Sen. Ron Wyden Says Older VPNs Have Become a Target for Hackers. Here's Why

Sen. Ron Wyden is urging federal agencies to replace aging, internet-facing VPN systems with zero-trust technology after years of damaging cyberattacks.
We receive compensation from the products and services mentioned in this story, but the opinions are the author's own. Compensation may impact where offers appear. We have not included all available products or offers. Learn more about how we make money and our editorial policies.

In a letter sent Monday to leaders at the Office of Management and Budget (OMB), the Cybersecurity and Infrastructure Security Agency (CISA), and the National Institute of Standards and Technology (NIST), Wyden called for a government-wide transition away from "legacy, insecure, internet-facing" VPNs in favor of newer "zero trust" remote access technologies.[1]

"For too long, federal agencies and government contractors have suffered devastating cyberattacks due to their reliance on legacy, insecure, internet-facing VPN servers to grant employees remote access," Wyden wrote.

The Oregon Democrat cited a string of high-profile attacks targeting enterprise networking products, including Cisco, Fortinet, Ivanti, and Check Point devices, and argued that continually patching vulnerable systems is no longer enough.

"The federal government has become trapped in an endless game of 'whack-a-mole' in responding to widespread compromises of legacy remote access technologies," Wyden wrote.

In this article
What is Wyden proposing?
Does this mean consumer VPNs are insecure?
Zero trust isn't a silver bullet
Should you ditch your VPN?

What is Wyden proposing?

Wyden is asking federal cybersecurity agencies to require departments to phase out legacy remote-access infrastructure over the next two years and replace it with zero trust architecture, a security model that continuously verifies users and devices rather than assuming anyone inside a network can be trusted.

He argues that traditional enterprise VPNs create a visible entry point for attackers because they're designed to accept connections from the public internet.

"Legacy remote-access technologies operate a digital 'front door' that is accessible to the public internet so that mobile devices and remote employees can log in," Wyden wrote. "Because these entry points are exposed, hackers can easily scan, target, and break into them."

By contrast, Wyden says modern remote-access systems don't advertise their presence online.

"Instead of leaving an open door accessible from the public internet, modern solutions provide remote access without broadcasting their presence," he wrote. "This effectively makes these servers invisible, ensuring that hackers cannot attack an entry point they cannot see."

Does this mean consumer VPNs are insecure?

Not necessarily.

The VPNs discussed in Wyden's letter are the enterprise systems organizations use to let employees remotely access internal company networks. These typically rely on dedicated VPN appliances positioned at the edge of an organization's network that accept inbound internet connections.

That's different from the consumer VPN services many people use to encrypt internet traffic on public Wi-Fi, reduce tracking, or help protect their privacy online.

The Congressional Research Service memo attached to Wyden's letter specifically defines enterprise VPNs as systems that place a publicly accessible VPN gateway between an organization's private network and the internet, allowing authenticated users broad access once they're connected.

On the other hand, zero trust systems are designed to grant access only to specific applications and continuously verify users throughout a session. They also avoid exposing publicly accessible login gateways whenever possible.

Zero trust isn't a silver bullet

While Wyden argues zero trust architecture addresses many of the weaknesses of older VPN infrastructure, the attached Congressional Research Service analysis notes that zero trust systems have security considerations of their own.

For example, compromising the centralized policy engine that makes access decisions could allow attackers to grant unauthorized access or block legitimate users, particularly if organizations rely heavily on cloud-based providers.

Still, Wyden says it's time for the federal government to move beyond decades-old remote-access technology.

"It is no longer acceptable for agencies to use insecure, decades-old technology," he wrote.

Should you ditch your VPN?

No. Wyden’s proposal targets enterprise VPN systems that businesses and governments use for remote access, not the apps most consumers are using daily.

That said, there are a few steps worth taking to improve your own security:

  • Keep your devices and apps updated. Many of the attacks cited in Wyden's letter exploited known vulnerabilities in enterprise software that organizations hadn't fully addressed.
  • Use multi-factor authentication (MFA) whenever possible. Even if a password is compromised, MFA adds another layer of protection that can make it much harder for attackers to access your accounts.
  • Choose a reputable VPN if you use one. If you rely on a VPN to secure your connection on public Wi-Fi or protect your online privacy, stick with a provider that regularly updates its software, publishes security information, and supports modern encryption standards.
  • Be cautious of misleading headlines. News that governments are moving away from certain VPN technologies doesn't mean all VPNs are unsafe.

As organizations continue shifting toward zero-trust security models, consumers can expect businesses to increasingly rely on identity verification, device checks, and continuous authentication behind the scenes.

#1 Rated VPN for Privacy and Security
5.0
Editorial Rating
Get Deal
On NordVPN's website
2026 Editors’ Choice
Best Overall VPN
VPN
NordVPN
PROMOTION: Get 75% + 3 Months Free
  • Our #1 rated VPN, which has increased download speeds by up to 36% across all regions in our testing
  • Historically unlocks Netflix libraries in the US, Canada, UK, and Australia with no errors
  • Bundles with ad blocker, data removal, and encrypted storage for a more complete privacy setup

Author Details
Thomas Kent is a multi-disciplined reporter with over a decade of experience covering online platforms, digital trends, and consumer-facing tech. Tom focuses on digital privacy, data tracking, and user behavior, with a particular interest in how cookies, online surveillance, and platform design shape the modern internet experience. His reporting takes a research-driven, news-focused approach, translating complex technical topics into clear, accessible insights.

Citations

[1] Ron Wyden Missive