Skip to content

Security1 publisher3 min readPublished Updated

Courts Will Finally Count Government Hacking, But Only The Kind That Listens Live

Starting with the 2028 Wiretap Report, published in 2029, the judiciary will disclose how often judges approve hacking for real-time interception. Remote extraction of stored data stays uncounted.

The Watch · Security desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

Illustration accompanying Courts Will Finally Count Government Hacking, But Only The Kind That Listens Live
Generated illustration

What happened

  • The U.S. judiciary will begin publicly disclosing the number of times judges authorize the use of hacking tools and spyware for wiretaps, a category of surveillance known as network investigating techniques (NITs), according to a report by TechCrunch as summarized by SC World.
  • Starting with the 2028 Wiretap Report, which will be published in 2029, the judiciary will include data on NITs.
  • For nearly two decades, the Administrative Office of the U.S. Courts has published annual Wiretap Reports detailing authorized wiretaps.
  • Those annual Wiretap Reports have not specifically tracked the use of hacking tools and spyware.
  • The change comes after advocacy from Senator Ron Wyden, who has pushed for greater transparency in government surveillance.

Compiled by The WatchSomething wrong?How this is made

Why it matters

The federal judiciary will begin publishing the number of times judges authorize hacking tools and spyware for wiretaps, a category of surveillance the government calls network investigative techniques, or NITs, according to a TechCrunch report summarized by SC World [1]. The count will debut in the 2028 Wiretap Report, which is scheduled for publication in 2029 [2].

That is a durable change to a document that has been conspicuously silent on the subject. The Administrative Office of the U.S. Courts has published annual Wiretap Reports for nearly two decades [3], and those reports have never specifically tracked the use of hacking tools and spyware [4]. The change follows advocacy by Senator Ron Wyden, who has pushed for greater transparency in government surveillance [5]. The Electronic Frontier Foundation and the American Civil Liberties Union have called it a significant step toward accountability and better-informed policymaking, noting that other countries, including Italy, already publish comparable data [6].

Now the scope. The new statistics will cover the interception of real-time communications such as calls and messages [7]. They will not cover instances in which a device is remotely hacked to extract stored data [8]. That boundary does most of the work here: the published figure will be a lower bound on court-authorized government hacking rather than a total, because an entire technique family sits outside the count by design [1]. Anyone citing the 2028 number as "how often the government hacks" will be citing a subset and calling it a sum.

The reported description of the change is also thin on granularity. As described, it is a count of authorizations added to an existing report, with no indication of breakdowns by tool, vendor, agency, offense type, or outcome [9]. A single annual integer is more than zero, which is what exists today [4], but it will not tell an operator or a defense lawyer which exploit chains a magistrate found reasonable, or whether the same warrant covered one device or a thousand.

There is also a timing cost. Because the first NIT data covers calendar year 2028 and appears in 2029, the public sees the figures roughly a year after the conduct they describe [2]. And because the series has never included NITs [4], the first figure will arrive with no prior-year comparator, so trend analysis cannot begin until the 2029 report lands [3].

What to watch: whether the 2029 publication actually contains the promised NIT line, since the commitment is currently a plan rather than a published table [2]; whether Wyden or the advocacy groups that welcomed the change [5][6] press to extend counting to remote extraction of stored data [8]; and whether the eventual format includes any breakdown beyond a raw authorization count [9]. The transparency win is real and hard to reverse once it is in the report. The measurement gap is equally durable.

Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories