Federal Courts to Track Government Spyware Deployments for First Time
New transparency rule will reveal how often U.S. law enforcement uses hacking tools to intercept real-time communications, filling a two-decade data gap

A Long-Overdue Window Into Surveillance
The FBI has deployed hacking tools and spyware since at least 1998, yet no public accounting exists for how frequently these capabilities are used. That opacity ends in three years. The Administrative Office of the U.S. Courts announced this week it will begin tracking a new surveillance category - spyware and hacking tools used to intercept communications - in its 2028 Wiretap Report, set for publication in 2029.
The change addresses a transparency gap that has persisted for nearly two decades. While the judiciary has issued annual Wiretap Reports breaking down traditional interception orders by jurisdiction, crime type, and method, network investigative techniques have remained invisible in those statistics. Now, judges who authorize the use of these tools to tap real-time communications will generate data that flows into the public record.
The distinction matters: this new metric will capture only spyware deployed to intercept live calls and messages - Signal conversations, WhatsApp exchanges, and similar encrypted traffic. It will not count instances where authorities remotely breach a device to extract stored data like photos, files, or location history. The former constitutes a wiretap under U.S. law; the latter falls under search warrant procedures, which follow separate legal and reporting pathways.
The Legal Threshold for Digital Intrusion
Wiretaps occupy a narrow but powerful position in American surveillance law. To obtain one, law enforcement must clear a higher evidentiary bar than for standard search warrants, demonstrating to a judge that a crime is underway and that interception is necessary. This elevated standard reflects the invasive nature of real-time monitoring - a single authorization can sweep up months of communications from multiple parties.
One wiretap operation several years ago collected millions of text messages over three months, illustrating the scale these orders can reach. The existing Wiretap Reports enumerate audio taps capturing voice calls, oral surveillance using physical microphones, and electronic interception of texts and emails passing through provider infrastructure. The forthcoming spyware category will slot into this framework, revealing when authorities bypass traditional provider cooperation by hacking directly into endpoints.
According to a judiciary spokesperson, reporting forms and procedures require updating before the new data can appear. Individual forms submitted throughout the year from courts nationwide will now include fields for spyware-enabled wiretaps, ensuring the statistics reflect actual deployment patterns rather than aggregate estimates.
Policy Pressure and the Transparency Deficit
Senator Ron Wyden has pressed for this kind of disclosure since 2017, arguing that Americans remain largely unaware of the government's full surveillance toolkit. The Administrative Office's decision to add the tracking category came in response to Wyden's inquiries, though the senator emphasized that legislative action remains necessary. His Government Surveillance Transparency Act, reintroduced earlier this year, seeks broader reporting requirements across multiple surveillance authorities.
Privacy advocates view the change as a significant step. Eva Galperin, director of cybersecurity at the Electronic Frontier Foundation, noted that until now, assessing the scope of government spyware use has been a matter of guesswork. Public statistics will make it harder for authorities to downplay the prevalence of these techniques, particularly if the numbers prove substantial. When officials characterize spyware as a surgical instrument reserved for exceptional cases, deployment figures in the tens of thousands would undermine that narrative.
Brett Max Kaufman, senior counsel at the American Civil Liberties Union's Center for Democracy, called the move an important and overdue transparency measure that should inform better policy and legal frameworks around government hacking. The current secrecy around electronic surveillance orders, he argued, has left policymakers and the public operating with incomplete information.
International Context and the Road Ahead
Other jurisdictions already publish detailed spyware statistics. Italy, for instance, disclosed that authorities deployed spyware against 4,321 targets in 2023. Those figures provide a benchmark for assessing proportionality and abuse, allowing civil society and lawmakers to evaluate whether surveillance practices align with stated policy goals.
The U.S. has lagged in this area, despite the FBI's decades-long use of network investigative techniques. The 2029 publication will mark the first time the American public can see how frequently judges authorize these tools, broken down by jurisdiction and, potentially, by the types of investigations they support.
At DailyTechWire, we've tracked the expansion of government hacking capabilities across multiple jurisdictions, from export-controlled exploit vendors to law enforcement procurement patterns. The new reporting requirement offers a rare instance where policy catches up with practice, turning a shadowy operational capability into a quantifiable, debatable element of surveillance policy.
The three-year lead time before publication reflects the administrative complexity of updating court reporting systems nationwide. By 2029, researchers, advocates, and lawmakers will have hard numbers to weigh against claims of restrained, targeted use. Whether those figures reveal a scalpel or a sledgehammer will shape the next phase of the debate over government hacking - and whether existing legal standards adequately constrain a technology that has outpaced the statutes meant to govern it.


