Technology

Federal Courts Will Start Reporting Government Spyware Use — Starting in 2028

Martin HollowayPublished 11h ago5 min readBased on 13 sources
Reading level
Federal Courts Will Start Reporting Government Spyware Use — Starting in 2028
Photo by U.S. Senate Photographic Studio / Public domain

The Administrative Office of the U.S. Courts will begin publicly disclosing how often federal judges authorize the use of spyware and hacking tools for wiretaps, with the first data set to appear in the 2028 Wiretap Report, published the following year. A spokesperson for the Administrative Office confirmed the change in an email to TechCrunch on August 14, 2026.

The new category, described internally as "spyware/hacking" surveillance, will track instances where authorities deploy what the government calls network investigating techniques, or NITs — essentially, tools that let law enforcement hack into a target's device or network to intercept communications in real time. Senator Ron Wyden, an Oregon Democrat who has called for this kind of data to be published since 2017, was notified of the change by the Administrative Office. Wyden has pressed for transparency on government hacking of Americans' devices for nearly a decade.

The Administrative Office has issued annual Wiretap Reports for almost two decades, detailing how many wiretaps were authorized each year. Those reports break down authorized wiretaps by type: audio wiretaps, oral taps, and electronic interception of text messages, emails, and other messages passing through a provider's network. Until now, no public data has counted how often federal authorities deploy hacking techniques and tools such as spyware, despite the FBI using such methods since at least 1998.

The scope of the forthcoming disclosure has a defined boundary. The new spyware statistic will cover instances where authorities used spyware to intercept communications, such as Signal and WhatsApp calls and messages. It will not capture cases where tools were used to remotely hack into a phone and extract stored data such as images, files, and location information. That distinction matters because it leaves a substantial category of government hacking — data extraction from compromised devices — outside the public accounting.

Wiretaps require a high bar of evidence before a judge authorizes a live tap, allowing police to gain real-time access to calls, messages, and other communications. Attorneys at the Department of Justice's Office of Enforcement Operations review each wiretap application before it is submitted to a court. Federal appellate courts have long treated denials of orders under the Wiretap Act as appealable final orders. The legal framework is well established; the novelty is that a specific surveillance method within that framework will now receive its own line item in public reporting.

The statutory definitions themselves have not been uniformly settled. At least one federal trial court found that keystroke monitoring by spyware is not "electronic communication" as defined at 18 U.S.C. — the section of federal law that governs wiretap and electronic surveillance rules. That ruling shows how the interaction between novel surveillance techniques and statutory language can produce outcomes that the public, and even practitioners, might not anticipate.

Federal and state courts reported a combined 24 percent decrease in authorized wiretaps in 2025 compared with 2024, according to the Judiciary's 2025 Wiretap Report. The overall volume of wiretap authorizations is declining even as the government prepares to begin separately tracking the spyware subset.

The announcement also arrives against a backdrop of security concerns surrounding the federal judiciary's own systems. In August 2025, U.S. federal courts disclosed that their systems were targeted by cyberattacks, and the federal judiciary's electronic case filing system was breached in what was described as a sweeping hack believed to have exposed sensitive information. The U.S. government has taken unspecified "special measures" to protect people potentially exposed in that breach. A separate cyber breach involving the federal court records management system was investigated by the Justice Department in 2022.

The two threads are not directly connected: the wiretap reporting change is a policy decision driven by legislative pressure, while the court system breaches are security incidents. But the juxtaposition is unavoidable for anyone tracking the judiciary's handling of sensitive digital information. The courts are preparing to disclose more about government surveillance at a time when their own digital infrastructure has shown material vulnerabilities.

The gap between the 2026 announcement and the 2028 data collection, with publication in 2029, means that several years of spyware deployments will continue to occur without public accounting. For technologists and civil liberties advocates who have sought this data, the timeline is the price of the concession. For the judiciary, it provides lead time to establish tracking methodologies for a surveillance category that intersects with classified tools and techniques.

The broader context here is one of incremental progress in an area where secrecy has long been the default. The new reporting category fills a gap that has persisted for nearly three decades — a stretch during which the government quietly expanded its hacking capabilities without any corresponding public record of how often those tools were deployed. Whether the disclosure will extend beyond the interception of communications to encompass the broader range of government hacking techniques is an open question, and one that Wyden and other transparency advocates are likely to continue pressing.