Security1 distinct publisher3 min readUpdated
Starting with the 2028 Wiretap Report, published in 2029, the judiciary will disclose how often judges approve hacking for real-time interception. Remote extraction of stored data stays uncounted.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
The federal judiciary will begin publishing the number of times judges authorize hacking tools and spyware for wiretaps, a category of surveillance the government calls network investigative techniques, or NITs, according to a TechCrunch report summarized by SC World [1]. The count will debut in the 2028 Wiretap Report, which is scheduled for publication in 2029 [2].
That is a durable change to a document that has been conspicuously silent on the subject. The Administrative Office of the U.S. Courts has published annual Wiretap Reports for nearly two decades [3], and those reports have never specifically tracked the use of hacking tools and spyware [4]. The change follows advocacy by Senator Ron Wyden, who has pushed for greater transparency in government surveillance [5]. The Electronic Frontier Foundation and the American Civil Liberties Union have called it a significant step toward accountability and better-informed policymaking, noting that other countries, including Italy, already publish comparable data [6].
Now the scope. The new statistics will cover the interception of real-time communications such as calls and messages [7]. They will not cover instances in which a device is remotely hacked to extract stored data [8]. That boundary does most of the work here: the published figure will be a lower bound on court-authorized government hacking rather than a total, because an entire technique family sits outside the count by design [1]. Anyone citing the 2028 number as "how often the government hacks" will be citing a subset and calling it a sum.
The reported description of the change is also thin on granularity. As described, it is a count of authorizations added to an existing report, with no indication of breakdowns by tool, vendor, agency, offense type, or outcome [9]. A single annual integer is more than zero, which is what exists today [4], but it will not tell an operator or a defense lawyer which exploit chains a magistrate found reasonable, or whether the same warrant covered one device or a thousand.
There is also a timing cost. Because the first NIT data covers calendar year 2028 and appears in 2029, the public sees the figures roughly a year after the conduct they describe [2]. And because the series has never included NITs [4], the first figure will arrive with no prior-year comparator, so trend analysis cannot begin until the 2029 report lands [3].
What to watch: whether the 2029 publication actually contains the promised NIT line, since the commitment is currently a plan rather than a published table [2]; whether Wyden or the advocacy groups that welcomed the change [5][6] press to extend counting to remote extraction of stored data [8]; and whether the eventual format includes any breakdown beyond a raw authorization count [9]. The transparency win is real and hard to reverse once it is in the report. The measurement gap is equally durable.
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
The U.S. judiciary will begin publicly disclosing the number of times judges authorize the use of hacking tools and spyware for wiretaps, a category of surveillance known as network investigating techniques (NITs), according to a report by TechCrunch as summarized by SC World.
Starting with the 2028 Wiretap Report, which will be published in 2029, the judiciary will include data on NITs.
For nearly two decades, the Administrative Office of the U.S. Courts has published annual Wiretap Reports detailing authorized wiretaps.
Those annual Wiretap Reports have not specifically tracked the use of hacking tools and spyware.
The change comes after advocacy from Senator Ron Wyden, who has pushed for greater transparency in government surveillance.
Privacy advocates including the Electronic Frontier Foundation and the American Civil Liberties Union have hailed the change as a significant step toward accountability and informed policy-making regarding government hacking, noting that other countries such as Italy already provide similar data.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Single secondary brief, no primary document
All claims rest on one short trade brief that itself attributes the reporting to TechCrunch. No Administrative Office of the U.S. Courts notice, policy text, or judiciary statement is supplied, and there is no second independent publisher in the cluster. The core facts are internally consistent and specific (reporting year, publication year, scope boundary), which lifts the score above the floor, but nothing is corroborated.
Nothing published yet
Adoption cannot be measured: the disclosure regime does not produce output until the 2028 Wiretap Report is published in 2029, and the supplied source reports no interim implementation, pilot, or data release. No usage, deployment, or uptake facts are present to score.
Mildly overstated by the accountability framing
The framing of a 'significant step towards accountability' runs modestly ahead of what the supplied facts deliver: a first count arrives only in 2029, covers real-time interception only, omits remote extraction of stored data, has no baseline for trend analysis, and is not described as broken down by tool, vendor, or agency. The overstatement is mild rather than severe because the source does report the scope carve-out plainly rather than hiding it.
Visible advocacy and aggregation incentives
The supplied source names interested parties whose incentives shape the framing: a sitting senator who campaigned for the change and two advocacy organizations that benefit from portraying it as a win. The publisher is a security trade outlet republishing another outlet's scoop, which favors clean positive framing over scrutiny of the disclosure's limits. No countervailing voice from the judiciary, law enforcement, or tooling vendors appears, so only one side's incentives are observable.
Moderate-low
The factual spine is coherent and specific, and the derived conclusions follow directly from the source's own scope statement, which supports moderate confidence in what is claimed. Confidence is held down by single-source, single-publisher dependence on a secondary summary, the absence of any primary judiciary document, no measurable adoption, and no described detail about the contents of the future disclosure.
product
US courts turn government hacking into a line item, starting with 2028 wiretap data1 distinct publisher
invest
Tiny corp wants Etched's numbers. Jane Street led $700M at $21B without publishing any1 distinct publisher
invest
The carried-interest fight is worth $16.3 billion, which is to say almost nothing1 distinct publisher
build
Vivodyne is spending venture money on wet-lab throughput, not bigger models2 distinct publishers
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 14, 2026