US Courts Will Begin Publishing Government Spyware and Hacking Wiretap Statistics

The Administrative Office of the U.S. Courts will begin publicly disclosing how often federal judges authorize the use of spyware and hacking tools for wiretaps, with the first data set to appear in the 2028 Wiretap Report, published the following year. The change was confirmed by a spokesperson for the Administrative Office in an email to TechCrunch on August 14, 2026.
The new category, described internally as "spyware/hacking" surveillance, will track instances where authorities deploy what the government calls network investigating techniques, or NITs, to intercept communications. Senator Ron Wyden, who has criticized "the unnecessary secrecy around electronic surveillance orders" and has called for this kind of data to be published since 2017, was notified of the change by the Administrative Office. The Oregon Democrat has pressed for transparency on government hacking of Americans' devices for nearly a decade.
The Administrative Office has issued annual Wiretap Reports for almost two decades, detailing how many wiretaps were authorized each year. Those reports break down authorized wiretaps by type: audio wiretaps, oral taps, and electronic interception of text messages, emails, and other messages passing through a provider's network. To date, no public data has counted how often federal authorities deploy hacking techniques and tools such as spyware, despite the FBI using such methods since at least 1998.
The scope of the forthcoming disclosure has a defined boundary. The new spyware statistic will cover instances where authorities used spyware to intercept communications, such as Signal and WhatsApp calls and messages. It will not capture cases where tools were used to remotely hack into a phone and extract stored data such as images, files, and location information. That distinction matters because it leaves a substantial category of government hacking, data extraction from compromised devices, outside the public accounting.
Wiretaps require a high bar of evidence before a judge authorizes a live tap, allowing police to gain real-time access to calls, messages, and other communications. Attorneys at the Department of Justice's Office of Enforcement Operations review each wiretap application before it is submitted to a court. Federal appellate courts have long treated denials of orders under the Wiretap Act as appealable final orders. The legal framework is well established; the novelty is that a specific surveillance modality within that framework will now receive its own line item in public reporting.
The statutory definitions themselves have not been uniformly settled. At least one federal trial court found that keystroke monitoring by spyware is not "electronic communication" as defined at 18 U.S.C., a ruling that underscores how the interaction between novel surveillance techniques and statutory language can produce outcomes that the public, and even practitioners, might not anticipate.
Federal and state courts reported a combined 24 percent decrease in authorized wiretaps in 2025 compared with 2024, according to the Judiciary's 2025 Wiretap Report. The overall volume of wiretap authorizations is declining even as the government prepares to begin separately tracking the spyware subset.
The announcement also arrives against a backdrop of security concerns surrounding the federal judiciary's own systems. In August 2025, U.S. federal courts disclosed that their systems were targeted by cyberattacks, and the federal judiciary's electronic case filing system was breached in what was described as a sweeping hack believed to have exposed sensitive information. The U.S. government has taken unspecified "special measures" to protect people potentially exposed in that breach. A separate cyber breach involving the federal court records management system was investigated by the Justice Department in 2022.
The two threads are not directly connected: the wiretap reporting change is a policy decision driven by legislative pressure, while the court system breaches are security incidents. But the juxtaposition is unavoidable for anyone tracking the judiciary's handling of sensitive digital information. The courts are preparing to disclose more about government surveillance at a time when their own digital infrastructure has demonstrated material vulnerabilities.
The gap between the 2026 announcement and the 2028 data collection, with publication in 2029, means that several years of spyware deployments will continue to occur without public accounting. For technologists and civil liberties advocates who have sought this data, the timeline is the price of the concession. For the judiciary, it provides lead time to establish tracking methodologies for a surveillance category that intersects with classified tools and techniques.
Looking at what this means for the surveillance transparency landscape, the new reporting category fills a gap that has persisted for nearly three decades. Whether the disclosure will extend beyond the interception of communications to encompass the broader range of government hacking techniques remains an open question, and one that Wyden and other transparency advocates are likely to continue pressing.


