AI-enabled scam activity over the past year. The solution to the criminal abuse of AI is not to ban or stifle the technology. It is to use it, and use it wisely.
▶ 0:38:48At TRM, we are already building those Every innovation our adversaries turn against American families is one we can turn back against them, faster, smarter, and at greater scale. The threat is daunting, but it is also one we can solve, and solve together. We know what to do.
▶ 0:39:11The The White House executive order on combating cybercrime names this threat for what it is, a national security threat, and creates a whole-of-government The DOJ's Scam Center Strike Force has exemplified that approach in action. But we live in an age where the private sector holds the author- holds the data, and the public sector holds the Neither can confront this threat alone.
▶ 0:39:40That is exactly what TRM's Beacon Network was built to bridge. Beacon is the largest public-private network for the interdiction of illicit proceeds and the seizure of stolen funds in the digital asset ecosystem, connecting every major cryptocurrency exchange with 70 law enforcement agencies across the US and allied When a victim reports a scam, Beacon can move actionable intelligence in real time to the exchanges
▶ 0:40:10and agents who are in who can interdict and seize back those funds. That is the type of real-time public-private coordination the executive order envisions, already operating and ready to scale.
▶ 0:40:26Congress can codify that framework, pass a digital assets hold law so exchanges can freeze illicit funds, empower the private sector through cyber letters of marque or white hat hat white hat hacking to disrupt criminal create a victim compensation fund, give federal, state, and local law enforcement the tools and training to fight back.
▶ 0:40:50We can protect American citizens by leveraging transformative technology for and we must do it together. The tools exist, the networks like Beacon prove what is possible when the public and private sectors move as one. Thank you, and I look forward to your questions. Thank you, Mr. Redburn, and I'll recognize Mr. Burkey for 5 minutes to summarize his opening statement.
▶ 0:41:14Chairman Guest, Ranking Member Correa, Chairman Ogles, and members of the subcommittees, thank you for the opportunity to testify today today and for your leadership on this critical issue. I'm Josh Burkey, Executive Director of the Industry Traceback Group and a Senior VP at US Telecom. US Telecom leads the Traceback Group, which is designated by the FCC as the consortium for tracing illegal calls.
▶ 0:41:38I also served on the FTC's Scams Against Older Adults Advisory Group and on Aspen's National Task Force for fraud and scam prevention. The telecom industry has been making to protect American consumers from illegal calls. We've deployed tools like call blocking, call authentication, and industry-led traceback, complemented by aggressive enforcement by our government partners. It used to take law enforcement months to determine who made an illegal call.
▶ 0:42:06Now with traceback, we often find those criminals within hours. We work closely with federal and state law enforcement, routinely tracing calls referred to us, including scams impersonating the Department of Homeland Security, and providing actionable information to support enforcement. We know this works. Raids of illegal call calling operations in India led to an 85% drop in IRS robo I IRS scam robo calls.
▶ 0:42:32FCC and state attorneys general action virtually eliminated an illegal auto warranty campaign. Today, scam robo call volume is 50% lower than its peak. The Traceback Group has worked with banks, tech companies, and others to identify the criminals behind these calls and support law enforcement action, including recent information sharing supporting HSI takedowns. Fraudsters have evolved from high volume to higher impact.
▶ 0:42:59The most sophisticated operations, as my colleagues have already discussed, are run by organized transnational criminal networks. A decade ago, the dominant illegal calling threat was concentrated in South Asia, especially India. Today, the most consequential development is the rise of scam compounds in Southeast Asia. Mexican drug cartels have built their own illegal calling operations targeting Americans as well.
▶ 0:43:25We now face a global fraud-as-a-service marketplace where tools, tactics, and infrastructure are rapidly shared and The methods used to bring these schemes onto US networks are evolving as well. We trace calls back to entities posing as US-based providers, sometimes through shell companies, sometimes impersonating US legitimate companies. We see growing instances of calling platforms compromised and used to to used to deliver scam calls.
▶ 0:43:54SIM boxes are used to generate calls from within the United States, even if the callers themselves are located To put it simply, criminals have adapted to traceback enforcement by hijacking or deploying domestic infrastructure. These trends underscore the limits of what industry can do on its own. We cannot make arrests or prosecute the criminals even when we identify them. When I testified before Congress last year, I outlined areas where federal action can make a difference.
▶ 0:44:24The administration's March 2026 2026 executive order is an important step. It reflects the whole-of-government approach that this problem demands and treats scams as what they are, crimes. Now the focus must be implementation. There are three areas where Congress can First, reinforce the EO and its enforcement mandate by providing resources to support investigative capacity, prosecution, and cross-border coordination.
▶ 0:44:52Prosecutors and investigators must be able to move with urgency and work with willing partners abroad. Our industry, including the Traceback Group, stands ready in Second, provide a safe harbor for information sharing for improved fraud prevention and detection. Emerging partnerships show real promise in identifying and disrupting scams. A safe harbor could unlock even deeper Third, support and scale what works, including proven tools like traceback.
▶ 0:45:21Fraud continues to take a toll on American consumers. We are committed to being a constructive partner in this fight. Thank you, and I look forward to your questions. Uh thank you, Mr. Burkey, for your opening statement. I would now like to recognize Ms. Stifle for 5 minutes to summarize her opening Chairman Guest, Chairman Ogles, Ranking Member Correa, thank you for the opportunity to testify today.
▶ 0:45:50I'm Megan Stifle, the Chief Strategy Officer at the Institute for Security and We are a 501c3 nonprofit critical action think tank focused on the implications of technology for our national security. In our work on cybersecurity, we address misaligned incentives in the technology ecosystem that leave our critical infrastructure vulnerable. At IST, I also serve as the Executive Director of the Ransomware Task Force. I'd like for you to think back to the spring of 2021.
▶ 0:46:18Five years ago next week, the Ransomware Task Force released its report with 48 recommendations for a comprehensive anti-ransomware campaign. Two weeks later, the Colonial Pipeline was shut down by Russian ransomware gang, endangering 40% of the gasoline supply east of the Mississippi. Government agencies were forced to warn Americans not to put gas in plastic bags as gas lines in some states brought back memories of the 1970s.
▶ 0:46:46Since Colonial, we've seen attacks on the meat processor JBS, the LA Unified School District, CommonSpirit hospitals, Change Healthcare, CDK Global, and more. Ransomware rose to the level of an urgent national security threat that demanded our attention. Today, I'm pleased to report that we are making some progress in the fight against cybercrime. The national security threat posed by ransomware has decreased, thanks in part to the work of this committee. But we cannot rest on our laurels. Criminals are constantly evolving, and so must we.
▶ 0:47:17Cyber fraud, from extortion-based intrusions to business email compromise, continues to cost our economy billions each year with significant impacts on small businesses. Nation-state adversaries are leveraging the cybercrime ecosystem to target our critical infrastructure, and rapid advancements in artificial intelligence-enabled cyber tools threaten to erode many of the gains we've made in cybersecurity in the last few years. Recent Recent actions by the administration have emphasized the importance of countering cybercrime.
▶ 0:47:46However, challenges with cuts to the federal workforce and funding, as well as organizational upheaval, all threaten to stall this progress. In addition, the administration's strategic approach risks leaning too heavily on disruption at the expense of shoring up our defenses at home. In fact, for the first time, we've seen material steps backwards when it comes to implementing recommendations from the Ransomware Task Force.
▶ 0:48:08This committee in particular should continue its bipartisan oversight of the administration to ensure that CISA is able to carry out its mission in the face of significant cuts to its Beyond the immediate changes needed, we must also look to the future. We will never achieve our strategic strategic goals in cyberspace without moving upstream to make systems-level changes.
▶ 0:48:28This requires a firm foundation for the efforts for efforts like the Common Vulnerabilities and Exposures, or CVE, which helps the entire ecosystem understand and defend against cyber and which is under coming under increasing pressure from AI-discovered It demands more accountability for services like residential proxy networks that are regularly abused by criminals and nation-state adversaries.
▶ 0:48:52And it requires strengthening relationships among government agencies and between government and industry so they are built on trust and emerge from truly collaborative Without these system-level changes, we will remain vulnerable. I have several recommendations for the committee.
▶ 0:49:09First, the committee should pass legislation authorizing key programs, including the CVE program and the Critical Infrastructure Partnership Advisory Council, to ensure they are not Second, members of the committee should work with your counterparts to pass long-term or permanent extensions of cybersecurity authorities, including the Cybersecurity Information Sharing Act of 2015 and the State and Local Cybersecurity Improvement Act of Third, the committee should also strengthen the ability of the private sector and government actors to work to disrupt cyber threats by authorizing the Joint Cyber Defense
▶ 0:49:39Collaborative or JCDC and clarifying lawful lawful defensive measures that private sector actors can take when countering ransomware or other cyber crime. And finally, I hope this committee will continue to conduct oversight and effective hearings covering topics such as residential proxy networks, the Cyber Response and Recovery Fund, the rise of product security regimes, measures to disincentivize extortion payments, and the effect of AI on vulnerability As leaders on inside sorry excuse me as leaders in cybersecurity in the house,
▶ 0:50:09I also hope you will work closely with other committees on cross-jurisdictional issues including CISA funding, cyber insurance, expanding the E-Rate program to include cybersecurity, and additional oversight of the SolarWinds incident carried out by the People's Republic of China which target the telecom networks that form the backbone of our everyday 2026 is a decisive moment. We can see the potential opportunities and dangers from AI on the horizon, but there is still time to act.
▶ 0:50:40As Americans, what we need more than anything today is leadership. When we move decisively, we can seize the initiative from adversaries and materially change the cyber crime landscape. I hope today's hearing is an opportunity to jump-start a new wave of bipartisan, effective, and transformative cybersecurity policy. Thank you for the opportunity to testify and I look forward to your questions. Uh thank you, Ms. Kaiser. Members will now be recognized by order of seniority for their 5 minutes of questioning.
▶ 0:51:08I now recognize myself for questioning. Ms. Kaiser, um in your opening statement um you mentioned that uh healthcare facilities uh have become the single most targeted uh within the group. Uh I think you the number that I recall you said that in 2025 there were 460 attacks uh doubled from the previous year.
▶ 0:51:35Uh and you mentioned in your written opening statement uh and you touched a little bit uh briefly in your oral opening statement uh about attack in my home state of Mississippi. Um and um just for the benefit of the other members of this committee, want to read a little bit about what's contained there in your opening statement uh about that attack.
▶ 0:51:56Uh you say on February 19th, 2026, when ransomware actors struck the University of Mississippi Medical Center, also known as UMMC, uh that it was not simply a large hospital, but it was the medical backbone of the entire state.
▶ 0:52:12It is Mississippi's only academic medical center operating seven hospitals, 35 clinics statewide, and home of the state's only level one trauma center, the state's only children's hospital, and the only organ and bone marrow transplant program.
▶ 0:52:28When attackers took down UMMC's network knocking Epic, its electronic healthcare record system, fully offline and forcing clinical staff to revert to pen and paper, they did not merely disrupt a business, they degraded the emergency medical capacity of an entire Clinics closed across Mississippi. Outpatient surgeries and cancer treatment appointments were canceled.
▶ 0:52:56For 9 days, the state's only facility equipped to handle the most severe trauma cases operated under manual downtime procedures with staff tracking patients' medication and orders on paper. You then go on to say the hackers behind the UMMC attack knew exactly what they were targeting. They contacted the hospital afterwards with demands.
▶ 0:53:20They understood that they had taken down a system that Mississippi patients depended on for survival and they used that leverage Ms. Kaiser, I will tell you that I believe that there are no penalties too for individuals who would target our healthcare system. Uh you in your uh report, you and also touched on this in your uh opening statement, uh you talk about a couple of different things.
▶ 0:53:50You talk about using terrorist designations for those individuals who would attack hospitals. Uh you talk about individuals being charged with murder or manslaughter if those attacks led to the death of individuals. And I think you did say in your opening statement that there had been a number of deaths, uh 47 that had been documented uh with old uh information. We believe now that number to be in the hundreds.
▶ 0:54:16And so uh as it relates to the terrorist designation under 18 USC 2331 and under 8 USC 1182, uh do you believe that the Department of Justice currently has the authority to charge under those sections, or do you believe that Congress needs to uh specifically give the Department of Justice that authority?
▶ 0:54:45So the law defines terrorism as acts dangerous to human life intended to coerce a civilian population. I think that encrypting a hospital systems and demanding ransoms while patients are being diverted meets that definition, but I'm not asking for a designation today. What I'm saying is that we need honest legal analysis towards that looking at the existing law and determining if departments believe it meets those thresholds.
▶ 0:55:15Uh I mean those designations aren't a blunt instrument. They're a scalpel. There's a deliberate process behind that um where they only designate the worst of the worst. But I agree completely with you and I want to emphasize what you said. There's no penalty too strong for the individuals that are holding Americans at lives at risk. They're making calculated decisions to target these individuals.
▶ 0:55:41And that's why Halcyon is actually funding an update to that research I noted uh to see exactly how we quantify the risk today. And are you aware of an example where the Department of Justice has ever used these code sections to seek criminal uh under the definition of terrorist for an attack on healthcare system?
▶ 0:56:02I'm not aware of any, but with the new executive order, I think that opens a broader spectrum for the Attorney General to look at the most serious provable offenses and determine what weight they can bring to bear.
▶ 0:56:16And one last question as it relates to murder and manslaughter as far as uh federal felony murder charges, um kind of the same question, do you believe that Congress needs to give the Department of Justice additional authorities to charge under that section, uh or do you believe that they have the current authorities now and would just need to make that on a case-by-case basis? Clarifying guidance would be helpful, but they likely have the authorities today under the current statutes.
▶ 0:56:47Uh thank you. Uh at this time I yield back and I recognize Mr. Correa for his 5 minutes of questioning. Thank you, Chairman. Ms. Kaiser, I'm going to follow up on that line of discussion. Do we need clarifying language to redefine or expand the intent of the law to go after some of these individuals?
▶ 0:57:07Sounds like the language is there, it just has not been applied in these We've conducted legal analysis and have determined on our end that the language exists as it is now to be able to pursue this, but the process in by which they conduct those types of activities is uh is something that needs to be arbitrated across all of the departments. I'll emphasize one specific aspect there.
▶ 0:57:35It can be very difficult to prove an exact death at a hospital or medical facility in the middle of an attack. So we can look at Medicare data, Medicaid data, and say there's an excess number of deaths when there's a ransomware attack, but proving that one specific death is harder when you're going to paper and pen, when you're don't have electronic records, when you're looking at when you're in the middle of a crisis.
▶ 0:58:01So the way in which a prosecutor needs to Is this a candidate felony murder rule? Yes. And trying to think along those lines. Exactly. Thank you. Very quickly to each and every one of you, is the federal government doing enough in its role, a leading role in this area, Ms. Kaiser? I worked these issues for years at FBI and I
▶ 0:58:29need to step up even more? I They need additional authorities and resources to be able to
▶ 0:58:34answer is we need to do more. Mr. We need more resources, we need newer tools, we need more training across the
▶ 0:58:44Uh we continue to work well with the federal government, but um more is something that we think continues to need need more resources and
▶ 0:58:51Ms. Stiefel. Uh acting director of CISA has identified the need to rehire 300 individuals. So I would say yes, we definitely need additional
▶ 0:59:01300 were laid off through there have been significant decreases in in staffing across the federal government, particularly in the cybersecurity space, and we understand that about a third of CISA's workforce has left the agency. Quick question to each one of you. Ms. Kaiser, what keeps you up at night?
▶ 0:59:24That Americans may not understand how much at risk and how many lives at risk these criminal groups are holding them at every Mr. Redbord. that AI is supercharging the operations of our adversaries, and we need to make sure that we're scaling at the same
▶ 0:59:42Mr. Berkowitz. You know, the the daunting amount of work that we all need to put up our sleeves and do together and So, we're not there yet or from it. We're we're working on it, but yeah.
▶ 0:59:52Ms. Stiefo. The scope and scale of vulnerabilities across our critical infrastructure, in particular thinking also about our state and local entities that have recently had resources removed from their ability to upshore up their defenses against cyber attacks. is easy to do up here. I think at the end of the day, we just got to step up and say the buck stops here. What is it, Ms. Keiser?
▶ 1:00:19What are your recommendations that we in Congress can do to start fixing these challenges? Championing the policies that I noted within my opening statement, the terrorism designations, examining that, examining the felony murder laws, but also ensuring that we are funding the state and local governments that are constantly under attack by these actors. State the locals as well. Mr. Redbord.
▶ 1:00:48Empowering the private sector, the government has the authorities, the private sector has the data. The private sector needs the authorities as well to get go after them.
▶ 1:00:58Strengthen the weakest link in the Mr. Berkowitz. Um you know, I agree with my my colleagues. There's a lot of work being done in the private sector. There's a lot of innovation investment, and we need to keep pushing forward with that in in partnership with the government. Ms. Stiefo. I would say looking to pass long-term or permanent extensions of cybersecurity authorities, including the Cybersecurity Information Sharing Act of 2015 and the State and Local Cybersecurity Improvement Act of 2021.
▶ 1:01:26With last 28 seconds that I have, I would have an ask for you. 5 minutes is very short for us to get to specifics, but I would ask each and every one of you to give me in writing later on your five top recommendations of what we here in Congress can do to move forward on these issues. Not only protecting the future Colonial pipelines, but protecting Main Street.
▶ 1:01:51Those are the folks that just have nowhere to turn other than really to suffer in silence. Thank you very much, Mr. Chairman. I Gentleman yields. The chair now recognizes Chairman Ogles for his Thank you, Mr. Chairman. Um and thank you to the witnesses for being here. I mean, obviously we're in a a new era, a new day when it comes to cyber and cyberattacks, etc.
▶ 1:02:20primarily driven by AI, and that's where I guess I want to start is when you look at AI and the tools that are being deployed and and how quickly AI is advancing, what can these criminal networks do today that they couldn't do just months ago? Ms. Keiser. So, we see predominantly adversaries using AI to gain that initial step into from company networks.
▶ 1:02:48What I mean by that, it's easier to lie with AI. It's easier to make convincing emails with malicious links. It's easier to make these deep fakes, these fake videos or fake voice calls that trick companies into letting them on the network, and then it's easier to exploit vulnerabilities or find vulnerabilities that let them on. That being said, what we see today is the most benefit to is going towards the wannabe cyber actors.
▶ 1:03:17Advanced adversaries are integrating AI. They're looking at it in a way in which businesses are today for efficiencies, but there's a world of people who couldn't do attacks yesterday. They can today. And even if they're noisy, even if they're not all that effective, going from 0% to 5% is a big win for them.
▶ 1:03:37And what we're going to do is exhaust security teams and cause massive problems in how they develop these tools, how they develop their attacks, where it may render certain types of data or certain companies just unavailable for recovery. Mr. Redbord. There are two really important pieces to this. This first, our adversaries are using it at scale. I mentioned a 500% increase in AI-enabled fraud and scams.
▶ 1:04:04We see ransomware actors using agents as affiliates really for the for the first time. We're seeing North Korea use it to launder the proceeds of billion-dollar crypto hacks. But the other part that sort of I'm most focused on at TRM, we're working with the Department of Justice, with the Treasury Department, with the FBI, IRS-CI, DEA, Secret Service to provide AI-enabled tools that allow us to move as fast. For me, that that's the answer here, right? Bad actors are always early adopters of transformative technology.
▶ 1:04:35Think automobiles, end-to-end encrypted messaging apps, crypto, and now AI. We need to move as fast as those bad actors, and the tools exist today. Mr. Berkowitz. Yeah, and you know, I'd echo a lot of the comments of my colleagues that they it really enables improvement of the quality of the scam and and really helps that. It it makes you know, more people are able to do the scams that now that the equipment, but it also increases the scale in what we see in the calling side.
▶ 1:05:04That said, you our our folks are using AI. They're they've long used machine learning, automation, and so there's some things like it's easier in the calling networks to detect someone making millions of calls versus someone making five really bad ones. So, some of our tools actually still work well in an AI world, but we're continuing to evolve as well. Ms. AI is making it harder for victims to say no to making a payment.
▶ 1:05:31And one of the reasons for this is the shift that we've seen in the ransomware ecosystem, whereas previously ransomware actors encrypted data, meaning that they locked it up, they now take the data and use it to extort victims to force them to make a payment.
▶ 1:05:45So, when they've copied records, whether it be from a hospital, intellectual property from a Fortune 500 someone's private images as the ranking member described, they're now using AI to analyze that data to be able better able to They in fact in many cases know the victims' financial, for example, their financial capacity more than the victims do.
▶ 1:06:08And they're using that analysis capability essentially have a response to every blockade that the victim tries to assert, making it harder for the victims to not make the payment and disclosing this information, eventually jeopardizing both the long-term stability of that organization, but also putting our ability as leaders in the global economy and innovators at risk. Thank you, ma'am. Ms.
▶ 1:06:32Keiser, you know, 5 years ago the Department of Justice made the decision to elevate ransomware investigations to the same priority level as terrorism cases. As we go forward, should it be not just a priority, but actually classified as a terrorist attack when you're targeting critical infrastructure? There are substantial benefits to what you're talking about. I mean, a designation doesn't just freeze assets. It changes the entire geopolitical equation.
▶ 1:07:02In particular, imagine telling a foreign government, you've been you have a designated terrorist living in your country. That changes safe haven conversations with these countries that are harboring all of these criminal your I think this will really have an effect, especially among the 60 nations whom we share a membership with the International Counter Ransomware Initiatives, saying nation-states that tolerate ransomware criminals, and they need
▶ 1:07:32to feel that pressure. And then real quickly, um you know, obviously this is a a problem at scale. I mean, when you I prior to my current role, I was CEO of the county, the county executive. We had a regional hospital in my you know, in my county. Incredibly vulnerable vulnerable, right? So, what what is more practical uh making that type of designation and cutting the head off of the snake, so to speak, or trying to equip municipalities across the country?
▶ 1:08:03Either is difficult, but we've got to figure this out as we go forward because again, it's becoming more aggressive. Really quickly, and I'll yield back, Mr. Chairman. I I don't think I can choose. I think you have to have defense and offense to be able to block these attacks at their source.
▶ 1:08:17One note I'd make is that when we're equipping municipalities, when we're providing out those funds, we do need to make sure that we're equipping them with the knowledge as well of how to spend that money, how to arbitrate between the various aspects, and ensuring to your earlier question on AI, we're looking not just at prevention, which is going to be really difficult in the age of AI, but like how do you detect it quickly? How do you kick them off your network? How do you really make sure you're resilient? Thank you. I yield back, Mr. Chairman. Gentleman yields back.
▶ 1:08:46The chairman recognizes the gentleman from Rhode Island, Mr. Magaziner, for his Thank you, Mr. Chairman, and to my colleagues and to our expert witnesses Um cyber scams are a tremendous and growing challenge. We see that in my home state of Rhode Island.
▶ 1:09:04We know that critical infrastructure is being targeted, water systems, power systems, hospital systems, businesses, I think the most tragic stories are when seniors are scammed, scammed out of their life savings that they worked their whole lives for, and in some cases reduced to poverty as a result. So, So is something that should be a priority of this Congress and I I thank my colleagues for for convening this hearing.
▶ 1:09:32Uh few issues that I wanted to call attention to and ask our witnesses about. Um Mr. uh uh Bersu, um in your written testimony you talked about uh SIM farms or SIM uh I I I forget what you call it, the phrase you used, but SIM boxes. I think this is very important and we had a few of us had a classified briefing on the topic not long ago. Could you just explain to all of us once again what these are and why they're so Yeah, absolutely.
▶ 1:10:01So it's uh where the the criminal actors will get prepaid um phones, prepaid SIM cards, they can plug it into technology and then they are able to generate from the US on our on our networks calls that really when the caller may sit or you know, text messages alike may sit abroad. So it really is an enabler. It's not calls coming in through the through foreign gateways, they're actually starting in the US.
▶ 1:10:27And and crucially some of these SIM boxes or SIM farms, you know, can generate thousands of calls, right? Thousands of calls essentially anonymously that that can be used, you know, with real phone numbers um to fraudulently scam people. Is that right?
▶ 1:10:43Yes, one of the challenges is it doesn't look like an individual who's making, you know, hundreds of thousands of calls cuz it's individual numbers, individual SIMs making a handful of calls, but it is something the industry's been working on how to better identify it with traffic analy- analytics.
▶ 1:10:58That's what I wanted to ask about. I mean, to any of our witnesses, do you feel that the telecommunications industry is doing enough to identify where these SIM farms are located? Because as I understand it, if thousands and thousands of calls a day are being made from the same building, the same geography, that ought to be something that the companies themselves could could track and potentially flag for the authorities. Is that not right? So it's something the industry has been working on.
▶ 1:11:26There's uh you know, it's a complex ecosystem. It's not just customers of the large carriers, it's sometimes they're resellers. Um but it is something that we've been working. We've had a working group with uh the major carriers that we've been tracing back calls that we identify SIM farms, sharing information, and figuring out how to uh do filtering and other things to take them down quicker. Would anybody else like to weigh in on this? Is there more that the industry could be doing or that we could help the industry do to locate these uh these SIM farms? All right.
▶ 1:11:56Let me ask a related question then. My understanding is that one of the things that these fraudulent numbers are used for is to open fake social media accounts, right? You can use a fake phone number from a SIM card to open a Facebook account or a an X account or whatever. once it has been identified that an account has been opened with a fraudulent number, why would a social media company keep those accounts active?
▶ 1:12:19Am I correct that the big social media companies are still keeping accounts active that they know were created with a fake phone number? That's my understanding. And so, you know, I think we have to have a conversation with our industry partners, not just in the telecommunications industry, about locating these SIM farms, but also with the email companies, the social media companies.
▶ 1:12:42If there is an account, and I and I think there's millions of them that we know were opened fraudulently with fraudulent phone numbers, why are you keeping those accounts active? They're clearly being used for fraud. Um I just want to ask, I only have a moment left, so I just want to ask all of our uh the CISA workforce has been absolutely decimated over the last year. I think close to half of the CISA employees uh have been eliminated. Does anybody think this is a good idea from a cybersecurity point of view?
▶ 1:13:13Second, uh the administration has approved the sale of advanced uh Nvidia chips to China to the Chinese Communist government that is in many cases a sponsor of cyberattacks against the United States. Does anybody think allowing the sale of these advanced chips is a good idea? Well, that's something that I think we ought to do something about as a Congress on a bipartisan basis and with that, I'll yield.
▶ 1:13:44Gentleman yields. The chair now recognizes the gentleman from Arizona, Mr. Crane for his questioning. Thank you, Mr. Chairman. I want to say thank you to you guys for showing up today to help us get a better handle on this issue on online scams, crypto fraud, and digital extort- extortion.
▶ 1:14:05I actually had a uh constituent reach out to me probably about 6 months ago who had saw an ad on Fox News and uh it was for a farming equipment, tractors, etc., used equipment. He actually ended up making up the purchase and never received the product. Um so he reached out to me. We were able to get in touch with uh the, you know, federal agencies who looked into it.
▶ 1:14:35Thankfully, the bank worked with this gentleman and helped him get his money back, but then he continued to text me letting me know that he he was still seeing this ad run on Fox News. So a lot of our constituents see something on Fox News or CNN or whatever channel they're watching and they see um having some integrity to it. Um we really haven't covered that I've heard in this hearing. What would you guys advise average Joe American to do?
▶ 1:15:05What, you know, operating procedures would you have them look at in avoiding even getting involved in any of these scams? I'm going to start with you, Ms. Keiser. So when I was at the FBI, one of the teams that I had responsibility for was the Internet Crime Complaint Center, so the group that does the report we talked about today. Uh the question I got a lot is like, why why do you put out these stats? Like what do you hope to get out of this? And my number one answer was so that people don't feel alone, right?
▶ 1:15:34That individuals understand that this happens to a large swath of American citizens and that if they should believe if they believe they have been scammed, if they believe they've been attacked, they should report it to local law enforcement, to the FBI, to the Internet Crime Complaint Center. They should contact their bank right away because often times, and I'll defer to my colleague on some of these money flows, but often times some of that money can be recouped if it's done quickly.
▶ 1:16:03But but before we even get to that point, Ms. Keiser, where they're attacked, how do they avoid getting attacked in the first place? Does, you know, how do they notice or have their spidey senses go off that, hey, this doesn't exactly feel right? Does anyone want to help the average Joe with that one? So it's incredibly difficult, but what I would note is that if you feel under like urgent pressure, it's probably a scam.
▶ 1:16:29Take a beat, take a step, call someone in your family, contact and identify ways in which you can verify that company, but it's really when you're put under pressure, often times that's the biggest indicator that something's wrong. Go ahead, Mr. I I would just add I think that was that was quite frankly beautifully said. I think what we need is a massive public service campaign at a federal level um across all these different jurisdictions. Uh a just say no, if you will, uh for scams and fraud.
▶ 1:17:00Uh we need people to understand that to take a beat as as Ms. Keiser said. Uh at TRM, we run the largest reporting database for fraud and scams in the crypto ecosystem. It's called chainabuse.com. You can go on your phone and look at it right now. It's just open source. It provides victims an opportunity to report so other people are not ultimately scammed down the road. So I think it's a combination of things.
▶ 1:17:21You're right that we talk a lot about offense and how to go after these transnational groups, but really defense is a key part of this and I think public service and awareness is absolutely critical here. Of all the ways that these scammers can target Americans, whether it's text message, social media, phone calls, emails, of all of those, are you seeing um these individuals target um you know, specifically or more predominantly through a certain means?
▶ 1:17:50You know, it it's through a whole host of different types of of ways. Um just to put a point on it, I think one more thing Ms. Keiser said is that uh the FBI has been terrific in this area. Uh it's not only through IC3, but they run a program called Level Up where they're literally doing hand-to-hand combat. They're going to reach out to victims directly, show up at your door, and say, "Hey, don't go ahead and send those funds." Obviously, it's very hard for this to scale, but you marry technology with that type of initiative uh and there's a there's a lot of good work being done out there.
▶ 1:18:20Absolutely. My office 2 weeks ago had FBI out at a Vance and Pace in Arizona and Over Guard to help residents um identify and look at some of the ways that they could possibly be scammed or defrauded. So I want to say thank you to the FBI for doing that. Um Mr. Mr. Bercow or Ms. Stifle, with my remaining time, do you guys have any suggestions for Americans on how to avoid even getting entangled in any of these fraudulent schemes?
▶ 1:18:50Yeah, I I I'd agree with my colleague, especially the the take a beat, but I think one is recognize that any of us could be a victim. I mean, I work on these issues and I was under the spell for a few seconds when I got a message that my account was accessed from Russia. So it can happen to any of us, so I think that's why the take a beat is real important, but take advantage of the tools that are out there. There's blocking, labeling, there's other things on the phone side, use those. Thank you. I yield back. Gentleman yields back. The chair now recognizes the gentlewoman from Illinois, Ms.
▶ 1:19:20Ramirez for her Thank you, Chair and Ranking Member for this hearing today and for the witnesses all for being here as well. Well, the substance of this hearing is certainly very serious. We're back to Republican hearings dripping in unseriousness. And I'll tell you why.
▶ 1:19:37It's laughable that my Republican colleagues are trying to use this time to condemn fraud, extortion, and crime while one supporting the most corrupt scammer administration in US history and two, being completely unwilling to conduct oversight or rein in the In preparing for today's hearing, it was noted profit-motivated transnational criminal organizations. They leverage corruption, intimidation, and advanced technologies so they can reach new markets and create income streams.
▶ 1:20:07Such organizations defraud US citizens, businesses, and government agencies while at the same time moving billions of dollars in illegal earnings through global financial systems. Does this sound familiar to anyone else?
▶ 1:20:22The House Judiciary Committee Democrats released a report last year that documented how the president has used his office to enrich himself and his family with crypto holdings worth as much as 11.6 billion dollars and income of more than 800 million from the sale of crypto assets in the first half of 2025 alone while at the same time dismantling federal oversight and safeguards that once protected Americans from fraud, from scams, and financial exploitation.
▶ 1:20:53Profit-motivated transnational crime, corruption, and scamming, that's how the Trump administration operates. He uses all those tools to reward his loyalists and then to be able to remain in power. Look, while I agree we have to combat corruption, crime, and scams, and it has to be important for us to understand the US economic and national security we also have to understand that combating these threats require adequately resourcing and staffing these federal agencies, staffing critical
▶ 1:21:23infrastructure, and having checks and balances, and policy solutions that make us all more secure. But my colleagues here are unwilling to do any of these things. How? They're decimating CISA.
▶ 1:21:37They're abdicating their oversight And they're wasting our time instead of advancing policies that protect working people from today's crooks and con men in office or from buying seats in Look, my district is so tired of corruption, of self-dealing, and lack of accountability. And so I I want to get to a quick question here. Ms. Steifel, it's my understanding that in March, the White House released President Trump's cybersecurity strategy for America.
▶ 1:22:04The document was just over three pages of substance around about things six In your professional opinion, is a six-page document with three pages of substance sufficient to describe a comprehensive strategy for American The most recently released strategy does stand in contrast to the 2018 strategy which laid out a number of
▶ 1:22:34key elements that would strengthen the country's cybersecurity posture including establishing cybersecurity and infrastructure security agency. Yeah. Thank you for your response. The reality is, I'll say it more directly, it is not because the 2018 strategy was a far more comprehensive than what we are seeing today and it should concern every single member of these And it's because Trump and his cronies around the world are the most dangerous transnational criminal networks threatening us right now.
▶ 1:23:04They're swindling us, stealing our hard-earned dollars, waging a war in our cities, and committing war crimes abroad all for private profit. It's not lost on me that Trump signed the legislation establishing CISA but started attacking it the minute it became an obstruction to his criminal interest. If you ask Republicans, do you want to use the power of government to end hunger? Nope. Make housing more affordable? Nah. Bring the prices of gas down? Nah.
▶ 1:23:32But if you ask them, do you want to use the power of government to get rich and trick, cheat, and defraud the American people? Well, what we've seen here is why the response is, yes, let's do that. That is despicable. That is not why we were sent to Congress and it's why we have to address the issues of cybersecurity, but we also have to address the issues of corruption in the White House. With that, Mr. Chairman, I yield back. Uh the gentlelady yields back.
▶ 1:23:59The chair now recognizes the gentleman from North Carolina, Mr. Budd, for his questioning. To the witnesses, thank you all for being here. I this is a an obviously a very important issue, one that's of of great significance to all Americans. And Ms. Kaiser, let me just start with you.
▶ 1:24:16We've talked a lot about, you know, government personnel and resources that are in place and so forth, but given the the dynamism of this threat, how important is it in not just a staffing component, but also a systems component to address this issue and is it even possible from a governmental standpoint
▶ 1:24:37In terms of systems, you're talking about the actual networks from a governmental system. Uh so, within uh the government itself, I was lucky enough to be able to be a part of the interagency weekly meetings that talked about, you know, threats to uh the US government networks as well as threats to across our critical infrastructure and what I can say is it's the same, right? The the types of thing the types of targeting that happens to the private sector happens to the government. The defenses are the same.
▶ 1:25:04It's ensuring that you've done basics, but now with AI, right? You have to do more and it's really in that kind of you have to assume you could be compromised, so what do you do then? How do you kick them
▶ 1:25:16terms of the threat itself, creating a defense for that threat is obviously going to require a whole lot of flexibility, a lot of creativity. Uh these are adjectives that are not usually reserved for the government side of things. And so I'm asking from your standpoint, how can the government evolve with the threat that seems to change day over day, night after night?
▶ 1:25:36So, one aspect is when the government is looking at reauthorizing and allocating the funds, the cybersecurity grants that Congress has authorized, it's doing so in a really smart way. Like identifying the actual needs of the in of the sector or government agencies that are receiving the funds. It's having a two-way conversation, not a one-way conversation, and it's moving fast.
▶ 1:26:03It's being able to allocate those funds because in cybersecurity, you know, time equals attacks. Yeah. Uh Mr. Rebbert, I'm I want the same the same chapter to you. I'm very skeptical of that when you look at the government bureaucracies, whether it's federal, state, or local, they're usually clumsy and very wasteful and that's not the nature of this threat. From your perspective, how can we best align to defend the American people against this type of threat? Thank you for the question.
▶ 1:26:29Um look, over the last, you know, couple of years, I think we've seen a real willingness from the public sector to be working much more closely with the private sector. And part of this is because we move very, very fast. Um and whether that means ensuring that the government has the data they need, we have it or we can go out and get it and we provide it. So, I think it's the real key here to solving this is working really, really closely together to ensure that uh the authorities and the data are all there to to take on this threat.
▶ 1:26:56In terms of the ingredients that are needed to match the threat, from your perspective, what what types of uh and progressions do we need to be sure that we're supporting in Congress? It's really that I mean you and I were both assisting US attorneys and I think it's really about the tools. It's that investigators have every single tool they need and when bad actors are leveraging technology, we need to make sure that every investigator has the AI technology, the blockchain intelligence, the things that they need to
▶ 1:27:24never going to happen from the government side organically. So, with the private sector side, how can we ensure that we have the necessary environment so that the private sector can develop the tools that will be used to protect Americans? Absolutely. In my opening statement, I mentioned the Beacon Network.
▶ 1:27:38It's the largest public-private partnership in this space and it's in large part because the private sector came together and said, "Hey, we need to stop bad actors in the wake of a North Korea hack from off-ramping funds to use for weapons proliferation." So, we all came together, reached out to the public sector, and said, "Let's do this together." I think that's a really sharp model for the what is possible today.
▶ 1:27:59And in terms of of the the posture of our country, it seems in many respects, I mean, we've mentioned China, Russia, North Korea, and certainly the Iranian folks, they're they're all attacking us. It seems to have exceeded law enforcement and moves into more of a national security component. How would how does that change the posture at all? I'll start with you, Ms. Kaiser. It's absolutely a national security issue. I think that countering cyber threats from wherever they come is one of the leading national security challenge of our lifetime.
▶ 1:28:27You mentioned the nation states and like one aspect I'd like to highlight here is nation states, so we've seen Iran, we've seen China, we've seen Russia, we've seen North Korea actually use these cyber criminal tactics, use the same infrastructure, use the same way in which the criminal groups are targeting us to actually conduct attacks on American networks. That's happened in the Iranian conflict right now.
▶ 1:28:52And so, it's really important to look at this all as a connected system and understand that disrupting one component disrupts It's the absolutely most important shift in the posture, you know, in in recent moving from law enforcement to national security. The reality is that wars are now fought in cyberspace and across blockchains and we have to leverage every national security piece that we can, offensive and defensive. Mr. Budd. You know, I I just agree with my colleagues here.
▶ 1:29:25I would just add that I think we also as we're thinking about CISA is for the for Congress to authorize the Joint Cyber Defense Collaborative, we as you have reiterated depend on industry to help strengthen and defend America and we at this point are not on our strongest footing with among other things also the lapse of the critical infrastructure partnership advisory panel capability for the Secretary of DHS and the Director of CISA to have honest conversations with industry about the range of threats that they're facing and
▶ 1:29:55the capabilities they can bring to defeat them. Right. Ms. Chairman, I'll back. Chairwoman Yells back. The Chair now recognizes the gentle lady from Texas, Ms. Johnson for her questioning. Thank you, Mr. Chairman. Thank you all for being here. I think this is a very critical and important in our nation at this time. We have all experienced an extreme increase in spam texts and calls ranging from toll road payments and UPS package fees to solicitations for crypto investments or or even romantic relationships.
▶ 1:30:25In 2024 alone, Texans reported losing 1.35 billion dollars to scams with the most significant losses reported to those over 60 years old. WFAA, a local news outlet in Dallas, reported that scam reports increased in 2025 by 118% doubling what was reported in 2024. These scams often target vulnerable communities and three in 10 Americans who lost money to scams say it has a significant impact on their finances.
▶ 1:30:55And in one case, a victim lost 47 million dollars causing an entire bank to collapse and hundreds of people to lose their retirement savings. The truth is these sinister operations by profit-motivated transnational criminal organizations are operating at a never-before-seen scale and our government is not equipped to address it right now. This is a self-inflicted wound thanks to the Trump administration's gutting of CISA whose mission includes identifying and preventing these crimes.
▶ 1:31:26And I want to echo many of the concerns my colleagues have made and many of you on the panel have made concerning the defunding of CISA and that we need to absolutely invest in a robust CISA if we're going to address this problem. Ms. Stiefel, my understanding is that these scams have accelerated in recent years to the proliferation of hundreds of large-scale compounds powered by forced labor across Southeast Asia, particularly in Burma, Cambodia, and Laos as well as the Philippines.
▶ 1:31:56In Cambodia, for example, corrupt officials allow scam centers to operate in the open in open where scamming now generates 12 billion dollars annually, over half of that country's GDP. Why is international collaboration so critical in addressing these scam centers and how have recent cuts and the reorganization of the State Department put those efforts of collaboration at
▶ 1:32:27We are as the ranking member mentioned in his opening statement, only as strong as our weakest link. And the examples that you gave are representative of issues that we see as we also explore ransomware including the willingness of safe havens to harbor criminals and not respond to requests for assistance or to deny bury their head in the sand.
▶ 1:32:48We depend on a whole of government, as my colleagues have mentioned, response to the threats that this country faces that are emanating through information and communications technologies or the internet. That means that we need to have not only a deep bench at CISA, but we also, as you mentioned, need to have a deep bench at State.
▶ 1:33:09among other things, the State Department is now our lead in something called the Counter Ransomware Initiative which is now in its fourth year with now over 70 countries and organizations participating in it. And it is the one place where these governments and multilateral organizations have come together to to identify a priority, exchange best practices, identify policy objectives, build investigative capacity to counter in this case, the ransomware threat.
▶ 1:33:39But that type of leadership that that emanated from the United States, the Counter Ransomware Initiative is something that the United States started and the State Department has taken on the responsibility to carry the mantle in this administration. We need to continue to show that leadership. And we have to do so with a full bench around the inner agency, both at State, FBI, CISA, elsewhere. Right. I'm very concerned about the diminished bench that we have at this time.
▶ 1:34:04And just just to the just general panel, what suggestions do you have for this committee to how we can improve collaboration between Department of Homeland Security and the State Department to address this issue in particular? Do you all have any specific recommendations other than what Ms. Stiefel was just talking about? I would just say over the last, you know, several months, year, we've seen more and more sort of inner agency approach to these issues.
▶ 1:34:33It's not going to just be the State Department. It's not going to be just DHS or law enforcement agencies or national security agencies. It's really all coming together. A couple great examples I think that exist today. The DOJ started a scam center strike force about six months ago. We There was a takedown of one of these large scam compounds in Cambodia called Prince Group that involved the largest forfeiture action in US history, about 15 billion of proceeds from this type of illicit activity.
▶ 1:35:02There's a model in but there's also 10 more, 15 more Prince Groups across Southeast Asia and we have to level leverage every authority from offensive cyber to public-private public-private work in order to go after these bad actors. Unfortunately, I'm out of time. But Mr. Chairman, thank you for this conversation. I do think responding to scams in this country is one of the most critical things we can be doing and I applaud the work. Thank you. Gentle lady Yells back.
▶ 1:35:30The Chair now recognizes the gentleman from Virginia, Mr. Wexton Shaw for his questioning. Thank you, Mr. Chairman and and thank you for holding this hearing on an important topic. We want the bureaucrats to be traumatically affected. When they wake up in the morning, we want them not to want to go to work because they're increasingly viewed as the villains. We want their funding to be shut down. We want to put them in trauma.
▶ 1:35:57That was Russ Vought, President Trump's OMB director, talking about, among the 1,000 federal workers who worked at CISA were fired, pushed out, or driven out. So while we have an executive order words on paper that says we take this issue seriously, we have a lot of language at the dais today about how important this is.
▶ 1:36:23This is not taking cybersecurity seriously because when you treat the experts who are doing the work and they are Let's talk about that. When you treat the experts that way, you're not taking the issue seriously. I want to just cite some of what you wrote in your written testimony, Ms. Stiefel. The Critical Infrastructure Partnership Advisory Council, a core mechanism for coordinating cyber policy across government industry, has yet to restart since being shuttered.
▶ 1:36:54The Secretary of Homeland Security if the Secretary of Homeland Security decides to convene sector-specific advisory committees, coordination will be a challenge given cuts. Budget cuts to the FBI's cyber division expected to reduce personnel by half. The acting commander of US Cyber Command testified that the effect on the command's ability to carry out its mission would be impactful because of budget cuts.
▶ 1:37:21We've talked about the state and local cybersecurity grant program which proved, quoting Ms. Stiefel, effective in marshaling resources to help state, local, tribal, and territorial governments improve their defenses, yet it has been zeroed out in the administration's budget.
▶ 1:37:36Shared cybersecurity services provided at subsidized rates for state and local governments, especially small rural state and local governments that don't have the resources through the Multi-State Information Sharing and Analysis Center have been canceled leaving states and local governments, especially in rural communities, to scramble for protection. That's what has happened. Ms.
▶ 1:38:05Stiefel, one that you didn't, I don't think, note in your written testimony, I apologize I missed some of what you said, is CISA's pre-ransomware notification initiative. Can you tell us what that is or perhaps what it was? Thank you. It's a really critical program that currently is not operating to my knowledge.
▶ 1:38:25The individual who ran the program is no longer at the agency and the program essentially received indications of warning from industry in many cases in parts supported by the Cybersecurity Information Sharing Act and the incentives that that legislation offers to industry, the liability protection it affords to share information with the government that the government can then leverage to defend the homeland.
▶ 1:38:48So this program run by actually basically one individual would call, receive these tips, and call victims who either already had a threat actor in their networks or were known to be soon to be targeted by these threat actors and gave them notice that they were about to become a victim and in many cases worked those victims and with their counsel to try and mitigate the risk that this that they knew that they were about to face. Would Would you describe that work as creative and nimble?
▶ 1:39:19Quite. It's also I think I want to underscore that it is really driven on trust. Yeah. The uh ability for this particular individual to notify over 4,000 organizations and prevent them from beginning from becoming victims and preventing billions of dollars in losses to the economy doesn't come from 3 weeks on the job. It comes from I think he was at the department for over a decade. I'll put a finer point on it. $9 billion.
▶ 1:39:44$9 billion in damages that initiative prevented in large part because of the work, to use the term Director Vote likes to use, of one And I guess we succeeded in making him not want to go to work because he left.
▶ 1:40:03And that program is no longer So, ransomware is occurring today because this administration drove out the expert, the federal employee, who was helping to prevent it to the tune of $9 billion. We are shooting ourselves in the foot. We have to stop attacking the experts who serve our nation because we have a political agenda.
▶ 1:40:31If this administration doesn't stop doing that, we will continue to lose this cyber war. I yield back. Gentleman yields back. The chair now recognizes the gentleman from Texas, Mr. Green, for his questioning. Thank you, Mr. Chairman. Thank the ranking member as well. And I welcome the Um Mr.
▶ 1:40:53Chairman, we understand that cryptocurrency fraud is something that has to be dealt with by way of regulation.
▶ 1:41:08Um currently using digital methodologies and unregulated currencies can remain anonymous and evade law enforcement.
▶ 1:41:34ability to be pseudo anonymous, pseudonymity, is a problem. Pseudonymity is a problem because we have allowed a system to develop that allows people to transfer unlimited amounts of funds without identifying themselves. Ms.
▶ 1:42:02Tiefer, how do you propose we regulate such that we can deal with the pseudonymity of the transfers of large sums of money, which by the way may go to terrorist used for ransom purposes, extortion? How do we deal with that?
▶ 1:42:30Congressman, when we established the ransomware task force, one of its core recommendations was to ensure that know your customer and anti-money laundering capabilities were uh required of exchanges that it that transmit these Uh in addition, we think that similar due diligence measures can also be taken in other aspects of the ecosystem, for example, in the domain registration space that would also help us take a more scaled approach to combating a range of illicit activity online.
▶ 1:42:59Now, pseudonymity exist is um efficacious because you have peer-to-peer transfers of money, In the banking system, you have a central bank. Goes to the central bank, then to a We still have this problem of transfers.
▶ 1:43:28By the way, we can catch many of the culprits, but it's difficult. And some of the culprits get away because of peer-to-peer And the crypto industry is spending millions upon millions of dollars to make sure Congress has people within it who are going to support the peer-to-peer
▶ 1:43:59transfers. They They place privacy the ability to prevent to prevent avoiding paying taxes on money. This pseudonymity has to be dealt with such that we, as you said, know your customer. But you can't know your customer if you don't have a customer to know.
▶ 1:44:29So again, I I'm not pressing you. I I understand you understand the problem. Uh but the problem is is actually bigger simply saying we'd like to regulate when millions upon millions are being to buy the best Congress that money can buy to support the crypto industry's insatiable appetite
▶ 1:45:01to maintain pseudonymity. I I welcome a comment if you have one. The ability to investigate illicit activity is central to the government's ability to defend the nation, and so I assert that there's definitely a need to have greater visibility into a range of activity online, uh which is one of the reasons why in my written testimony I reiterated the need to reauthorize the Cybersecurity and Information Sharing Act of 2015.
▶ 1:45:32Um I have 11 seconds. Yes, I I read body language quite well.
▶ 1:45:37Thank Thank you so much. Um I spent my career as a prosecutor investigating cases involving bulk cash smuggling and networks of Hawalas and shell companies and high-value art. Uh there was no ability to trace those things on an open public ledger. Uh we work very closely with law enforcement today to be able to combat fraud and financial crime in crypto because we actually have the ability to watch every transaction in real time, and there's a lot of benefit there. Thank you. Thank you.
▶ 1:46:04And and every transaction is more than just a few thousand transactions. Do you agree? Every transaction is more than a few thousand transactions. I'm so sorry. I'm not You said you you have the ability to watch every
▶ 1:46:21Every transaction in in in real time on an open public ledger where
▶ 1:46:24Right. And what I'm saying to you, that that is an awesome number of transactions. It's It's an awesome number of transactions. We can now see more transactions in in in on blockchains than we can in the traditional world. And in and in so doing, you have to also not only see them, now you've got to look into each one of them so as to ascertain whether or not this is a part of some illicit trade. Absolutely.
▶ 1:46:49And we can now do that in on blockchains where you never could do that in the traditional financial system, right? Through networks of, you know, wire transfers and bulk cash. Now we can see every transaction move on an open public ledger in real time and track and trace to build investigations and see Are you saying that all transactions are on the open public ledger? All transactions on public blockchains, so Bitcoin, Ethereum.
▶ 1:47:12blockchain. Public blockchain. Okay. Do you agree that there are blockchains that you are not monitoring? Um I We We monitor every blockchain. Every blockchain in history I mean, every blockchain that exists? When you lose visibility on financial transactions in the cryptocurrency world, it's often because it moves into a cryptocurrency exchange or off the blockchain. Uh certainly there are privacy tools, uh and we are uh getting very, very good at being able to track Let me to ask this as a follow-up.
▶ 1:47:40The people who engage in the people who engage in extortion and succeed with the extortion, explain how they elude the transparency that you are speaking of. It's It's really become a race. It's a race between law enforcement and bad actors. Bad actors are trying to off-ramp their funds as fast as they can. So, a ransom payment is made in Bitcoin, for example, the FBI and and and others are using tools like TRM to track and trace.
▶ 1:48:07But it's this cat-and-mouse game that has always existed in the That's why we have to shut down those off-ramps. And just just real quickly, uh those off-ramps are highly regulated. They're required to have in in the United States today, they're required to have compliance
▶ 1:48:20I'm I'm in agreement with you. That's why I mentioned the awesome number because of the number and the speed at which these transaction takes take place and the pseudonymity associated with it, it makes it difficult to catch the culprit who's moving quickly before you can get to him. And that's why it's so important that law enforcement and regulators have the tools to move as fast as these bad actors. I I agree with you. Thank you.
▶ 1:48:43Thank you. Gentleman yields back. Uh I would like to again thank our witnesses uh for being here. Uh just to um show the frequency of these attacks uh as uh we were here addressing this very important uh topic, uh my good friend and the ranking member received an email scam um just moments ago. Uh so this is another one as he would say.
▶ 1:49:10So, this is an ongoing issue that we will continue uh to address. Again, your testimony, your insight into these topics uh help us as we try to shape uh and try to make sure that we are legislating to protect the American public. Uh, in closing, uh the members of this committee may have additional questions for the witnesses.
▶ 1:49:35Uh, we would ask uh that witnesses uh respond to any uh additional questions in writing uh pursuant to committee rule 7E. Uh, the hearing record will be held open for a period of 10 days. And with that, without any objection, uh this committee stands adjourned. Thank you again.