The Administrative Office of the U.S. Courts will begin publicly disclosing how often judges approve government use of hacking tools and spyware in lawful wiretap investigations, adding a new "spyware/hacking" category to its annual Wiretap Report. The change will first appear in the report covering 2028 activity, scheduled for publication in 2029, and will track use of network investigative techniques (NITs) for real-time interception of communications.
The new reporting is expected to cover surveillance targeting calls and messages, including encrypted services such as Signal and WhatsApp, but it will not include remote device hacking used to collect stored data because those actions fall under separate search-warrant authorities. The move follows years of pressure from Senator Ron Wyden and has been welcomed by privacy groups including the EFF and ACLU as a long-sought transparency measure over government hacking practices that have reportedly been used by the FBI since at least 1998 without public accounting.

See the reporting duties and controls this puts on the clock.
5 events from the most recent confirmed update back to the earliest known activity.
Public data showed that Italy had 4,321 spyware targets in 2023. The references cite Italy as an example of a country already publishing detailed public spyware-use statistics.
A May 2021 document proposed guidelines for possible FBI use of NSO Group technology and referenced criminal matters where personnel believed the tool might apply. Court records cited later did not establish that Pegasus was actually used in an FBI investigation.
Senator Ron Wyden had sought public transparency around government spyware and hacking use since 2017. The later judiciary reporting change is described as following or reflecting that advocacy.
The FBI has used hacking techniques and spyware since at least 1998, according to the reporting. The references note there had been no public dataset counting how often those tools were deployed.
The Administrative Office of the U.S. Courts decided to begin publicly reporting how often judges authorize hacking tools and spyware for wiretaps, adding a new spyware/hacking category to Wiretap Reports. The reporting will cover network investigative techniques used for real-time interception, while excluding remote hacking used to obtain stored data under separate warrant authorities.
See what this changes for your reporting obligations and which controls it puts on the clock.
5 references tracked. Mallory keeps watching after this page renders.
techrepublic.com
Open sourcetechrepublic.com
Open sourcecyberveille.ch
Open sourcescworld.com
Open sourceuscourts.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.