A whistleblower working with the DOJ says NSO Group offered staffers from US mobile security firm Mobileum “bags of cash” for access to global cellular networks
Context & Ripple Effects
NSO Group has spent years trying to crack the US market through the front door: it poured millions into lobbyists and consultants but was rebuffed by US law enforcement agencies that balked at the cost of its tools. Its reputation problem deepened after investigations found its Pegasus malware on 23 phones belonging to government officials, reporters, executives, and activists.
The new allegation shifts the story from selling tools to buying infrastructure: a whistleblower cooperating with the DOJ says NSO offered Mobileum staffers 'bags of cash' for access to global cellular networks. That would extend a pattern already visible in its product claims — from harvesting cloud data via stolen authentication tokens to reaching victims at the network layer itself.
First-order effects
- Mobileum staffers are now personally implicated in a DOJ-backed whistleblower case, and any network access they may have granted becomes evidence in a federal inquiry into NSO Group.
- NSO faces a second front beyond device-level scrutiny: if the cash-for-access claim holds, its US expansion strategy moves from rebuffed lobbying to alleged improper inducements, which is exactly what a DOJ cooperation agreement is built to pursue.
Second-order effects
- Telecom operators and mobile-security firms like Mobileum come under pressure to audit insider-access controls, since the alleged vector is employees selling network entry rather than software exploits bought off the shelf.
- Western intelligence and law-enforcement buyers, already wary after the Pegasus revelations, gain fresh justification to treat NSO not just as a vendor with a tainted product but as an actor seeking unauthorized reach into core network infrastructure.
Third-order effects
- If the pattern holds, spyware vendors' access strategies migrate down the stack — from phone exploits to carrier networks and cloud credentials — pushing regulators to police infrastructure insiders and supply chains, not just exported hacking tools.
- The case could harden a structural split in which surveillance-tool firms deemed infrastructure risks are locked out of Western markets entirely, formalizing the rebuff NSO already experienced with US agencies.
The trend: Commercial spyware is shifting from selling device exploits toward acquiring direct access to network and cloud infrastructure, drawing scrutiny from regulators who previously focused only on the tools themselves.