Skip to content

Product1 publisher3 min readPublished

US courts turn government hacking into a line item, starting with 2028 wiretap data

The Administrative Office of the US Courts will add a "spyware/hacking" category to its annual Wiretap Report, creating a countable public figure where there has never been one.

The Product Desk · Product desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

Illustration accompanying US courts turn government hacking into a line item, starting with 2028 wiretap data
Generated illustration

What happened

  • The FBI has been using hacking techniques and tools, such as spyware, since at least 1998, but to date there is no public data counting how often the feds were deploying them.
  • Starting in 2029, the US judiciary will publicly disclose how many times judges authorized wiretaps to be carried out with hacking tools and spyware, which fall under the category the feds call network investigating techniques, or NITs.
  • The Administrative Office of the US Courts told Democratic senator Ron Wyden this week that it will begin tracking the new "spyware/hacking" surveillance category starting in the 2028 Wiretap Report, which will be published the following year. TechCrunch reported this on August 14, 2026.
  • For almost two decades the Administrative Office of the US Courts has issued annual Wiretap Reports detailing how many wiretaps were authorized each year, broken down by whether federal or state judges ordered them, in which states the wiretaps were conducted, what type of crime was investigated, and other data.
  • An Administrative Office of the US Courts spokesperson told TechCrunch: "The Wiretap Report is compiled from individual forms submitted from throughout the country and throughout the year. Before the new data can appear in the annual report, reporting forms and procedures need to be updated to accommodate the new categories."

Compiled by The Product DeskSomething wrong?How this is made

Why it matters

The Administrative Office of the US Courts has told Democratic senator Ron Wyden that it will begin tracking a new "spyware/hacking" category starting with the 2028 Wiretap Report, published the following year [3]. From 2029, that produces a public count of how often judges authorized a wiretap to be executed using hacking tools, a method the government files under network investigative techniques, or NITs [2].

The practice is not new; the counting is. The FBI has used hacking techniques and tools, including spyware, since at least 1998, and to date no public data has counted how often [1]. Calendar 2028 is the first year that will be tallied, thirty years after the documented start of the practice [16].

The vehicle is what makes this durable. For almost two decades the Administrative Office has published annual Wiretap Reports that break authorizations down by whether a federal or state judge signed them, by state, and by type of crime investigated [4], and by tap type: audio, oral, and electronic [6]. Adding a category turns the method into a field on a form rather than a subject of litigation and inference. It also explains the lag. An Administrative Office spokesperson told TechCrunch that the report is compiled from individual forms submitted across the country throughout the year, and that "reporting forms and procedures need to be updated to accommodate the new categories" before the data can appear [5]. The change was disclosed in August 2026; the first number lands three annual cycles later [17].

Read the scope carefully, because it is narrower than "government hacking". The statistic will cover spyware used to intercept communications in real time, including Signal and WhatsApp calls and messages, and not tools used to remotely break into a phone and extract stored images, files, or location data. The first is a wiretap; the second is a search under a different legal process and is not covered [9]. Wiretaps also start from a small base: they require a higher evidentiary showing than a search warrant and are issued in far fewer numbers [7]. Reach is another matter. Years ago, a single wiretap supported an operation that collected millions of text messages over three months [8].

Eva Galperin, director of cybersecurity at the Electronic Frontier Foundation, said that "up until now, we have only been able to guess at the size of the problem" [13], and that a published figure makes denial harder: "It is hard to say that you are using spyware as a surgical tool when you have deployed it tens of thousands of times" [14]. That argument runs both directions. A low first-year count will be cited as proof of restraint, and there will be no back series to test it against.

Wyden, who has criticized "the unnecessary secrecy around electronic surveillance orders" and has pushed for this data since 2017, twelve years before it will be published [10][18], welcomed the move and said Congress must still pass his Government Surveillance Transparency Act [11], a draft bill he and others reintroduced earlier this year [12]. ACLU senior counsel Brett Max Kaufman also called the change important [15].

Watch the form design rather than the announcement: whether NIT authorizations are split federal versus state, as wiretaps already are [4]; whether "spyware/hacking" is one checkbox or is crossed with audio, oral, and electronic tap types [6]; and whether device searches, which stay uncounted, become the next gap someone has to legislate [9].

Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories