Digital Evidence Collection and Analysis by Law Enforcement is moving faster than the Law

[
[
[

]
]
]

For thirty years, the federal judiciary has posted something genuinely admirable: an annual, public, statutorily required tally of every wiretap in the country. It’s called the Wiretap Report, the Administrative Office of the U.S. Courts compiles it, and Title III has demanded it since 1968. It tells you how many intercepts judges authorized, federal and state, in which places, for which crimes, at what cost, and how many arrests and convictions followed. In a field defined by secrecy, it is a rare, hard number.

This month we learned what that number has been quietly leaving out.

In this Techcrunch article, the Courts told Senator Ron Wyden that it will begin counting a category of surveillance it has never separately reported: the times a judge authorizes the government to use spyware and hacking tools — what the FBI calls network investigative techniques, or NITs — to carry out a wiretap. The new “spyware/hacking” line will appear starting with the 2028 Wiretap Report, published in 2029. Until then, the public accounting shows zero — not because it never happened, but because it was never on the form.

Sit with the timeline. The FBI has been using hacking techniques to conduct surveillance since at least 1998 and the Courts changed the Federal Rules of Criminal Procedure to support them in 2016. The one public report that exists to count government interception will begin reflecting that fact in 2029. That is roughly a thirty-year gap between a surveillance capability entering the field and entering the ledger.

How does a technique used for three decades stay invisible in the report built to count exactly this? The answer is the same failure this blog keeps finding in every corner of surveillance law: the categories were built around a technology, and the technology moved.

The Wiretap Report sorts interception into the buckets Congress could see in 1968 and the years just after — wire (the audio of phone calls), oral (a microphone or bug in a room), and electronic (messages, texts and emails, captured as they cross a provider’s network). Every one of those is interception in transit: the government grabs the communication somewhere along the path between sender and receiver. Spyware does something categorically different. It doesn’t sit on the wire. It compromises the endpoint — the phone or laptop itself — and works from inside the device. That maps onto none of “wire,” “oral,” or “electronic” as the report understands them, so for decades it fit no box, and a thing that fits no box gets counted in no box.

That is the technology-specific hole I wrote about in the very first post, surfacing in the oversight machinery instead of the definitions. Build your categories around the tools of the moment and the next tool falls straight through the gaps — not because anyone hid it, but because the reporting form never had a line for it.

And here is why it’s more than a bookkeeping fix, and why it ties straight back to Tuesday. On Tuesday I argued that the authority required to collect should scale with the intrusiveness of the collection. Spyware is the intrusion at its maximum. A classic wiretap captures your communications as they pass. Spyware takes the device — and a modern device is not a phone line, it’s your papers, your location, your camera, your microphone, your whole digital life, live and continuous. It is the most invasive collection the government does, and it has been folded into the ordinary run of “wiretaps,” authorized under intercept orders, and — until 2029 — not even distinguished in the count. You cannot match authority to intrusiveness if you refuse to distinguish the most intrusive technique in the arsenal from the least. The reporting gap and the authorization gap are the same gap: a legal framework that can’t tell the difference between tapping a call and seizing a machine.

And here is the number that makes the omission matter. The count the report does keep has been falling. Just 1,735 wiretaps were authorized in 2025 — a 24% drop in a single year, and far below the 3,000-plus routinely authorized a decade ago. Read quickly, that looks like surveillance receding. It is nothing of the kind. Traditional wiretaps are declining because the communications they were built to catch have moved somewhere a wiretap can’t reach — end-to-end encrypted apps, and data sitting in the cloud. The report’s own encryption figures show the pressure: hundreds of intercepts a year now run into encryption the government can’t break. So the government follows the communications to where they actually live, with cloud-storage warrants, device searches, and, increasingly, the spyware that compromises the endpoint before the encryption ever engages. None of those show up here. The Wiretap Report is thus doing two things at once: counting a shrinking slice of surveillance and missing the methods that are replacing it. The falling headline number and the uncounted spyware category are the same story told from opposite ends.

To be fair to the report, it has adapted before — which shows both that it can and how slowly it does. After encryption began frustrating intercepts, the statute was amended so that starting in 2000 the report would track how often wiretaps ran into encryption and whether it defeated them. So the mechanism can absorb a new phenomenon — but only when Congress or the AO is pushed to add a line, and here the push came from a single senator’s inquiry, a generation into the practice. A transparency regime that only sees a new technique when an individual legislator happens to ask about it is not a transparency regime. It’s a series of lucky catches.

This is the section of the model act the story belongs to — reporting and oversight — and it’s why I’d draft that section very differently from § 2519. Three changes fall out of this one news item.

First, define the reported categories functionally, not technologically. Don’t count “wire, oral, and electronic.” Count by what the collection does to the person: interception in transit, compulsion of stored data from a third party, and compromise of the person’s own device. A new tool that compromises a device lands in the device-compromise category automatically, the day it’s invented, with no form revision required. Functional categories don’t rot, for the same reason functional definitions don’t.

Second, make the reporting mandatory, self-updating, and audited rather than reactive. The count should attach to the intrusion, not to whether someone remembered to add a box — and an independent body, not the agencies doing the collecting, should verify it. It’s worth knowing that the Wiretap Report is already suspected of undercounting even the categories it does track, because it’s assembled from forms officials have to remember to file, and provider transparency numbers have at times told a different story. A count you can’t audit is a count you have to take on faith.

Third, close the carve-outs. The Wiretap Report, by statute, excludes surveillance conducted under the Foreign Intelligence Surveillance Act entirely — an enormous category of interception that simply isn’t in this public accounting at all. Whatever the reasons, the lesson for a model statute is that every carve-out is a place where practice can grow in the dark. If a category of collection is powerful enough to require authorization, it is powerful enough to be counted.

Now the strongest objection, because it’s real. Some of these techniques are genuinely sensitive, and there’s a legitimate worry that publishing granular figures about a specific hacking capability could reveal something operational — how often a particular tool is used, and against what, in ways that help targets take countermeasures or expose vulnerabilities the government relies on. Counting common phone taps is one thing; counting a niche exploit might be another.

I take the sensitivity seriously, but it justifies far less secrecy than it has been used to buy. An aggregate annual number — how many times a court authorized device-compromise surveillance, for which categories of crime, in which districts — reveals frequency and scale, not method. It does not publish the exploit, name the tool, or hand anyone a countermeasure. The Wiretap Report has published exactly that kind of aggregate for classic intercepts for decades without burning a single capability, and spyware has earned no special exemption from a count that discloses only that it is happening, and how much. Protect the operational details in the individual sealed record; do not let “the technique is sensitive” become the reason the public never learns the technique exists at scale. The sensitivity concern is an argument about the granularity of disclosure, not about whether to count at all.

That’s the whole reason to put reporting in the statute rather than leave it to a form. Reporting is not the ceremonial appendix at the end of a surveillance law. It is the precondition for everything else in this project. You cannot set a default of no (§ 2) and check whether it is holding; you cannot calibrate authorization to intrusiveness (§ 3) and know whether the calibration is real; you cannot build remedies for abuse (§§ 9–10) that anyone can actually invoke — if the public and the Congress can’t see what the government is doing. The spyware category arriving in 2029 is good news. That it took until 2029, and a senator, is the entire argument for writing the count into the law itself — functionally and completely — so the next technique doesn’t get its own thirty years of invisibility.

Leave a comment