TodayFriday, August 14, 2026

US Courts to Disclose Government Spyware Use for First Time, Starting 2029

The Administrative Office of US Courts will finally count government spyware use in annual reports, but the first public number is three years away.
August 14, 2026
Illustration of spyware threatening mobile device security as US courts begin tracking government surveillance tool use
US courts will start tracking government spyware use starting with 2028 data. [Image Source: TechCrunch]

WASHINGTON — For nine years, Senator Ron Wyden has been asking a simple question: how often does the federal government use spyware to surveil Americans? On Thursday, the institution closest to that question gave the closest answer it has yet been willing to provide. The Administrative Office of the U.S. Courts announced it will add a new category to its annual Wiretap Report tracking government use of hacking tools and spyware against real-time communications, with public disclosure starting in 2029.

The announcement represents the first formal acknowledgment by the judicial system that commercial and government spyware has become a routine enough tool of law enforcement to require its own statistical category. The Wiretap Report, published annually since 1968, has long tracked traditional intercepts: the court orders authorizing the government to tap phone calls and read text messages in real time. Spyware, the category of tools that compromise a device directly and silently, has never appeared there. Starting with 2028 data, it will.

The Administrative Office said the change reflects what investigators, digital security researchers, and civil liberties organizations have documented for years: that law enforcement and intelligence agencies have expanded their use of what the courts call network investigative techniques, or NITs, to intercept live communications. A spokesperson said the agency is updating “reporting forms and procedures to accommodate the new categories,” according to TechCrunch.

What the announcement covers has a precise boundary, and that boundary matters as much as what falls inside it. The new tracking applies to spyware used to intercept real-time communications, including calls made over an encrypted app or messages sent through Signal or WhatsApp at the moment of transmission. It does not apply to tools used for remote data extraction: pulling stored files from a device, reading past messages, accessing photos, or tracking a target’s location. Those are different legal authorities, governed by different court orders, and the new reporting requirement does not reach them.

That distinction is not a technicality. The spyware that has generated the most documented controversy, including tools deployed against journalists, opposition politicians, and human rights workers that Apple warned iPhone users in 110 countries about Thursday, is predominantly used for remote device access rather than real-time interception. Pegasus, the flagship product of the US-blacklisted Israeli company NSO Group, can access a device’s stored data, activate its microphone and camera, and monitor location, all without the target’s knowledge. The contempt motion Meta filed against NSO Group this summer alleged that Pegasus was intercepting WhatsApp traffic even after a federal court ordered it to stop, an allegation that sits precisely at the boundary between the tool category the new reporting will count and the tool category it will not.

Apple iOS notification warning users of spyware attacks from government surveillance tools including NSO Group Pegasus
Apple alerted iPhone users in 110 countries to mercenary spyware attacks Thursday, the same day courts announced new reporting requirements. [Image Source: TechCrunch]
Eva Galperin, the director of cybersecurity at the Electronic Frontier Foundation, offered a carefully qualified assessment. “Being able to point to a report saying that spyware was used X number of times will help with accountability,” she said, adding one condition: “especially if it turns out that number is quite high.” The hedge is the point. Nobody currently knows what that number is. Nobody will know it for three years.

Wyden has been attempting to change that since 2017, when he first asked the Administrative Office to include spyware in its reporting. He reintroduced the Government Surveillance Transparency Act earlier this year as part of a broader legislative push that followed the lapse of Section 702 of the Foreign Intelligence Surveillance Act in June. That lapse, the first since the law’s creation in 2008, left the government’s largest foreign surveillance program running on court certifications rather than statutory authority, a situation that exposed the program’s practical independence from congressional oversight and handed reformers a bargaining chip they have not yet cashed.

The timeline Thursday’s announcement established is not accidental. Data collected in 2028 appearing in a report published in 2029 amounts to a delay of roughly three years on a decision made this week. The Wiretap Report is a historical document; it tells the public what happened, not what is happening. By the time the first spyware statistics appear, any accountability they might generate will be three cycles removed from the surveillance they count.

The gap between the announcement and its consequences raises the question the announcement does not answer: what is the government actually doing right now? The Administrative Office’s decision says the answer matters enough to count, but not enough to count quickly. The agency has simultaneously acknowledged a problem and scheduled its first measurement for a date so far away that the problem may look quite different by then.

Historical data creates pressure on the present. When the first spyware number appears in a government report, whether it is dozens of uses or thousands, it becomes the baseline against which every subsequent year is measured, a public accounting where previously there was none. That is not accountability. It is the precondition for accountability, which is meaningfully different, and which the government has spent years making as difficult as possible to establish.

Whether the disclosure that arrives in 2029 reflects honest counting will depend on definitions the Administrative Office controls. The distinction between real-time interception and remote device access is one the government drew, not one that maps cleanly onto how spyware is deployed in practice. A tool like Pegasus is rarely used for one purpose and not the other; the same device compromise that reads stored messages can also capture live communications. The legal authority under which a use is authorized determines which category it falls into, assuming it was authorized at all.

The Wiretap Report has always tracked authorized surveillance: court orders issued, orders executed, targets identified, communications intercepted. It does not track unauthorized collection, and neither will the new spyware category. The number that appears in 2029 will tell Americans how often the government told a court it was using spyware and received permission to proceed. What it will not tell them is anything about the uses that never reached a court. Those will stay where they have always been, counted in no report, and unknown.

Dilnaz Shaikh

Dilnaz Shaikh

Dilnaz Shaikh is a journalist at The Eastern Herald covering current affairs, politics, climate, environment, and international news with a focus on planetary issues and global governance.

Leave a Reply

Don't Miss