U.S. Courts to Expose Scale of Government Spyware Deployments

Federal judges have quietly authorized the government to deploy spyware and network hacking tools for years. Now the numbers will come to light.
Starting with data from 2028, the annual Wiretap Report will include a new category for these operations. Publication follows in 2029. The change marks the first time the public will see standardized figures on how often courts sign off on such invasive surveillance. The shift promises to reshape debates over law enforcement tactics.
But don’t expect immediate clarity. Forms and procedures need updates first. And the data covers only real-time interception of communications. Remote searches of stored data on devices fall under different rules. Still, the move arrives at a moment when mercenary spyware dominates headlines.
The Administrative Office of the U.S. Courts confirmed the plan to TechCrunch. It will track wiretaps conducted via hacking tools and spyware, known internally as network investigative techniques, or NITs. Traditional reports already break down conventional wiretaps by offense type, duration and success rate. This addition slots right in.
The FBI has relied on these methods since at least 1998. Yet no public tally existed. Privacy advocates long criticized the gap. They argued it left Congress and the public in the dark about the true volume of digital surveillance.
Sen. Ron Wyden welcomed the reform. He has repeatedly pressed for sunlight on monitoring practices. Americans, he contends, deserve to know the full menu of tools in use. The new figures could finally provide that.
Eva Galperin, director of cybersecurity at the Electronic Frontier Foundation, sees practical value. Public data might reveal whether authorities reserve spyware for narrow targets or cast wider nets. “Publicly reported figures could make it easier to determine whether spyware is being used selectively or on a much larger scale,” she told Digital Trends.
Her point lands with force. Spyware scandals have multiplied. Apple alone has warned users across more than 150 countries of mercenary attacks. On Aug. 13, 2026, the company issued fresh notifications. Researcher John Scott-Railton of the Citizen Lab highlighted one on X. “ALERT: Did you get a notification like this today? Seek expert security help asap! Apple just sent out a fresh round of threat notifications about mercenary spyware. That means tech like Pegasus used by governments to spy on you,” he posted.
These alerts don’t just scare targets. They spark investigations. They expose operators. And they underscore why hard numbers matter. Without them, estimates swing wildly. Italy disclosed 4,321 spyware targets in 2023 alone. The U.S. will lag years behind with its first comparable dataset.
Distinctions in the reporting matter too. The new category targets live wiretaps. Think intercepted calls, texts or app messages in real time. Judges require strong showings of probable cause here, much like older telephone taps. Stored data pulls, by contrast, count as searches. They travel through separate warrant processes and won’t appear in these counts.
That carve-out leaves questions. Commercial tools often do both. They can siphon communications while also vacuuming photos, contacts and location history. The Wiretap Report won’t capture the full picture. Yet it offers a start. A baseline. Something concrete where before there was opacity.
Recent events add urgency. Just yesterday, Yahoo News echoed the announcement, noting the judiciary’s intent to disclose authorization counts precisely. Broader concerns swirl too. A March 2026 Foreign Intelligence Surveillance Court opinion, discussed by the Brennan Center for Justice, highlighted ongoing compliance failures in Section 702 programs. While not directly tied to domestic spyware, it fuels skepticism about oversight across surveillance activities.
Law enforcement defends these tools. They crack encrypted apps. They locate fugitives. They thwart plots that old-school bugs can’t touch. But history shows abuse risks. The absence of data fueled suspicion. Now advocates can point to trends. They can question spikes. They can compare against traditional wiretap volumes, which have hovered in the low thousands annually in recent reports.
Updates to forms won’t happen overnight. The Administrative Office must train judges, revise paperwork and integrate NIT categories. Expect delays if past reporting changes offer any guide. Even so, the commitment signals growing pressure for accountability.
Technology itself accelerates the need. Apple’s Lockdown Mode, rolled out to counter sophisticated attacks, shows how commercial spyware has evolved. It exploits zero-days. It bypasses standard protections. Governments buy it from private vendors. Some of those vendors operate with little restraint until scandals erupt.
Citizen Lab and Amnesty International have documented dozens of cases. Journalists, activists, even politicians appear on target lists. The U.S. government itself faces accusations of purchasing similar products, though it insists on strict controls. Public numbers could test those claims.
Of course, transparency has limits. The reports aggregate data. They won’t name specific operations or targets. Classified intelligence uses likely stay hidden. Yet the baseline matters. It lets analysts spot growth. It informs legislation. It gives voters context when new scandals break.
Critics wanted more. Immediate disclosure. Granular breakdowns. Inclusion of stored-data hacks. The chosen path is incremental. But incremental beats nothing. The 2029 report, whenever it drops, will mark a quiet milestone in surveillance oversight.
Until then, the conversation continues. Apple notifications arrive without warning. Researchers tweet alerts. Senators demand answers. And somewhere in a federal courthouse, a judge weighs another request for a NIT warrant. Soon, we’ll know how many such requests succeed each year. The era of invisible spyware counts draws to a close.