The bill empowers federal agencies to find and attempt to neutralize U.S. data stolen and held abroad—potentially reducing economic and security harm and increasing transparency—while raising significant privacy, escalation, operational risk, and taxpayer-cost concerns.
Taxpayers, financial institutions, hospitals, and small businesses gain a coordinated federal effort to locate U.S. financial, medical, biometric, intellectual property, and trade-secret data stolen and held by foreign actors, improving incident response and recovery.
Small businesses and private firms could see reduced harm from exposed trade secrets or personal data because agencies are authorized to attempt to recover, destroy, or manipulate stolen encrypted U.S. data when in the U.S. economic or security interest.
Taxpayers and state governments benefit from increased transparency and congressional oversight because agencies must provide a public (unclassified) report with recommendations to Congress within one year.
Taxpayers and the broader economy face heightened risk that military- and intelligence-led cyber operations targeting stolen data could provoke retaliation or escalate conflict with foreign states, endangering national security and commerce.
Financial institutions, hospitals, and small businesses risk service disruptions or loss of legitimate data because overseas operations to destroy or manipulate stolen data may cause collateral damage to legitimate systems.
Patients with chronic conditions, people with disabilities, and private-sector entities could experience expanded government intrusion into private data and greater privacy risks because agencies are authorized to access or manipulate data held abroad.
Based on analysis of 2 sections of legislative text.
Requires DoD and DNI to develop strategies to identify and, when appropriate, destroy/manipulate/recover stolen encrypted covered data and classified material held by foreign entities and report to Congress within one year.
Official title: Require the Federal Government to identify and address stolen sensitive data and classified information, and for other purposes.
Introduced March 26, 2026 by Margaret Wood Hassan · Last progress March 26, 2026
Requires the Department of Defense and the Office of the Director of National Intelligence to build strategies to locate covered United States persons’ data and classified material unlawfully held by foreign entities, determine whether it was encrypted and if it has been decrypted, and develop options to address that material (including destruction, manipulation, or recovery). If the Secretary of Defense and the DNI jointly conclude such actions serve U.S. economic or national security interests, they may attempt them consistent with law and the developed strategies and should, when practicable, notify lawful owners before and after actions; a joint unclassified report with recommendations to Congress must be submitted within one year.