US Spyware Transparency: A Warning for Malaysian SMEs

US Spyware Transparency: A Warning for Malaysian SMEs — featured image

by

When You Don’t Know Your Business Phone Is Being Watched

You run your business from a phone that’s always in your pocket. You use WhatsApp to close deals, Telegram for the team’s daily updates, and Google Drive to store customer invoices. You assume that all of it is private. But what if it isn’t?

Here’s the news: the U.S. judiciary has agreed to start publishing exactly how often the federal government uses spyware to tap into live communications — calls, messages, and app conversations. This is the first time in decades that any government will report these numbers publicly. It’s a big deal, and not just for Americans.

Why should a Malaysian SME owner care? Because this decision exposes how much surveillance can happen without you ever knowing — and because the tools governments use in the U.S. have a way of appearing elsewhere. If you’re dependent on digital communications to run your business, you need to understand what this means for your privacy, your customer data, and your legal risks.

TL;DR: Starting in 2029, U.S. courts will publicly count how many wiretaps use spyware to access real-time calls and messages. It’s a transparency breakthrough that gives us a rare look at government hacking. For Malaysian SMEs, it’s a reminder to check your own security habits and to watch how global surveillance trends could affect local laws and business practices.

What This Means: Spyware Isn’t Just for Secret Agents Anymore

Let’s clear up the jargon. When the U.S. government wants to listen in on someone’s live phone call or read their WhatsApp messages as they arrive, it goes to a judge and asks for a wiretap. Usually that means tapping the phone network. But increasingly, law enforcement uses hacking tools or spyware to do the same job — remotely installing software on a target phone that captures calls and messages in real time. The FBI has been using these techniques since at least 1998, according to TechCrunch.

Previously, there was no public data on how often the feds used spyware for wiretaps. The annual Wiretap Reports published by the Administrative Office of the U.S. Courts always counted traditional wiretaps, but never distinguished which ones were executed via spyware. That changes with the 2028 report, released in 2029, which will include a new “spyware/hacking” category.

One important distinction: this reporting only covers real-time interception — listening in as messages are sent. It doesn’t cover other forms of hacking like remotely extracting photos, files, or location data from a stored device. That’s legally separate and remains invisible. So even this transparency won’t show the full picture of government surveillance. But it’s a starting point.

“Up until now, we have only been able to guess at the size of the problem.” — Eva Galperin, Electronic Frontier Foundation

How This Applies to Malaysian SMEs

You might be thinking: “we’re a small company in Malaysia, not a cartel — nobody is wiretapping us.” But that’s the wrong way to look at it. First, Malaysian law already allows for wiretapping and accessing communications under several statutes, including the Communications and Multimedia Act and the Penal Code. The government has used wiretap powers before, and communications interception is a well-established practice. There is simply no public reporting on how often it happens here.

Second, your business is only as secure as the least-protected phone that carries your company’s secrets. Imagine an employee losing a phone or clicking a malicious link. If spyware gets installed, it can capture audio from calls, read chat apps, and even record keystrokes. You won’t see it, and neither will your team — the malware is designed to be invisible. The U.S. reporting reminds us that governments are actively building and buying these tools. Criminal gangs use the same technology. If a hacker in another country can remotely switch on your contractor’s microphone, they’ll hear your supplier’s pricing, your client list, your overdue invoices.

For Malaysian SME owners, the practical takeaway is to treat every smartphone and laptop as a potential battlefield. This is not about being paranoid; it is about being smart. Use end-to-end encrypted messaging apps for sensitive business conversations. Turn on two-factor authentication everywhere. And critically, create a simple policy that your team never discusses passwords, bank details, or customer data in apps that don’t offer encryption by default. The U.S. transparency move isn’t going to change Malaysian law immediately — but it signals a global shift toward accountability, and it can be used as a benchmark to ask tougher questions of your own government.

There’s also a commercial angle. If you sell to bigger companies or foreign clients, they increasingly care about where their data travels. Showing that you know about surveillance risks and take steps to mitigate them can be a selling point. You don’t need to become a cybersecurity expert, but you should be able to say honestly, “we use encrypted tools and we don’t store sensitive data on unsecured devices.”

Finally, think about your customers. Many Malaysian SMEs handle personal data — NRIC numbers, addresses, health details, or payment info. If a government anywhere ever asks to access that data, you need to have a basic understanding of your legal rights and duties. The U.S. example of publishing spyware counts may set a precedent that pushes more jurisdictions, including Malaysia, to disclose similar data. When that happens, you’ll want to already have good housekeeping in place.

What You Can Do: Practical Steps Right Now

  • Audit your communication tools: List every app your team uses to talk to customers and between themselves. Replace weak ones with end-to-end encrypted options.
  • Enable automatic updates: Spyware often exploits outdated operating systems. Set phones and laptops to update themselves overnight.
  • Use a password manager: Don’t reuse passwords across business accounts. A simple password manager is easier than a data breach.
  • Create a “no sensitive info on unsecured apps” rule: If a conversation contains payment details or passwords, move it to a secure tool.
  • Keep personal and business phones separate: If you can, use work-only devices for business. The more apps on someone’s personal phone, the wider the attack surface.

The Data Behind the Headlines

What you should know Details
FBI spyware use began At least since 1998
First public spyware wiretap count Due in the 2028 report, published in 2029
Real-world scale of a single wiretap A prior U.S. wiretap collected millions of text messages over three months
Italy’s published spyware stats 4,321 targets in 2023

The Bigger Picture: Transparency Is a Business Environment

Governmental spyware is not a conspiracy theory — it’s a documented industry. The U.S. publishing its numbers is a small but meaningful step toward letting citizens know what their government does in secret. For Malaysia, it raises a simple question: why shouldn’t we know the same?

This trend will likely influence what tech companies build, how they respond to government requests, and how much encryption they push by default. As a business owner, you can benefit from that trend without changing your entire infrastructure. Just stay informed, stay cautious, and make sure you’re not leaving doors open.

The day the 2028 report is published will be an interesting day for privacy advocates. But for you, the more important day is today — the day you decide whether your business communications are protected enough. That decision doesn’t require knowing the exact number of spyware uses. It requires treating every customer conversation and supplier negotiation as valuable data worth protecting.

Because if the government can hide how often it uses spyware, imagine what a criminal can do with the same tools. The best time to prepare was yesterday. The second best time is now.

Ready to Streamline Your Operations?

Your business should run itself. AutoRunBiz deploys AI agents to automate your daily operations — WhatsApp orders, invoicing, customer follow-ups, and accounting. Book a free 15-min ops audit to see where automation fits your business →