Starting in 2029, the public will know, for the first time, an exact count of how many times a federal judge authorized the government to hack into someone’s phone or computer to wiretap their communications. This unprecedented disclosure from the Administrative Office of the U.S. Courts arrives after three decades of the FBI and other agencies using these tools in near-total statistical darkness according to TechCrunch. It is a forced crack in a windowless room where the most invasive electronic surveillance has been authorized for decades.
The Windowless Courtroom Doors Are Finally Cracking Open
For anyone outside the intelligence or law enforcement community, the use of judicial spyware authorizations has been a black box. The courts have published annual Wiretap Reports since at least 1998, detailing thousands of authorizations for traditional phone taps and electronic intercepts. Yet the category for using "spyware/hacking" to execute those wiretaps, what the government calls Network Investigating Techniques (NITs), has never existed. The change, confirmed to Democratic Senator Ron Wyden, means that starting with the 2028 report (published in 2029), a new line item will appear. It is not a sweeping reform, but a reluctant admission that this power is exercised and ought to be quantified. As Wyden told TechCrunch, “The American people remain largely in the dark about the different ways that the government is spying on them.” This cracks the door, but it does not open it.
Counting the Uncounted: The Opaque History of Judicial Spyware Authorizations
The legal authority for this surveillance is not new. The FBI has been using hacking techniques since at least 1998. Judges have been signing off on these operations by authorizing wiretap orders that are carried out with spyware instead of, or alongside, a traditional tap on a telecom provider. The difference is one of method and invasiveness. A standard wiretap intercepts communications as they pass through a network. A spyware-enabled wiretap requires hacking the target’s device itself, installing malware to capture Signal calls or WhatsApp messages directly from the source. The legal standard is the same, but the technical execution is vastly more intrusive.
The pressure for this disclosure has built for years. Wyden has called for it since 2017. Privacy experts have operated on anecdotes and rare court document leaks. The courts’ move now, amidst a shifting political climate on surveillance, suggests a defensive calculation: offer a minimal transparency measure to forestall more demanding legislation.
Breaking Down the Numbers: What the First Spyware Disclosure Report Will and Won’t Show
The 2029 report will provide a single, critical data point: the annual count of spyware-authorized wiretaps. Expect a number. It will likely be listed alongside the counts for audio wiretaps, oral intercepts, and other electronic surveillance. That number, alone, will be revolutionary for public debate.
Crucially, here is what the report will NOT show:
- The Target: No data on whether subjects were suspected terrorists, drug traffickers, activists, or politicians.
- The Tool: No disclosure of whether the spyware was commercial (like Paragon’s Graphite or NSO’s Pegasus) or a bespoke government creation.
- The Scope: It will not reveal if one authorization led to the interception of one person’s messages or, as in a past case cited in the source, millions of text messages over three months.
- Search vs. Wiretap: It will not cover when spyware is used to search a device (extracting photos, files, location data), a different legal process. This disclosure is strictly for real-time communications interception.
“Being able to point to a report saying that spyware was used X number of times will help with accountability, especially if it turns out that number is quite high,” said Eva Galperin, director of cybersecurity at the Electronic Frontier Foundation. “It’s hard to say that you’re using spyware as a surgical tool when you’ve deployed it tens of thousands of times.”
The raw count is a start, but as Galperin implies, it’s a lever. A low number could be used to argue restraint; a high one would instantly fuel demands for far deeper scrutiny. For context, Italy’s public data shows spyware was used against 4,321 targets in 2023.
Stakeholder Whiplash: From Privacy Activists to Federal Prosecutors
The new disclosure policy sends divergent signals across the surveillance ecosystem.
Privacy and Civil Liberties Advocates view this as a foundational, yet insufficient, win. The ACLU’s Brett Max Kaufman called it “an important and long-overdue step forward for transparency.” Its true value is as a tool to demand more. A startlingly high number would be immediate ammunition for Wyden’s Government Surveillance Transparency Act, which seeks more comprehensive reporting. A suspiciously low number would lead to questions about undercounting or the use of parallel, non-judicial surveillance methods.
Law Enforcement and Prosecutors are likely apprehensive. Their operational playbook for deploying tools like Graphite or Pegasus has never been quantified. Public counts could lead to uncomfortable questions about cost, success rates, and the proportionality of using a weapon-grade cyber tool for routine investigations. It could also alert criminal networks to the scale of certain tactics, potentially changing their behavior.
The Commercial Spyware Industry faces new indirect scrutiny. Vendors like Paragon Solutions and NSO Group, which have sought contracts with agencies like ICE, can no longer operate on the premise that U.S. government use of their tools is an invisible, deniable matter. A major line item in the federal wiretap report tied to a specific vendor would become a political flashpoint. This comes as the industry is navigating a volatile U.S. policy landscape, where, as our related reporting shows, Apple's Lock Screen Alert Warns iPhone Users of Spyware Attack.
Judges themselves enter a new era of potential accountability. Previously, their signature on a spyware-enabled wiretap order disappeared into a confidential file. Now, their collective authorizations will contribute to a public tally. This could incentivize more rigorous scrutiny of applications, knowing their decisions will eventually be counted, if not individually named.
The New Transparency and Its Ripple Effects on Surveillance Tech
A public number alters the field. It moves spyware from the realm of shadowy, hypothetical capability to a documented, measurable government activity. This has several likely downstream effects:
Market Pressure on Vendors: Companies selling hacking tools to the U.S. government can expect increased due diligence. A government agency purchasing a tool that could significantly bloat its publicly reported spyware wiretap count may think twice. Ethical and legal safeguards in contracts will become a bigger selling point.
Judicial Caution: Judges, aware their authorizations are now quantified, may raise the bar slightly for granting such invasive requests. They will be more likely to consider whether a less intrusive method could suffice.
Public Resource Debate: The cost of commercial spyware contracts, like the now-ended $2 million ICE contract with Paragon Solutions, can be juxtaposed against the reported utility (the wiretap count). Lawmakers and oversight bodies will have their first concrete hook to ask: “We are spending millions on these tools; how often are we actually using them, and for what?”
From a Count to a Conversation: Predicting the Next Five Years of Surveillance Oversight
The 2029 report is not an endpoint, but a starting pistol. The next five years will unfold in predictable stages.
Stage 1: The Number Drops. In late 2029 or early 2030, the first figure is published. The immediate reaction will define the next battle. If the number is in the dozens or low hundreds, the government will claim it proves surgical, rare use. Privacy advocates will scrutinize it for anomalies and argue it’s implausibly low, pointing to parallel programs and demanding audits. If the number is in the thousands, it will trigger immediate congressional hearings and media firestorms.
Stage 2: The Demand for Granularity. The conversation will rapidly move beyond “how many” to “who, what, and with what.” Legislators will push to amend reporting requirements to include categories of crime (e.g., espionage vs. drug trafficking), the specific spyware used, and the number of non-target “incidentally” collected communications. The fight will be over turning a single data column into a detailed spreadsheet.
Stage 3: The Policy Reckoning. The ultimate test is whether this data leads to substantive change. Will a high count result in new legislative restrictions on spyware use, similar to the geofencing or facial recognition debates? Or will the report become a mere compliance footnote, an accepted cost of modern law enforcement? The answer hinges on who seizes the narrative first when the number goes live.
The courts’ decision to count these authorizations is a profound shift from a culture of secrecy to one of minimal accountability. It accepts, for the first time, that the public has a right to know the scale of one of the government’s most intrusive powers. That number, however sparse, is a handle on a door that has been locked for thirty years. What happens next depends on how hard the public, and their representatives, decide to pull.
Why This Changes Everything
- For the first time in three decades, the public will get exact data on how often the government hacks devices for surveillance, moving from total secrecy to quantified disclosure.
- This creates basic accountability for one of the most invasive surveillance tools, allowing oversight of a power the FBI has used since at least 1998.
- It marks a crack in the 'black box' of judicial spyware authorizations, setting a precedent for transparency even if it falls short of comprehensive reform.
Originally published on XOOMAR. For more news and analysis, visit XOOMAR.
Top comments (0)