Recent Bills
- H.R. 10171August 27, 2026
- H.R. 10156August 27, 2026
- H.R. 10172August 27, 2026
- H.R. 10160August 27, 2026
- H.R. 10181August 27, 2026
- H.R. 10176August 27, 2026
- H.Res. 1496August 27, 2026
- H.R. 10164August 27, 2026
- H.R. 10170August 27, 2026
- H.Res. 1494August 27, 2026
- H.R. 10163August 27, 2026
- H.R. 10157August 27, 2026
Committees
- Administration
- Agriculture
- Agriculture, Nutrition, And Forestry
- Appropriations
- Armed Services
- Banking, Housing, And Urban Affairs
- Budget
- Commerce, Science, And Transportation
- Education and Workforce
- Energy And Commerce
- Energy And Natural Resources
- Environment And Public Works
- Ethics
- Finance
- Financial Services
- Foreign Affairs
- Foreign Relations
- Health, Education, Labor, And Pensions
- Homeland Security
- Homeland Security And Governmental Affa…
- Indian Affairs
- Indian and Insular Affairs
- Intelligence
- Judiciary
- Natural Resources
- Oversight And Government Reform
- Permanent Select Intelligence
- Rules
- Rules And Administration
- Science, Space, And Technology
- Select Intelligence
- Small Business
- Small Business And Entrepreneurship
- Subcommittee on Aviation
- Subcommittee on Border Security and Enf…
- Subcommittee on Coast Guard and Maritim…
- Subcommittee on Commodity Markets, Digi…
- Subcommittee on Conservation, Research,…
- Subcommittee on Counterterrorism and In…
- Subcommittee on Cybersecurity and Infra…
- Subcommittee on Disability Assistance a…
- Subcommittee on Economic Development, P…
- Subcommittee on Economic Opportunity
- Subcommittee on Emergency Management an…
- Subcommittee on Energy and Mineral Reso…
- Subcommittee on Federal Lands
- Subcommittee on Forestry and Horticultu…
- Subcommittee on General Farm Commoditie…
- Subcommittee on Health
- Subcommittee on Highways and Transit
- Subcommittee on Livestock, Dairy, and P…
- Subcommittee on Nutrition and Foreign A…
- Subcommittee on Oversight and Investiga…
- Subcommittee on Oversight, Investigatio…
- Subcommittee on Railroads, Pipelines, a…
- Subcommittee on Transportation and Mari…
- Subcommittee on Water Resources and Env…
- Subcommittee on Water, Wildlife and Fis…
- Transportation And Infrastructure
- Veterans' Affairs
- Ways And Means

Hearings to examine on threats and challenges posed to Department of Defense personnel and operations from adversarial access to publicly available data coupled with advanced data analysis tools now widely available on the commercial market.
Meeting•Senate Armed Services Subcommittee on Emerging Threats and Capabilities•Oct 7, 2025 · 2:30 PM
Summary
Senate Armed Services Subcommittee on Emerging Threats and Capabilities held a meeting on Oct 7, 2025 at 2:30 PM in Russell Senate Office Building, Room 222.
Record
The meeting has its transcript on the record.
Transcript
The transcript runs to 1,298 lines and 70,237 characters, as the Government Publishing Office printed it.
senate-hearing-62460.txt1[Senate Hearing 119-259]2[From the U.S. Government Publishing Office]34 S. Hrg. 119-25956 THREATS AND CHALLENGES POSED TO DOD PERSONNEL AND OPERATIONS FROM7 ADVERSARIAL ACCESS TO PUBLICLY AVAILABLE DATA COUPLED WITH ADVANCED8 DATA ANALYSIS TOOLS NOW WIDELY AVAILABLE ON THE COMMERCIAL MARKET910=======================================================================1112 HEARING1314 before the1516 SUBCOMMITTEE ON17 EMERGING THREATS AND CAPABILITIES1819 of the2021 COMMITTEE ON ARMED SERVICES22 UNITED STATES SENATE2324 ONE HUNDRED NINETEENTH CONGRESS2526 FIRST SESSION27 __________2829 OCTOBER 7, 202530 __________3132 Printed for the use of the Committee on Armed Services3334 [GRAPHIC(S) NOT AVAILABLE IN TIFF FORMAT]3536 Available via: http: //www.govinfo.gov37 ______3839 U.S. GOVERNMENT PUBLISHING OFFICE404162-460 PDF WASHINGTON : 20264243 COMMITTEE ON ARMED SERVICES4445 ROGER F. WICKER, Mississippi, Chairman46DEB FISCHER, Nebraska JACK REED, Rhode Island47TOM COTTON, Arkansas JEANNE SHAHEEN, New Hampshire48MIKE ROUNDS, South Dakota KIRSTEN E. GILLIBRAND, New York49JONI K. ERNST, Iowa RICHARD BLUMENTHAL, Connecticut50DAN SULLIVAN, Alaska MAZIE K. HIRONO, Hawaii51KEVIN CRAMER, North Dakota TIM KAINE, Virginia52RICK SCOTT, Florida ANGUS S. KING, Jr., Maine53TOMMY TUBERVILLE, Alabama ELIZABETH WARREN, Massachusetts54MARKWAYNE MULLIN, Oklahoma GARY C. PETERS, Michigan55TED BUDD, North Carolina TAMMY DUCKWORTH, Illinois56ERIC SCHMITT, Missouri JACKY ROSEN, Nevada57JIM BANKS, Indiana MARK KELLY, Arizona58TIM SHEEHY, Montana ELISSA SLOTKIN, Michigan59 John P. Keast, Staff Director60 Elizabeth L. King, Minority Staff Director61 _______6263 Subcommittee on Emerging Threats and Capabilities6465 JONI K. ERNST, Iowa, Chairman66TOM COTTON, Arkansas ELISSA SLOTKIN, Michigan67MIKE ROUNDS, South Dakota JEANNE SHAHEEN, New Hampshire68KEVIN CRAMER, North Dakota KIRSTEN E. GILLIBRAND, New York69MARKWAYNE MULLIN, Oklahoma TIM KAINE, Virginia70TED BUDD, North Carolina GARY C. PETERS, Michigan71ERIC SCHMITT, Missouri JACKY ROSEN, Nevada72TIM SHEEHY, Montana MARK KELLY, Arizona7374 (ii)7576 C O N T E N T7778 ---------7980 october 7, 20258182 Page8384Threats and Challenges Posed to DOD Personnel and Operations From 185 Adversarial Access to Publicly Available Data Coupled with86 Advanced Data Analysis Tools Now Widely Available on the87 Commercial Market.8889 Member Statements9091Statement of Senator Joni Ernst.................................. 19293Statement of Senator Elissa Slotkin.............................. 29495 Witness Statements9697Kirschbaum, Joseph W., Director, Defense Capabilities and 398 Management, U.S. Government Accountability Office.99100Sherman, Justin, Founder and Chief Executive Officer, Global 24101 Cyber Strategies.102103Doyle, John, Chief Executive Officer, Cape....................... 43104105Stokes, Michael, Vice President of Strategy, Ridgeline 45106 International.107108 (iii)109110 THREATS AND CHALLENGES POSED TO DOD PERSONNEL AND OPERATIONS FROM111 ADVERSARIAL ACCESS TO PUBLICLY AVAILABLE DATA COUPLED WITH ADVANCED112 DATA ANALYSIS TOOLS NOW WIDELY AVAILABLE ON THE COMMERCIAL MARKET113114 ----------115116 TUESDAY, OCTOBER 7, 2025117118 United States Senate,119 Subcommittee on Emerging120 Threats and Capabilities,121 Committee on Armed Services,122 Washington, DC.123 The Subcommittee met, pursuant to notice, at 2:28 p.m., in124room SR-222, Dirksen Senate Office Building, Senator Joni Ernst125(Chairwoman of the Subcommittee) presiding.126 Subcommittee Members present: Senators Ernst, Slotkin,127Kaine, and Peters.128129 OPENING STATEMENT OF SENATOR JONI ERNST130131 Chairwoman Ernst. We will go ahead and get started this132afternoon, and we may be joined by other Members. I know we133have a pretty full schedule this afternoon, so thank you.134 Good afternoon. The Subcommittee on Emerging Threats and135Capabilities meets today to receive testimony on how our136adversaries are using publicly available data to undermine the137security of Department of Defense (DOD) personnel, platforms,138and operations. As our lives become increasingly connected, the139invisible trail of metadata, location signals, app usage,140biometric data, and other digital breadcrumbs has created a new141exploitable surface for adversaries. Data that seems142insignificant on its own can, when aggregated with other143information and intelligence, reveal troop movements,144operational planning, and the daily routines of our personnel.145 Foreign intelligence services and cybercriminals can146harvest and analyze this information in ways that threaten the147security of DOD missions and the safety of our servicemembers148and their families. We have seen in public news reports how the149use of commercially available fitness apps has inadvertently150exposed the location of sensitive military bases. We have seen151how social media and mobile devices have been used to geolocate152personnel and manipulate their information environment.153 The pace of technology and the widespread use of Internet-154connected devices presents a significant and evolving155challenge. Today, we will hear from experts across the156government and industry to understand the scope of this threat157and what must be done. Thank you.158 With that, then I will turn to the Ranking Member.159160 STATEMENT OF SENATOR ELISSA SLOTKIN161162 Senator Slotkin. Great. Thank you, Senator Ernst, for163holding this really important hearing. Thank you to our guests164for joining us and helping us parse through this.165 I think, you know, for those of us who watch the national166security space really closely, I think it is very clear that167the future of warfare may not be tanks and airframes, but168really data and who controls that data, who can easily169amalgamate that data and then weaponize that data. While there170are lots of actors out there, we certainly know that China is171just a massive player in this space and, in my opinion, has172already, both through commercially available information but173also through the theft of personal information, really made a174business of collecting this data for a whole bunch of reasons.175I think something like in the order of $600 billion annually is176lost in intellectual property that is taken from U.S. companies177through cyber attacks, so it is a real threat, even if it is178hard to get our hands around.179 There is, I think, lots of good bipartisan work going on on180this in the National Defense Authorization Act (NDAA) and other181spaces, but I think this is a great opportunity to highlight182for the American public kind of the nature of changing warfare183and how their own personal data is now on the frontlines in a184very, very different way, so look forward to hearing the185conversation.186 Back over to you, Madam Chairwoman.187 Chairwoman Ernst. Wonderful. Thank you. I will just start188with some brief introductions of our witnesses today, and then189you will each be recognized for your statements. You will each190have 5 minutes for opening statements.191 We have Dr. Joseph Kirschbaum, and he is the director in192the Defense Capabilities and Management team at the U.S.193Government Accountability Office (GAO), where he oversees194evaluations of defense and intelligence programs for195congressional committees. So thank you very much for being here196today, Dr. Kirschbaum.197 Justin Sherman is the founder and Chief Executive Officer198(CEO) of Global Cyber Strategies, a Washington, DC-based199research and advisory firm specializing in cybersecurity, data200privacy, technology policy, and geopolitics for clients ranging201from startups to the U.S. Government. Thank you very much for202being here, Mr. Sherman.203 John Doyle is the founder and CEO of Cape, a privacy-first204mobile carrier designed to defend users' mobile identity and205limit the data exposure inherent in traditional cellular206networks. So thank you very much for being here, Mr. Doyle.207 Then finally, Michael Stokes is vice president of strategic208engagements and marketing at Ridgeline International, where he209leads business development, partner growth, and market strategy210efforts in the cybersecurity and digital signature management211space. Thank you very much, Mr. Stokes.212 With that, we will start with you, Dr. Kirschbaum, and you213are recognized for 5 minutes.214215 STATEMENT OF JOSEPH W. KIRSCHBAUM, DIRECTOR, DEFENSE216 CAPABILITIES AND MANAGEMENT, U.S. GOVERNMENT ACCOUNTABILITY217 OFFICE218219 Dr. Kirschbaum. Chairwoman Ernst, Ranking Member Slotkin,220and Members of the Subcommittee, I am pleased to be here today221to discuss the report which we will be issuing today on risks222of publicly available information to the Department of223Defense's personnel and operations and their approach to224address those risks. We have previously reported how the225escalation in the volume and interconnectedness of data and the226evolving DOD information environment have changed the national227security landscape. Historically, enemies who seek harm to U.S.228Forces or its people had to go where the information was and229find ways to get at it, you know, rifling through the trash,230sustained surveillance, and other techniques. These days, in231the information age, all that data and much more comes to them,232which lowers the bar of entry for malicious actors.233 At the heart of the matter is the fact that DOD234servicemembers, employees, contractors, family members235constantly provide massive amounts of traceable data, known as236the digital footprint, and do so intentionally and237unintentionally. This data can be collected and aggravated by238the public, data brokers, or malicious actors over time that239create a digital profile that can reveal potentially sensitive240and classified information.241 We are talking here about a mix of data and information.242This includes social media posts, official media releases,243public information, property records, transmissions from244personal electronic devices, electronic emissions from military245platforms themselves, and other examples. The availability of246these data and potential for them to be exploited are increased247by data brokers with both neutral and nefarious intent and the248application of artificial intelligence (AI).249 For our report, we develop notional threat scenarios that250exemplify how malicious actors can collect and use information251about DOD operations and its personnel. We develop these based252on analyses of literature, interviews, and information from the253Department of Defense, and by conducting our own investigation254into the types and sources of these data.255 Two of the scenarios are shown to my right and your left,256and there are in the handouts in front of you. The first is a257depiction of publicly available information presenting a force258protection threat to a servicemember and/or family members259through the aggregation of information and sources. A260servicemember's name, rank, photograph, and unit can be261identified from online sources. DOD websites and social media262often post this information freely.263 From there, a malicious actor can narrow their search by264visiting servicemembers or relative social media sites and265associated information and data tags. From there, you can start266collecting additional information, especially if one of the267individuals has a phone that allows identification by nearby268devices or if they have downloaded a third-party application269that tracks geolocation, as many of them do. Like puzzles,270these can be set into place to show pattern of life.271 In testing this scenario, our investigators didn't have to272proceed far into the internet or the dark web to find access to273data brokers selling significant quantities of additional274information on military personnel.275 The next is a depiction of risks to naval operations276through exposure of real-time information about a ship's277movements, its personnel, and onboard conditions. Taken278collectively, information from Navy and DOD posts and press279releases and seemingly private blogs and posts can be linked280with open transmissions from ship and aircraft platforms, as281well as personal connected devices to project the route of an282aircraft carrier and present a nefarious actor with a useful283intelligence picture.284 Our report also illustrates two other scenarios, risk to285military capabilities from training operations and equipment,286information and risks to military leadership from potential287disclosure of an official's behaviors and associations. As with288previous information environment challenges, DOD has no single289officer entity to address all risks associated with the kind of290thing we are talking about here, nor should it. DOD has291security disciplines and functions to manage these kinds of292risks. We found uneven progress among these areas to address293the risks we identified. This is about policy, organization,294and culture. Our forthcoming report issued today recommends295that DOD improve policies, guidance, training, and assessments296across those security disciplines, and DOD has already agreed297with those recommendations.298 In conclusion, DOD has an opportunity to make progress.299This will require them to look beyond what is strictly in their300control in terms of official data and information and what301might not be. That in turn will help the Department determine302how best to mitigate those threats.303 This completes my prepared statement, and I am happy to304address any questions.305 [The prepared statement of Mr. Kirschbaum follows:]306307 [GRAPHIC(S) NOT AVAILABLE IN TIFF FORMAT]308309 [Supporting documentation supplied by GAO to follow:]310311 [GRAPHIC(S) NOT AVAILABLE IN TIFF FORMAT]312313 Chairwoman Ernst. Thank you, Dr. Kirschbaum.314 Mr. Sherman, you are now recognized for 5 minutes.315316 STATEMENT OF JUSTIN SHERMAN, FOUNDER AND CHIEF EXECUTIVE317 OFFICER, GLOBAL CYBER STRATEGIES318319 Mr. Sherman. Subcommittee Chairwoman Ernst, Ranking Member320Slotkin, and distinguished Members of the Subcommittee, thank321you for the opportunity to testify today about the explosion in322data, digital connectivity, adversary threats, and how the U.S.323can respond.324 In my work, I have published at length on the risks of the325data ecosystem to national security, have worked on several326U.S. Government responses to the problem, and also teach at327Georgetown, graduate students on open source intelligence,328commercial data, and U.S. national security strategy.329 In the last 2 decades, the amount of data and digital330connectivity has exploded, both in the U.S. and globally. This331has afforded the U.S. a number of advantages in intelligence,332military, and security areas, but we are unfortunately333significantly behind when it comes to recognizing the threats334these pose to the United States and to the servicemembers and335other U.S. national security personnel that make a tremendous336sacrifice in their public service, including, for many, putting337their lives on the line every single day.338 In our current digital environment, a tremendous amount of339data is collected, analyzed, and transmitted near incessantly340on virtually every single American--health information, device341IDs, 24/7 phone location data, records of online purchases,342browsing histories, pornography consumption, propensities for343cigarettes or alcohol, late-night gambling, or overseas travel.344There are several dimensions to this risk: Open-source345information on public websites, social media pages, the dark346web, and even freely available commercial satellite imagery347platforms; data brokers that collect and sell thousands of data348points per person on hundreds of millions of Americans; real-349time bidding networks for online ads that constantly blast out350device-identifiable sensitive data every single day; vehicles351that transmit location signals every few seconds, accurate352within inches; and even commercial data analysis capabilities353that allow adversaries the ability to identify, reidentify, and354package up Americans' data.355 All of this can be exploited in cyber, information,356intelligence, and other operations against the United States357and represents an extraordinary counterintelligence threat. We358have already seen examples of how this threat has impacted U.S.359national security. The U.S. Government calls this the UTS or360ubiquitous technical surveillance problem.361 A few examples. The 2018 Strava scandal, as the chair362mentioned, showed how one web application could expose the363real-time locations and historical locations of United States364troops, including those jogging around forward-operating bases365in Afghanistan. I ran a Defense Department-funded threat366assessment where my research team set up websites in the United367States and Singapore, contacted U.S. data brokers, and bought368individually identified, highly sensitive health, financial,369and other data on thousands of Active Duty U.S. military370servicemembers with virtually no serious background checks or371vetting for as low as 12 cents a servicemember and even were372able to geofence the data to bases publicly known to house U.S.373Special Operations Forces. They also transferred this data374overseas.375 A 2023 study identified real data packages in advertising376systems right now with titles such as ``people who work in the377Pentagon,'' ``people working in defense and space,'' and378individuals labeled as government, intelligence, and379counterterrorism.380 Foreign adversaries such as China and Russia are readily381investing to be able to exploit these vulnerabilities. Beijing382has stolen enormous volumes of data on Americans, has advanced383cyber and AI capabilities, and has shown a strong OSINT384interest in United States Military Forces. Moscow, likewise,385has advanced cyber and intelligence functions and many open386source intelligence (OSINT) and cyber contractors it can throw387at this work.388 Given the threats, there are three steps that Congress can389take now. First is to compel the Defense Department to evaluate390these risk mitigation gaps, both in open-source/unclassified as391well as classified reports and both enterprise-wide as well as392within and between specific agencies.393 The second is to pass legislation to further lock down394Americans' data, building on recent efforts at the Department395of Justice and in last year's Congress with the bipartisan396Protecting Americans' Data from Foreign Adversaries Act or397PADFAA, among other things.398 Third is to help rethink the U.S. societal attitude. For399decades, we have seen the consequences of this connect now,400think later, download now, assess the risk later attitude, both401in society generally and with respect to our military.402Rethinking this is essential to national security and to the403future.404 So acting now is not just essential for our military405servicemembers whose lives are on the line, but also to the406Defense Department's vital mission set and broader U.S.407national security interests. Thank you.408 [The prepared statement of Mr. Sherman follows:]409410 [GRAPHIC(S) NOT AVAILABLE IN TIFF FORMAT]411412 Chairwoman Ernst. Yes, thank you, Mr. Sherman.413 Mr. Doyle, you are recognized.414415 STATEMENT OF JOHN DOYLE, CHIEF EXECUTIVE OFFICER, CAPE416417 Mr. Doyle. Chairwoman Ernst, Ranking Member Slotkin, and418Members of the Committee, thank you for the opportunity to419appear here today. My name is John Doyle. I am a former U.S.420Army Special Forces sergeant and the founder and CEO of Cape.421 Cape is a mobile carrier that safeguards user privacy and422security by systematically solving the technical423vulnerabilities that plague commercial cellular networks. We424serve customers within the government along with commercial425enterprise and everyday consumers.426 Back in 1991, members of the press were able to predict the427timing of Operation Desert Storm due to an unusual lapse in428security. They had figured out that late-night pizza deliveries429to the Pentagon spiked dramatically when major operations were430about to launch. Thirty-five years later, those who wish to431suss out sensitive information about troop positions, patrol432routes, or the timing of operations no longer need to call433Domino's. These days, it is much easier to figure out.434 That is because today's military relies heavily on the same435commercial cellular networks that we all use every day and the436same carriers that are regularly and repeatedly hacked and437exploited. These networks are almost universally available,438including on the battlefield, making them irresistibly439convenient to use in military contexts. This in turn makes it440easy for determined actors to track the activity of military441personnel based solely on the phones they carry in their442pockets and the volumes of data that those phones produce.443 The consequences of our reliance on these networks have444been felt on the home front, including most recently through445the Salt Typhoon cyberattacks, and the battlefield is no446different. In Ukraine, both Ukrainian and Russian forces use447commercial cellular networks heavily to coordinate operations448and carry out intelligence gathering, despite wide reporting449that both sides are also targeting each other based on cell450phone location data. Ukraine took new advantage of cell network451availability this summer with Operation Spiderweb, embedding452Subscriber Identifcation Module (SIM) cards into drones and453using Russia's own mobile networks to remotely pilot them into454Russian targets.455 Cell phones are not responsible for 100 percent of the data456vulnerabilities that military personnel face, but I would put457it close to 85 percent. The well-known and frequently exploited458weaknesses of commercial networks, paired with the volume of459publicly available data our adversaries can readily access,460make it possible to learn far too much about the habits and461locations of our servicemembers at scale. Advanced data462analytics platforms now allow bad actors to easily correlate463information across datasets, making the intelligence value of464telecommunications data even more extreme.465 Phone carriers abet this State of affairs by monetizing466customers' data directly, selling some of the most exquisite467pattern-of-life data imaginable to governments and private468entities alike. Some applications, some apps, exist to mitigate469certain threats at the device and app layer, but before Cape,470there was essentially nothing a user could do, even when that471user is a national security professional or a servicemember, to472mitigate risks at the network level. And if I may, the problem473is compounded by bureaucratic processes at the Pentagon that474funnel all cellular service procurement to a 10-year Indefinite475Delivery, Indefinite Quantity (IDIQ) contract called Spiral 4476that has not been opening onramps to new, innovative entrants477since the last award.478 Still worse, the contract is written to insist on479procurement of lowest-priced, technically acceptable solutions,480in other words, buying cellular service based on price only and481not insisting on solutions to the problems inherent in the482incumbents. I would be remiss if I didn't specifically mention483section 1513 of the House fiscal year 2026 NDAA, which484addresses these shortcomings, and I would ask for this body's485support of that provision through the conference process.486 The threat the status quo poses is profound. Every487servicemember has a smartphone in their cargo pocket. The good488news is that this is not an intractable problem. My company is489just one of several working in the problem space, and others490are represented here at the table with me. We at Cape are491focused on tackling network vulnerabilities that our492adversaries abuse to gain insight into personnel and493operations. After decades of stagnation in the security of494commercial networks, while technology dedicated to exploiting495weaknesses graduated from the Pentagon Pizza Index to state-of-496the-art data analytics, we are finally seeing the rise of497technology dedicated to fixing those weaknesses instead and498traction for policy changes to enable adoption of those499technologies by the Force.500 Thank you for convening this important conversation, and I501look forward to answering your questions.502 Chairwoman Ernst. Thank you, Mr. Doyle.503 Mr. Stokes, you are recognized for 5 minutes.504505 STATEMENT OF MICHAEL STOKES, VICE PRESIDENT OF STRATEGY,506 RIDGELINE INTERNATIONAL507508 Mr. Stokes. Chair Ernst, Ranking Member Slotkin, and509Members of the Subcommittee, thank you for the opportunity to510testify.511 At Ridgeline, we have followed this problem closely since5122016. In our work across government and industry, we use the513term ubiquitous technical surveillance to describe this threat.514I will offer two things today, a concise definition of the515problem and a path forward.516 The Definition. As Mr. Sherman stated, UTS is not just a517single sensor you can switch off. It is a fused fabric of518phones and apps, connected cars, building cameras, electronic519payments, cell and Wi-Fi metadata, plus a vast commercial data520market. That fusion exposes patterns, and deviations from those521patterns are triggers for an adversary. An unusual no-phone522day; synchronized travel by people who should not be connected;523a route, flight, or driving pattern that does not match a524desired cohort, these anomalies trigger an automated525investigation, followed by human scrutiny. Near-peer526adversaries and sophisticated non-State actors such as cartels527already leverage UTS to anticipate, frustrate, and compromise528U.S. missions worldwide.529 The Path Out. Admiring the problem is one thing, and this530hearing is bringing that right attention to the problem, but531awareness without doctrine, policy, standards, and resourcing532will not move the needle. At Ridgeline, we enable what we call533digital signature warfare, a proactive approach to managing534digital signatures so behavior and emissions align with a535cohesive cover narrative before, during, and after operations.536The aim is simple. Protect the operational act, avoid537investigative triggers, and mitigate forensic reconstruction.538 So here are four recommendations to make that real. One,539name a single accountable lead for UTS and publish an540enterprise baseline for signature management. Today, UTS is541everyone's problem and no one's priority, so dollars for542digital force protection fall below the line. An ad hoc543approach to this issue is not sufficient. Task a single office544within Office of Secretary of Defense (OSD) of owning the545problem. They should issue a digital signature management plan546for any device that connects to the public internet. This547includes a serious conversation about personal cell phones.548This policy should consider commercial data covering device549posture, routing diversity, cohort fit, and normalized absence.550 Two, protect our people by shrinking the commercial attack551surface. The data broker ecosystem still trades in sensitive552datasets, including precise geolocation, as we have heard553today. Consumer opt-outs will not safeguard a sergeant's554commute to base housing, and Congress can direct a department,555do not call, collect, or do not sell policy for servicemembers556and dependents, enforceable on app stores and brokers with557penalties, and require annual inspector general and GAO audits558of compliance.559 Three, close two infrastructure gaps, telecom and connected560vehicles. As the impact of recent Salt Typhoon and recent561attacks come into focus, the vulnerabilities of our commercial562communications infrastructure are now clearer than ever. This563infrastructure compromise illustrates the need for end-to-end564encrypted enterprise-grade commercial messaging applications.565Connected vehicles are essentially smartphones on wheels566equipped with sensors and uplinks. These vehicles feed data567into unregulated commercial data economies.568 Support the Commerce Department's work to restrict569untrusted connected vehicles and fully implement provisions570that ban Chinese-connected vehicles on military installations.571 Leverage enterprise-grade secure messaging applications,572such as Element.io, to communicate unclassified content on573phones.574 Four, units should deploy a digital mirror, a survey575policy, a posture for UTS vulnerabilities, and then adjust576routes, timing, and devices' use as they blend into the desired577cohort. The objective is not to vanish; it is to look normal,578in pattern, all the time.579 Effective UTS mitigation is not theoretical. Technology,580training, and tradecraft already exist and are being581effectively applied at the very peak of our sensitive defense582and intelligence operations. It is time to adapt and scale583these solutions for a broader force.584 Let me close with a family level point. This is not only585for soft or intel operators. Spouses, kids, contractors, and586base workers all generate these patterns adversaries use. If a587hostile actor can determine where a soldier sleeps or where a588gate a unit uses, we have ceded initiative. With the steps589above, governance, guardrails for commercial data, and590infrastructure risk reduction, we can lower trigger rates, make591it harder for the enemy to reconstruct an operation, and reduce592the cost of secrecy across the force. That is how we turn UTS593from a persistent disadvantage into an operational edge.594 Thank you for the opportunity to testify.595 [The prepared statement of Mr. Michael Stokes follows:]596597 Prepared Statement by Michael Stokes598 introduction599 Chair Ernst, Ranking Member Slotkin, and Members of the600Subcommittee, thank you for the opportunity to testify.601 My name is Michael Stokes, Vice President of Strategy at Ridgeline602International. We have followed this problem closely since 2016. In our603work across government and industry, we use the term Ubiquitous604Technical Surveillance (UTS) to describe this threat.605 I will offer two things today: a concise definition of the problem606and a path forward.607 The Definition. UTS is not a single sensor you can switch off. It608is a fused fabric of phones and apps, connected cars, building cameras,609electronic payments, cell and Wi-Fi metadata--plus a vast commercial610data market. That fusion exposes patterns, and deviations from those611patterns are triggers for an adversary. An unusual no-phone day.612Synchronized travel by people who should be unconnected. A route,613flight, or driving pattern that does not match the desired cohort.614These anomalies trigger an automated investigation, followed by human615scrutiny. Near-peer adversaries--and sophisticated non-State actors,616such as cartels--already leverage UTS to anticipate, frustrate, and617compromise U.S. missions worldwide.618 The Path Out. Admiring the problem is one thing; this hearing is619bringing the right attention to the problem. But awareness without620doctrine, policy, standards, and resourcing will not move the needle.621At Ridgeline, we enable Digital Signature Warfare--a proactive approach622to managing digital signatures so behavior and emissions align with a623cohesive cover narrative before, during, and after operations. The aim624is simple: protect the operational act, avoid investigative triggers,625and mitigate forensic reconstruction.626 Here are Four recommendations to make that real.627 One. Name a single accountable lead for UTS and publish an628enterprise baseline for signature management.629 Today, UTS is everyone's problem and no one's priority, so dollars630for digital force protection fall below the line. An ad-hoc approach to631this issue is not sufficient. Task a single office in OSD with owning632the problem. They should issue a Digital Signature Management plan for633any device that connects to the public internet. This includes a634serious conversation about personal devices. This policy should635consider commercial data, covering device posture, routing diversity,636cohort fit, and normalized absence.637 Two. Protect our people by shrinking the commercial attack surface.638 The data-broker ecosystem still trades in sensitive datasets,639including precise geolocation. Consumer opt-outs will not safeguard a640sergeant's commute to base housing. Congress can direct a Department641``Do-Not-Collect/Do-Not-Sell'' policy for servicemembers and642dependents--enforceable on app stores and brokers with penalties--and643require annual Inspector General and GAO audits of compliance.644 Three. Close two infrastructure gaps: telecom and connected645vehicles.646 As the impact of the recent Salt Typhoon and related attacks comes647into focus, the vulnerabilities of our commercial communications648infrastructure are now clearer than ever. This infrastructure649compromise illustrates the need for end-to-end encrypted enterprise-650grade commercial messaging applications. Connected vehicles are651essentially smartphones on wheels equipped with sensors and uplinks.652These vehicles feed data into unregulated commercial data economies.653 Support the Commerce Department's work to restrict untrusted654connected vehicles and fully implement provisions that ban Chinese655connected vehicles on Military installations. Leverage enterprise-grade656secure messaging applications such as Element to communicate657unclassified content on phones.658 Four. Units should deploy a Digital Mirror, a survey policy, and659posture for UTS vulnerabilities, and then adjust routes, timing, and660device use until they blend into the desired cohort. The objective is661not to vanish; it is to look normal--in pattern--all the time.662 conclusion663 Effective UTS mitigation is not theoretical. Technology, training,664and tradecraft already exist and are being effectively applied at the665very peak of our sensitive defense and intelligence operations. It is666time to adapt and scale these solutions for the broader force.667 Let me close with a family level point. This is not only for SOF or668intel operators. Spouses, kids, contractors, and base workers all669generate the patterns adversaries use. If a hostile actor can determine670where a soldier sleeps or which gate a unit uses, we have ceded671initiative. With the steps above--governance, guardrails for commercial672data, and infrastructure risk reduction--we can lower trigger rates,673make it harder for the enemy to reconstruct an operation, and reduce674the cost of secrecy across the force. That is how we turn UTS from a675persistent disadvantage into an operational edge.676 Thank you for the opportunity to testify. I look forward to your677questions.678679 [Supporting documentation submitted by Mr. Michael Stokes to680follow:]681682 [GRAPHIC(S) NOT AVAILABLE IN TIFF FORMAT]683684 Chairwoman Ernst. Very good. Thank you all very much for685your opening statements.686 Now we will open up for our question-answer portion of687today's Subcommittee hearing, and I will yield to the Ranking688Member. Ranking Member, if you would like to start with your689questions, you have 5 minutes. Thank you.690 Senator Slotkin. Thank you. Thank you, Chairwoman, and I691apologize. I am going to have to step out after I ask these692questions.693 But super interesting topic and a topic, obviously, that694deeply impacts our military, our intelligence community. I am a695former Central Intelligence Agency (CIA) officer, so I am696trying to imagine what the CIA officers of the future are going697to be up against when they try to go undercover abroad. Their698movements, their social media profiles, their buying habits,699their facial recognition is all scraped and amalgamated. But I700think that this issue is one of those that overlaps with the701just normal civilian population. I don't think the average702person wants, you know, certainly someone from another country703having all this amalgamated data.704 So I guess the question I have could be for a couple of you705is, Mr. Sherman, the data brokers, the people who are paying 12706cents for all the data on, you know, a military soldier or on707an Army soldier's information, do you agree--I mean, I like708this idea of basically changing in law that you can't just buy709an American, you know, uniform military chunk of data. Does710that sound right to you? Is that the way you would propose?711 Mr. Sherman. I think that is right. The point my fellow712panelists made about widening the net, I think, is really713important, right? If we think about--you know, I had a data714broker once say to me, oh, well, we can't sell you GPS715datapoints on a military base--purely due to internal policy;716there is no law that says this--but we can sell you the data on717everywhere else they go and everything else they are doing all718the time, right?719 So, I think to that point, you know, family is one piece.720If we only focus on bases, well, what about off-base activity?721What about who they are meeting with? What about what they do722in off hours, right, and so forth?723 But I completely agree, Senator, I think cracking down on724the sale in the first place is the way to go.725 Senator Slotkin. Yes, and Mr. Stokes, I completely agree726and have had legislation for years now on banning Chinese-727connected vehicles from ever landing on our shores here. You728described them as like a traveling cell phone. I just think it729is like a traveling surveillance package.730 A couple of months ago now we had an incident where some731officials from Taiwan were traveling in Europe, and a car732accident was precipitated right in front of the place where733they were meeting. Again, I don't have the classified story on734that, but my immediate thought was, how did they know where735this person was? You know, what kind of vehicle was involved in736collecting information or precipitating it? So I am in full737support of banning those things.738 But can you give us a little bit of color, you know, put on739the adversary hat. If you had all this data on the U.S.740military locations, individuals, et cetera, illustrate for us741with a little color what kind of things you would be doing if742you were the adversary?743 Mr. Stokes. Thanks for the question, Senator Slotkin. That744is a very charged question, but I will put it out the best way745I can. Adversaries are already using this data effectively746against our servicemembers and our intelligence community. We747have found in our publicly available research at Ridgeline748where we were tracking cohorts of data from pockets at the749Pentagon, at Dulles Airport, and military installations where750you look and track the commercial ad tech data at those key751points. You might find, and we did find, Chinese-based cell752phones with Chinese-language packs who also go to the Chinese753embassies following the same cohort of individuals.754 I say that to imply that it is very likely that this is a755common occurrence among intelligence officers from the People's756Republic of China (PRC) to disrupt or deny or even potentially757cause vehicular accidents in Europe.758 Senator Slotkin. Yes. And then last, and I am not sure who759is the right person to answer this, but there is this whole760competing pressure with the Pentagon where we want to protect761data, and they don't have their house in order, according to, I762think, all of you, but we also want to make sure that we are,763you know, keeping up with the values of tech on AI and not764missing out on opportunities to do interesting things. Those765feel like, you know, countervailing pressures, right? And I766know that there have been organizations in the past year who767have been interested in data from the Department of Defense and768putting that through different AI apps. What is the advice to769those of us who oversee the Pentagon on how to think about AI770and data and what we should and should not be doing with that771data? Anybody? Don't jump all at once.772 [Laughter.]773 Mr. Doyle. That is a great question, Senator. Thank you for774it. It is probably also a little charged or certainly difficult775to answer holistically.776 I would offer, first, we face a similar challenge at Cape,777which is when you want to provide people, including778servicemembers, with cellular service, which everyone needs and779everyone relies on. People, including national security780professionals, have a very low tolerance for any compromises in781that user experience, and so one of the original design782principles at Cape is we have to provide uninterrupted,783basically transparent user experience to our subscriber base.784 I think you are describing a similar challenge, which is785folks simultaneously want to be mindful of their digital786footprint and careful in the way that they manage data, but787they also want to leverage all these incredibly powerful788technologies that are emerging literally every day all around789us.790 While I am not qualified to offer a specific technical791solution, I would offer that what we have found over a few792years of doing this now is the overarching problem statement793can seem daunting and can seem intractable, but when you break794it down into individual threats that you are trying to mitigate795and be specific about those threats and be specific about those796challenges, there is almost always a specific technical797solution to be built and deployed that can uphold both your798insistence on real user experience and accessibility to tools799and also take care of your data privacy.800 Senator Slotkin. Great. Thank you.801 I yield back. Thank you for letting me go first.802 Chairwoman Ernst. Wonderful. Thank you.803 So this has been a really interesting hearing, I think, for804so many of us. I know when I deployed Operation Iraqi Freedom805in 2003, not many of my soldiers had cell phones. You know, all806we could do was say, hey, after waiting in line for an hour to807get to the one landline that we had and your 5-minute phone808call with your family, just don't tell them where you are. You809know, things have changed significantly from that point in time81022 years ago.811 So I do see where this is an issue. I think many of you812have described quite well the threats that exist out there and813why that data can be so useful to our adversaries. So just814understanding that what we think of as seemingly harmless815information can really be leveraged not only against us, but816potential units, et cetera.817 Just the figure--and maybe one of you had said this--but818over 85 percent of our servicemembers use connected devices819that collect geolocation data, creating an exploitable surface.820So our adversaries are mapping that. We need to understand821that. We need to communicate that.822 You have already described how these services are using the823open-source datapoints to target. Mr. Sherman, you had talked824about just banning the sale of that data. Is there anything825else that the Department of Defense can specifically do to826reduce the operational value of the information to our827adversaries? And really to any one of you. Dr. Kirschbaum?828 Dr. Kirschbaum. Yes, so the example you gave, Senator, was829really perfect because that is a classic OPSEC operation830security example. When you look at the way the Department831treats these things, as we have over the last 10, 15 years,832they are usually the group that gets it soonest. The other833security disciplines that are part of the defense security834enterprise, force protection, counterintelligence, the data835protection group, mission assurance, they are not as fast to836come along. The good news is they are part of that security837enterprise, and they are all headed by undersecretaries of838defense, the right ones, the intelligence security policy, the839joint chiefs, and they have a structure set out to really840handle all this. It kind of warms my GAO heart. They have got841roles and responsibilities. They have got a harmonization of842policies. All that is the right path. What is important for843them to do now is to recognize that all the things we are844talking about need to be integrated into all those disciplines,845and they are not now.846 Chairwoman Ernst. Doesn't sound like an easy task. But yes,847I do agree with you. So then how can the Department better848train, then, our servicemembers to be aware and to recognize849when their personal data may have been shared or, you know,850exposing mission-sensitive information? What can they do? How851can we train them?852 Yes, Mr. Stokes.853 Mr. Stokes. Thanks for the question, Senator.854 UTS training or training about your digital signature is855imperative for every soldier, every sailor, every airman856because it is not just the person at the tip of the spear. If857everybody is aware about their digital signature and what they858can do about it, they then are affecting a much larger force.859 At Ridgeline, we offer ubiquitous technical surveillance860training and everything from 1-day chunks to several-week861training. We think it is required training for the force. It862used to be reserved for the special operators, and no longer is863the special operator the only person that needs to care about864this.865 Beyond just training, I highly recommend what we call a UTS866survey or a digital mirror where you have somebody collect all867of that commercially available data at your unit level or your868base or your squadron and look at it and tell you what you869actually look like in the data. From there, you can make more870informed decisions and potentially alter your digital signature871going forward.872 Chairwoman Ernst. Really good.873 Mr. Doyle.874 Mr. Doyle. Yes, if I may build on that. Thank you, Senator.875I echo what Mr. Stokes said about the importance and value of876training, although I would also point out that when we train on877these UTS challenges and digital signature management878challenges, often what we are trying to do is change user879behavior, in particular, often but not always the way that we880use our personal cell phones. In my experience and our881experience, user behavior with respect to commercial cell882phones is notoriously hard to alter, and there have been some883high-profile examples of this.884 It is not to invalidate or to minimize the importance of885training or the effectiveness of training, but also I would886encourage the Subcommittee to consider the importance of887technical solutions and policy changes that also get at the888root of the problem. I think you need a multi-pronged approach889in order to be successful.890 Chairwoman Ernst. Yes, thank you. Any other thoughts on891that? Yes, Mr. Sherman.892 Mr. Sherman. I would only underscore that last point,893right? I agree with everything my fellow witnesses said. As we894have also said, you know, national security operators are895always going to have a higher burden than the average American896in this area, but we can reduce it significantly with broader897privacy and security controls.898 So while that certainly is not, you know, only in DOD's899hands, I think some of the protections we have talked about900from data brokers to connected cars would do a lot.901 Chairwoman Ernst. Okay. Thank you very much. I appreciate902it, and I will yield back my time and will go to Senator903Peters.904 Senator Peters. Thank you, Chair Ernst, for that. You know,905I think this has been a great discussion. I appreciate all of906you being here, and certainly, the concerns with folks in907national security are very real and big, but as you know, this908is a problem for all Americans. I mean, I think most Americans909would be absolutely shocked if they knew what kind of digital910footprint they are leaving as they just go about their daily911life. And there are a lot of people, unfortunately, out there912with very nefarious intent that are not targeting just our913national security folks, although they are a primary target, no914question about it. They are targeting everybody, criminal915elements in particular. So this is something that we have to916get our arms around as a country, and it is only going to get917more concerning as AI continues to develop and the ability to918deal with all of the data that is out there.919 But before I get into data security, I would like to920discuss just briefly some work that I am doing with Senator921Ernst. With the creation of synthetic media, often by foreign922adversaries seeking to undermine our security, the ability to923verify information has become absolutely essential, I think you924would all agree, for public trust, for defense, and for925economic resilience. And while strong policies are necessary,926which you have raised, I think it was also mentioned by Mr.927Doyle, we also need technical tools. And certainly my idea as928well, working with Senator Ernst, is to provide tamper-evident929transparency for photos, for video, audio, text, all those930things that are out there.931 In the fiscal year 2024 NDAA, I authored section 1524,932requiring the DOD to pilot a digital nutrition label for media933that aids in understanding the origin of digital content, for934example, showing how it was made, by whom, and how it has been935altered over time. In this year's NDAA, we built on that936framework. Senator Ernst and I are co-leading legislation to937add Digital Content Providence Act to further advance those938efforts, so it is kind of all of these different approaches we939are going to have to take.940 But my first question is for you, Mr. Sherman, and Dr.941Kirschbaum. As a ranking member of the Senate Committee on942Homeland Security and Government Affairs, I recently released a943report that found that Department of Government Efficiency944(DOGE) is risking the sensitive data of all Americans at the945Social Security Administration. According to a whistleblower,946DOGE has copied Americans' sensitive Social Security data and947put it into a cloud data base, according to the whistleblower,948without any verified security controls in a cloud data base.949This data base includes the most sensitive information, as you950know, of not only all Americans, but all the military members,951national security personnel, as well as their family members.952 In fact, the Social Security Administration's own risk953assessment warned that there is a 65 percent risk of954catastrophic breach of this sensitive Social Security955information. That is, of course, if that information hasn't956already gone, and the whistleblowers say, we don't know. It is957hard to know whether or not that is already been breached. If958it has, the consequences are going to be extensive.959 So, Mr. Sherman, based on your expertise, is this the kind960of information in a data base that a foreign adversary like961Russia and China would just love to have?962 Mr. Sherman. Yes, thank you, Senator, and, of course, not963as in the weeds of the report as what you were saying, but,964yes, I will say two things, right? So one is we should always965operate on the assumption that any data anywhere is of interest966to adversaries, especially when it is aggregated in any kind of967way. The second thing is I think there are many lessons over968the last several years that we still maybe have not learned as969a country from the Office of Personnel Manaagment (OPM) breach,970right? Which is that, any time in particular, there is an971intense--and we can give examples across administrations, but972any particular concentration of the kind of data you are973talking about, again, that is going to be something a foreign974adversary is going to want to look at.975 Senator Peters. Yes, it is very, very important to make976sure that we have the safeguards. Just to put it on an977unsecured device is pretty scary. But maybe it will reassure978you that the individual who oversees this data base is a 19-979year-old man who was fired from his prior job for leaking data.980Does that bring any comfort to any of you that this is the guy981who is making sure that those foreign adversaries don't have982access to that information?983 Dr. Kirschbaum, could you describe the consequences if this984data were given or sold to an AI company that used this985information to train their models?986 Dr. Kirschbaum. Well, as Mr. Sherman was talking about, the987lessons from the OPM breach are pretty clear. I mean, any time988this data is out there and it is accessed by unauthorized989personnel, it is fuel. A lot of times we are--both in the990Department of Defense, based on our work, the response has been991reactive rather than proactive, and these are the kind of992things that we really stress with the Department because my993writ is looking at the Department of Defense. We stress just994leaning a little more forward, looking at what you ought to be995doing versus just plugging up holes because that is never going996to solve the problem.997 Senator Peters. Right. I am also deeply concerned by998reports that the DOD's recent $200 million contract with Elon999Musk's artificial intelligence AI company, xAI--this is the1000company's AI model that has a well-documented record of1001producing hate speech, including racist and antisemitic1002content. I am also concerned about the data risk for the social1003media company having access to DOD's most sensitive data on1004servicemembers as well as their families.1005 Mr. Sherman, what would be your top concerns about such a1006procurement in which a social media company could have access1007to DOD's sensitive data on servicemembers and their families?1008 Mr. Sherman. Yes, thank you, Senator, and I am not a1009content moderation expert, so I will speak to the data piece. I1010think this gets back to Senator Slotkin's question earlier,1011right, which is how do we think--I will make two points,1012right--at the strategic level about we want to make use of1013artificial intelligence or OSINT or take your pick at the same1014time as we are worried about security issues from it. I would1015say the answer is we can do both, right? Our adversaries would1016like to push this illusion that we can't have privacy and1017protection of data and successful competition, for example,1018right? So I would say that is the strategic point.1019 The policy point is I think this gets back to contracts,1020right? So any time any company is going through a DOD contract,1021especially if you are getting personnel data--and I have worked1022on legislation before in this area--you need to make sure there1023are the proper audits, security controls, other things in1024place, no matter what that company is, to understand what kinds1025of risks we are dealing with in that scenario.1026 Senator Peters. Madam Chairman, can I ask one more question1027if I have your indulgence?1028 Chairwoman Ernst. Yes, go ahead.1029 Senator Peters. Thank you.1030 Mr. Sherman, reports indicate that xAI is negotiating with1031foreign countries to build data centers. Such a partnership1032could allow the company to conduct operations in places, as you1033know, without core data protections and safeguards like we have1034here in the United States. So my question for you, what are the1035risks of xAI's work with a foreign country and the potential1036risk to the data of servicemembers and their families as they1037build out these data centers overseas?1038 Mr. Sherman. I would say, again, a set of criteria we can1039already apply, I would say, would be supply chain, right, and1040looking at, okay, much like we would look at who is putting the1041components in a connected vehicle that drives by a base. If we1042have a data center with data, we need to look at where is it1043based, what are the law enforcement laws in that country, what1044are the intelligence access capabilities in that country, which1045other companies have controls in that supply chain to access1046the data? Again, these are frameworks we have, but as1047mentioned, maybe with past breaches and so on, we haven't1048necessarily learned these lessons for the military yet.1049 Senator Peters. Many of those countries don't have any of1050those things.1051 Mr. Sherman. This is correct, yes. Many other countries do1052not have the kinds of democratic oversight we have over1053intelligence and military activities.1054 Senator Peters. Particularly potential adversaries1055especially don't have it.1056 Mr. Sherman. China, Russia, the like, yes.1057 Senator Peters. Great. Thank you.1058 Thank you, Madam Chair.1059 Chairwoman Ernst. Thank you.1060 Senator Kaine.1061 Senator Kaine. Thank you, Chair. It is a fascinating1062discussion. I want to ask a couple of questions that have been1063touched on, one about training and maybe I will start with one1064about the threat kind of universe.1065 When I came to the Senate in 2013, the discussions of1066adversaries' interest in our data was a little very focused on1067national security, data about intel officers, data about1068military, data about military operations. It seems like there1069has been an evolution during the time that I have been here1070that they are just interested in data on everything. Even if we1071don't know right now how we will use information about1072somebody's healthcare records or their Social Security or their1073consumer behavior, we just want to get it and have as clear a1074profile of every person as we can, and we will decide later how1075we are going to use it. Is that a fair, you know, kind of short1076form description? We have gone from real focus on national1077security-related data to just we want every bit of data we can1078get on everybody.1079 Mr. Doyle. If I may, Senator Kaine, I think that is a fair1080observation. I think as analytic capabilities and in particular1081as AI capabilities have advanced and made it tractable to1082leverage greater and greater quantities of data, then the1083interest in a broader set of data makes sense. In particular, I1084think it is interesting to think about if an adversary were1085focused on creating deepfakes and creating fraudulent content,1086the more composite data you can compile about the subject, the1087more convincing of a deepfake you can make, right? At least1088hypothetically you can imagine if I know which pharmacy you go1089to, that might be useful if I were to try to create a deepfake.1090 I think that underscores why it is so important to identify1091the primary sources and the most voluminous sources of that1092sort of data and take a really hard look at policy changes and1093technological solutions to help to cutoff or otherwise make1094unavailable the data. Of course, telecommunications is near and1095dear to my heart, but there are other examples as well.1096 Senator Kaine. There has even been instances in recent1097years of foreign connected purchases of American businesses1098where, say, a traditional purchase price that you might reach1099through like a capitalized earnings calculation, you see prices1100paid well in excess of that because a consumer business like a1101pharmacy chain or a grocery store chain not only has1102capitalized earnings that you can capitalize to come up with a1103purchase price, but they have a whole lot of data on their1104customer base. There is a premium that is being paid over what1105the actual profitability of the business is to be able to gain1106access to consumer data. That is starting to happen a lot.1107 Mr. Doyle. Absolutely, and you can see it across1108industries. When businesses figure out how to efficiently1109monetize their subscriber data or their customer data, it1110becomes an entire line of business unto itself, and it is1111exceptionally valuable. That is true in a truly commercial1112sense and, of course, true in a national security sense as1113well.1114 Senator Kaine. Let me ask a question about training for our1115military. This is an Armed Services hearing. That question went1116broader than armed services. Secretary Hegseth put out some1117directives last week, and we are still trying to get the1118details, but one was I think conceptually we should try to1119shrink the amount of mandatory training. You don't want to have1120overtraining on all kinds of stuff, and he said, look, training1121should be really focused on warfighting.1122 But this is an area where it strikes me some good training1123for people coming into the military about how to reduce a1124digital footprint that can be weaponized against you or1125weaponized against the American military would be a good thing.1126So I would like to hear about training, although, Mr. Doyle,1127you were a little bit skeptical and you said, you know,1128people's propensity to use their devices is such that training1129hasn't necessarily proven to be that effective in getting them1130to make the change. But, you know, for somebody entering into1131the military where they are going to have access to a lot of1132information that we would want to keep more, you know, close to1133the vest, what would your thoughts be for Armed Services1134Committee members about the kind of training we should be1135offering on this ubiquitous surveillance problem?1136 Mr. Stokes. Senator Kaine, thanks for the question. I will1137just throw out before Mr. Doyle that we recommend a1138comprehensive and cohesive strategy for UTS-based training. I1139think if you did this early within a servicemember's time1140within the Department, they would have the tools and1141capabilities to grow that as needed. Secretary Hegseth is1142right. You don't need to have weeks upon weeks of UTS-based1143training.1144 Senator Kaine. Yes.1145 Mr. Stokes. But I do think having a modicum of training at1146the beginning of their career and periodic throughout their1147career would be----1148 Senator Kaine. Maybe different levels of training----1149 Mr. Stokes. Hundred percent.1150 Senator Kaine.--depending on what your MOS would be. So1151everybody could get a base level right at the beginning, but1152then as you progress, depending upon what your position is, you1153might need----1154 Mr. Stokes. Absolutely.1155 Senator Kaine. Yes. Other thoughts on the training issue?1156 Dr. Kirschbaum. Yes, we have outstanding recommendations of1157the Department on this issue. As Senator Slotkin alluded to,1158warfare has changed. The information environment is very much1159like a domain amongst everything else. So we have had1160recommendations of the Department to look at how they train1161commanders and on down on how to deal with the information1162environment. It goes down to the unit level to some degree as1163well. And they have made some progress in seeing the value of1164those, but as I said, it is kind of diffuse.1165 We have examples of Air Force and Army units kind of1166assessing where they are in their own digital profile, but that1167needs to be expanded out writ large to the Department and1168beyond, apropos of your first question. But that is a lot of1169effort and a lot of prioritization and money to do that.1170 Senator Kaine. Can I continue a little bit, Senator Ernst?1171 Chairwoman Ernst. Certainly.1172 Senator Kaine. Dr. Hirschbaum, you said something, I think1173it was in response to a question maybe from Senator Slotkin1174where you had this paragraph that said the GAO really likes1175that they have done all these things right, but there is1176something that they are not yet doing right. Can you go back1177and say that to me again so I can understand it?1178 Dr. Kirschbaum. So if you read GAO reports, you will find a1179pattern. When we are looking for progress on something, whether1180it is implementation of a strategy, we are looking for several1181things. Who is supposed to do it? How do they know they are1182going to do it? What timelines are they working on? And how1183will they know they have achieved the ends they were trying to1184set out for? And those are all set out--in case you are having1185trouble sleeping at night, I can send you reports that will1186outline all this for you. Those are the kind of things we would1187like to see. Those are things that are guarantors of progress1188in some way, shape, or form.1189 Then, obviously, leadership. They have that structure in1190the defense security enterprise. If you look, it is people from1191the entire OSD, the Joint Staff services, they are all1192responsible in different ways. There are all these security1193disciplines. They have got that structure set out. It is a1194matter of applying the existing structure to this newer problem1195set.1196 As I said before, like the operations security people, they1197are more onboard, some of the other disciplines, not as much.1198Once they are more acclimated to caring about this, that1199existing structure will serve them well.1200 Senator Kaine. Okay, thank you, and then one last thing, if1201I could, just really more of a comment.1202 I am on the HELP Committee too--Health, Education, Labor,1203Pension--and I am sort of thinking about this discussion in1204light of, you know, what do we teach young people about digital1205footprint? On the HELP Committee, we also deal with abuses of1206elders on all kinds of scams that people fall victim to.1207Obviously, having more information about individuals makes your1208scamming much more likely to be successful because you can be1209really targeted in terms of going at somebody's known1210vulnerability.1211 So this is a hearing that has got my wheels turning not1212just on the Armed Services Committee but in thinking1213particularly on this training issue, you know, kind of thinking1214about the ways we need--we tell children don't accept candy1215from strangers or, you know, don't talk to somebody you don't1216know. I mean, we are trying to protect children's privacy. We1217always have. This is a new threat that I am not sure we are,1218you know--well, I know we are not as thoughtful yet as we1219should be about trying to equip people with an appropriate1220wariness about--I mean, a lot of good comes from this, but we1221are not doing a good job of necessarily teaching people to be1222skeptics, and I think we need to do more. So thank you for1223holding this hearing, Senator Ernst.1224 Chairwoman Ernst. Absolutely, and I do appreciate the1225conversation today. Rand had done a study not all that long ago1226of DOD personnel and found that only about 72 percent of those1227surveyed had actually had training about data brokerages, about1228their digital footprint. You are right, Senator Kaine, that1229there are so many other applications here not just in the DOD1230space but everywhere else across the United States.1231 I am curious. I am sure that many other countries have this1232same discussion. Are any of you aware of what maybe other1233allies or adversaries are doing in this space as well to1234protect their own citizens?1235 Mr. Sherman. I will offer two as an example. So one is I1236referenced the Department of Justice stood up a bulk data1237broker national security program, does not deal with certainly1238all of the issues we are talking about here but attempts to1239take a chunk out of it. The United Kingdom is now mimicking1240that program, essentially saying, okay, also we have lots of1241things going on in this area. This is one way we want to kind1242of take a swing at the problem.1243 The second is--and I preface this, we of course--this does1244not mean we should be replicating everything China is doing,1245but the Chinese Government in the last several years, for1246example, has greatly restricted the outbound transfer of1247genetic data on Chinese citizens, greatly restricted all kinds1248of ad tech and other things going on there. So if we think1249about it at the macro level, there are steps that some1250adversaries are taking. Russia has made dramatically less open-1251source information available to the West since the war. So1252there are ways our adversaries are trying to, you know,1253successfully or not at least knock this down a little bit. I1254think, again, that stands in contrast to really important work1255at the operational level but less at the strategic level in the1256U.S.1257 Chairwoman Ernst. Yes, Mr. Doyle.1258 Mr. Doyle. Thank you, Senator Ernst. I would build on that1259maybe in the more operational context and more in the national1260security context to say that in my observation, our allies take1261their cues heavily from the United States' leadership on this1262front, and so what I think that means for this committee is1263that investments or progress we can make on the technology1264front or on the policy front have, you know, obviously impact1265right here but also impact among our close allies.1266 Chairwoman Ernst. Wonderful. Thank you.1267 Yes. Yes, go ahead, Senator Kaine.1268 Senator Kaine. I am giving a talk with Senator Sheehy, and1269I need to walk out, but I am going to ask a question for the1270record and just to alert you to it. Is there anything in the1271regulation of data centers in the United States that could be1272done that could be sort of an upstream way of helping us deal1273with that challenge? There are all kinds of data center issues1274about, you know, the power demand and other things that are1275going on, and we wouldn't want to do regulation that would make1276data centers--you know, people would--we wouldn't want folks to1277say, well, we are not going to build in the United States, we1278are going to build elsewhere because we don't want to have a1279regulatory regime that is too constricting.1280 I will ask that question for the record, but just to alert1281you that it is coming. I would be curious to your thoughts on1282that.1283 Chairwoman Ernst. Yes, absolutely. Thank you.1284 We will go ahead and conclude today's hearing on the1285Emerging Threats and Capabilities Subcommittee and really1286appreciate the time and attention you have given to this.1287 Many of us are heavily invested. Senator Peters mentioned a1288bill that we are working on together, and it focuses a lot on1289the AI space and making sure that any digital images or1290products are authenticated. So we will continue working on1291that, but you have given us a lot of food for thought in many1292other areas.1293 So, again, thanks to our witnesses for taking the time1294today. We appreciate it.1295 With that, we will go ahead and close the hearing.1296 [Whereupon, at 3:27 p.m., the hearing was adjourned.]12971298 [all]