Federal court records show the FBI went beyond simply testing commercial spyware as it considered how the technology could be used in criminal investigations. Those records now expose a gap in a new US court reporting system that will count hacking-based wiretaps but not every stage of government interest in or use of device-hacking tools.
Beginning with 2028 activity, the federal judiciary plans to separately track court-authorized interceptions that use spyware or hacking techniques, with the first figures expected in 2029. The FBI’s NSO Group records show why those statistics will still be incomplete: agencies can evaluate tools, draft potential-use guidelines, and identify investigative applications before a case ever reaches a reported wiretap.
FBI records show how far the Pegasus review went
The Administrative Office of the US Courts plans to add a separate spyware/hacking category to its annual report, according to reporting on the judiciary’s decision. The category is intended to identify hacking techniques authorized for real-time communications interception.
A 2023 federal court record details how FBI and Justice Department personnel considered technology from Israel’s NSO Group, maker of Pegasus. Officials discussed whether and how the technology could support criminal investigations, and a May 2021 document proposed guidelines for possible use while referencing specific criminal matters where personnel believed the tool might apply.
The records do not establish that Pegasus was used in an FBI investigation. They show the Bureau issued a July 22, 2021, notice directing personnel to cease efforts involving the technology, while congressional testimony described the NSO license as an evaluation of the technology and its security implications.
Commercial spyware remains an active security concern. In June 2026, Meta said WhatsApp disrupted NSO-linked targeting attempts after a permanent injunction barred NSO from targeting WhatsApp and its users; Meta said it found no evidence that the fewer than 10 identified targets were successfully compromised.
The new wiretap count won’t capture every hack
Sen. Ron Wyden pressed the FBI for broader figures in December 2022. He sought annual figures for Network Investigative Technique operations, including how many were court-authorized and how many people, devices, and accounts were remotely searched.
Remote searches are not necessarily wiretaps. Hacking used to intercept communications as they occur can fall under the wiretap framework, while accessing information already stored on a compromised device can be treated as a search under different legal authority; the judiciary’s annual Wiretap Report also excludes interceptions regulated by the Foreign Intelligence Surveillance Act.
That gap has practical consequences for endpoint security. Google’s 2026 Android protections expanded Intrusion Logging for spyware investigations, giving researchers encrypted forensic records that can help identify suspicious installations, server connections, and attempts to tamper with device logs.
Mobile exploit chains also show why the device itself remains a high-value target. A June review of Apple’s 2026 security threats detailed targeted exploits and an iPhone attack framework capable of exposing messages, passwords, photos, emails, and other data after compromise.
The court figures due in 2029 should establish a baseline for hacking-based live interception beginning with 2028 activity. The FBI’s Pegasus records show the limit of that number: government interest in powerful hacking capabilities can begin long before a tool appears in a wiretap tally — and may never appear there at all.
Read more: The reporting system has important boundaries around what gets counted; here is what the new spyware records will disclose when the first figures arrive.
Discover more from PressNewsAgency
Subscribe to get the latest posts sent to your email.