Senator Ron Wyden sent a letter on September 2, 2026 to NSA Director Gen. Joshua Rudd, calling on the agency to update its cybersecurity guidance with clearer, more honest warnings about what a commercial VPN can and can’t protect Americans from. It’s his third letter on this general subject this year, after earlier ones in March and July, and it lands on a genuine technical gap rather than a manufactured scare.

What Wyden is actually asking for

The letter’s core argument, as reported by CyberScoop, is direct: “While commercial Virtual Private Networks (VPNs) are recommended by federal agencies and widely marketed as shields against online spying, standard consumer VPNs do not sufficiently protect users from sophisticated adversaries.” The concern isn’t that VPN encryption is broken. It’s that federal guidance recommending VPN use doesn’t currently spell out a specific, well-understood limitation: traffic analysis, where an adversary with visibility into both ends of a VPN connection can correlate timing and data volume to unmask activity without ever decrypting anything.

Why this keeps coming back to traffic analysis

According to TechRadar’s reporting, a Congressional Research Service memo cited in connection with the letter states plainly that “encryption strength alone does not protect users from an advanced, persistent threat conducting bulk data traffic collection.” That’s a description of traffic analysis specifically: single-hop VPNs route everything through one server, and an adversary capable of watching both the entry and exit points of that server can match traffic patterns together, a capability realistically limited to well-resourced state-level actors with backbone-level surveillance infrastructure, not an ordinary hacker or advertiser.

Want to compare all VPNs side by side? Check our full VPN comparison table with scores across 18 criteria.

What alternatives the letter points to

Wyden’s letter reportedly recommends the NSA’s guidance point users toward architectures specifically designed to resist this kind of correlation: multi-hop VPN configurations, Apple’s iCloud Private Relay (which splits traffic across two separately operated relays), Tor, and mixnet-based services like NymVPN. None of these are being described as replacements for commercial VPNs in general use. They’re positioned as the appropriate tools for a narrower category of high-risk user, journalists, activists, and others facing genuinely sophisticated state-level threats, where a standard single-hop VPN’s limitation actually matters.

A pattern, not a one-off letter

This is Wyden’s third letter pushing on VPN-related federal guidance in 2026, following earlier ones in March and July. Previous responses from the Office of the Director of National Intelligence reportedly offered only general cautionary notes about scrutinizing VPN providers, without directly addressing the traffic analysis gap this latest letter specifically calls out. The recurring theme across all three: federal agencies recommend VPN use broadly, but the specific technical caveats around what that recommendation does and doesn’t cover haven’t kept pace, in Wyden’s view, with the sophistication of the threats being discussed elsewhere in the same guidance documents, including a prior NSA advisory about a China-sponsored campaign targeting telecommunications and government networks.

The 2026 timeline, in order

Wyden’s push on this issue has built steadily over the year. In March, an earlier letter raised concerns about federal reliance on VPN technology generally. In July, a follow-up specifically targeted legacy, internet-facing VPN appliances inside federal agencies, calling for a two-year deadline to phase them out, a proposal about enterprise infrastructure rather than the consumer VPN app on your phone. This September letter is the most pointed of the three, naming a specific technical gap, traffic analysis resistance, and a specific fix, updated NSA guidance, rather than a broader institutional complaint. Read together, the three letters describe an escalating argument that federal messaging around VPNs hasn’t kept pace with how the underlying threats are actually described elsewhere in government advisories.

What clearer guidance would actually look like

The gap Wyden is describing isn’t really about whether VPNs are recommended at all, it’s about the fine print underneath that recommendation. Current federal guidance broadly endorses VPN use without consistently distinguishing between the kind of privacy protection a single-hop VPN provides against an ISP or a website, which is solid, and the kind of protection it can’t provide against an adversary with the resources to watch a connection at multiple points simultaneously. Clearer guidance, in Wyden’s framing, would spell out that second category explicitly and point specifically toward multi-hop or mixnet alternatives for the narrow set of people who actually need to plan around it, rather than leaving that distinction to be pieced together from academic papers and advocacy group reporting.

What this doesn’t mean for ordinary VPN users

It’s worth being precise about scope here, since letters like this tend to get flattened into “VPNs don’t work” headlines that overstate the point. For the overwhelming majority of what people actually use a VPN for, hiding browsing from an ISP, protecting data on public Wi-Fi, unblocking regionally restricted content, a standard audited VPN remains entirely effective. Traffic analysis is a real but narrow limitation that matters specifically against an adversary capable of large-scale, real-time network surveillance, which describes a small number of state intelligence services, not the threats most consumers are actually worried about day to day.

Why this is a guidance problem, not a product recall

Nothing in Wyden’s letter suggests any specific VPN provider did anything wrong, and no VPN company has been named as part of the concern, a distinction worth keeping in mind if headlines about the letter get shortened into something more alarming than what was actually said. The issue, as framed, is entirely about federal communication: agencies telling Americans to use a VPN without also explaining, clearly and specifically, the class of threat a VPN doesn’t cover. That distinction matters for how seriously to take this as a consumer. It’s a call for better labeling and clearer guidance, not evidence that any mainstream VPN provider has a flaw that needs fixing.

What to actually do with this information

If your day-to-day VPN use is about privacy from your ISP, public Wi-Fi safety, or streaming access, this letter doesn’t change anything about which VPN to pick or whether to keep using one. If you have a genuine reason to think you’re a target of state-level surveillance specifically, the letter’s recommended alternatives, Tor, multi-hop configurations, or a mixnet service, are worth researching directly rather than assuming your existing consumer VPN subscription covers that threat model. The NSA has not yet publicly responded to the letter at the time of writing. Given the pattern from the two earlier 2026 letters, a substantive public response, if one comes at all, is more likely to arrive as a quiet update to an existing advisory document months down the line than as a formal reply directly addressing Wyden by name.

Our verdict

Wyden's letter doesn't identify a new flaw in any VPN, it's pushing for federal guidance to be more specific about a known, narrow limitation: traffic analysis by state-level adversaries. Ordinary VPN use for privacy, public Wi-Fi and streaming is unaffected. High-risk users are the intended audience for the letter's recommended alternatives. For most people, a fast, audited VPN like NordVPN remains an appropriate everyday choice.

Keep reading: Traffic Analysis Attacks Explained and Sen. Wyden Wants Legacy VPNs Purged From the US Government.