Product1 distinct publisher3 min readUpdated
The Administrative Office of the US Courts will add a "spyware/hacking" category to its annual Wiretap Report, creating a countable public figure where there has never been one.
The Product Desk · Product desk

Compiled by The Product DeskSomething wrong?How this is made
Follow any of these and your For You feed starts watching them — no settings page required.
The Administrative Office of the US Courts has told Democratic senator Ron Wyden that it will begin tracking a new "spyware/hacking" category starting with the 2028 Wiretap Report, published the following year [3]. From 2029, that produces a public count of how often judges authorized a wiretap to be executed using hacking tools, a method the government files under network investigative techniques, or NITs [2].
The practice is not new; the counting is. The FBI has used hacking techniques and tools, including spyware, since at least 1998, and to date no public data has counted how often [1]. Calendar 2028 is the first year that will be tallied, thirty years after the documented start of the practice [16].
The vehicle is what makes this durable. For almost two decades the Administrative Office has published annual Wiretap Reports that break authorizations down by whether a federal or state judge signed them, by state, and by type of crime investigated [4], and by tap type: audio, oral, and electronic [6]. Adding a category turns the method into a field on a form rather than a subject of litigation and inference. It also explains the lag. An Administrative Office spokesperson told TechCrunch that the report is compiled from individual forms submitted across the country throughout the year, and that "reporting forms and procedures need to be updated to accommodate the new categories" before the data can appear [5]. The change was disclosed in August 2026; the first number lands three annual cycles later [17].
Read the scope carefully, because it is narrower than "government hacking". The statistic will cover spyware used to intercept communications in real time, including Signal and WhatsApp calls and messages, and not tools used to remotely break into a phone and extract stored images, files, or location data. The first is a wiretap; the second is a search under a different legal process and is not covered [9]. Wiretaps also start from a small base: they require a higher evidentiary showing than a search warrant and are issued in far fewer numbers [7]. Reach is another matter. Years ago, a single wiretap supported an operation that collected millions of text messages over three months [8].
Eva Galperin, director of cybersecurity at the Electronic Frontier Foundation, said that "up until now, we have only been able to guess at the size of the problem" [13], and that a published figure makes denial harder: "It is hard to say that you are using spyware as a surgical tool when you have deployed it tens of thousands of times" [14]. That argument runs both directions. A low first-year count will be cited as proof of restraint, and there will be no back series to test it against.
Wyden, who has criticized "the unnecessary secrecy around electronic surveillance orders" and has pushed for this data since 2017, twelve years before it will be published [10][18], welcomed the move and said Congress must still pass his Government Surveillance Transparency Act [11], a draft bill he and others reintroduced earlier this year [12]. ACLU senior counsel Brett Max Kaufman also called the change important [15].
Watch the form design rather than the announcement: whether NIT authorizations are split federal versus state, as wiretaps already are [4]; whether "spyware/hacking" is one checkbox or is crossed with audio, oral, and electronic tap types [6]; and whether device searches, which stay uncounted, become the next gap someone has to legislate [9].
Ranked by verification strength, evidence, and original report placement.
The FBI has been using hacking techniques and tools, such as spyware, since at least 1998, but to date there is no public data counting how often the feds were deploying them.
Starting in 2029, the US judiciary will publicly disclose how many times judges authorized wiretaps to be carried out with hacking tools and spyware, which fall under the category the feds call network investigating techniques, or NITs.
The Administrative Office of the US Courts told Democratic senator Ron Wyden this week that it will begin tracking the new "spyware/hacking" surveillance category starting in the 2028 Wiretap Report, which will be published the following year. TechCrunch reported this on August 14, 2026.
Eva Galperin, director of cybersecurity at the Electronic Frontier Foundation and an expert on government spyware, said: "Up until now, we have only been able to guess at the size of the problem."
For almost two decades the Administrative Office of the US Courts has issued annual Wiretap Reports detailing how many wiretaps were authorized each year, broken down by whether federal or state judges ordered them, in which states the wiretaps were conducted, what type of crime was investigated, and other data.
The annual wiretap reports break down the type of wiretaps authorized: audio wiretaps collecting real-time voice from phone calls; oral taps relying on real-world microphones and other eavesdropping techniques; and electronic tapping of text messages, emails and other messages as they pass through a provider's network.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Primary confirmation, single publisher, no published document
The core claim is confirmed on record by an Administrative Office of the US Courts spokesperson in an email to the reporting outlet, and reinforced by named, attributable reaction from Wyden, EFF and the ACLU. Against that, the cluster has one publisher, no copy of the AO's letter to Wyden or of the revised reporting forms, and no independent corroboration of the 2028 start date, so the record is credible but thin and entirely reliant on one account.
Committed, not yet implemented
Adoption of the transparency measure is at the commitment stage only: the AO has agreed to track the category, but by its own statement the reporting forms and procedures still need updating, collection covers calendar year 2028, and the first figures do not publish until 2029. No US data has been gathered or released, and the only concrete published spyware statistic in the cluster comes from Italy rather than the US judiciary.
Mildly overstated relative to a 2029 payoff
The substantive change is real and confirmed, but framing around a transparency 'win' runs ahead of delivery: nothing is counted until calendar year 2028, nothing publishes until 2029, and the reporting forms that make it possible do not exist yet. The reporting itself limits the overstatement by explicitly flagging that only interception is captured while remote device searches are not, and by carrying Wyden's own caveat that legislation is still needed — so the gap is modest rather than large.
Advocacy and legislative interests are visible and disclosed
The sourcing is dominated by parties with declared stakes in the outcome: Senator Wyden uses the news to press his reintroduced Government Surveillance Transparency Act, and EFF and ACLU representatives are advocacy voices whose case is strengthened by a public count. Their affiliations and aims are clearly disclosed, and the court administrator's confirmation is a neutral procedural statement, so the incentives are legible rather than hidden — but no agency or vendor counterweight appears in the cluster.
Solid on the announcement, weak on outcome
Confidence is high that the commitment was made as described, given the on-record spokesperson confirmation and named political and advocacy reaction. Confidence is much lower on what the change will yield: the count depends on form and procedure updates yet to be completed, will exclude device-search hacking, and no figure exists to validate against. One publisher and no primary documents cap the ceiling.
security
Courts Will Finally Count Government Hacking, But Only The Kind That Listens Live1 distinct publisher
invest
Tiny corp wants Etched's numbers. Jane Street led $700M at $21B without publishing any1 distinct publisher
security
A North Korean IT worker got hired by a federal agency. Vetting is a security control now.1 distinct publisher
invest
Washington licenses private hacking, and hands the contractor the liability1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 14, 2026