Investigation: Israel-based NSO Group's malware infected 23 phones belonging to government officials, reporters, execs, and activists, out of 67 checked
Washington PostDana Priest
Context & Ripple Effects
The findings arrived alongside a separate examination of Indian targets: seven of 22 phones checked showed NSO malware infections, including phones tied to top opposition politicians. The overlap turns a broad allegation about a target list into device-level forensic evidence.
The disclosure also builds on earlier reporting that senior government and military officials in at least 20 countries were among known targets of NSO's WhatsApp malware. Israeli officials later opened an inquiry into alleged Pegasus misuse, putting NSO's customer controls under direct scrutiny.
First-order effects
NSO Group faces intensified scrutiny over Pegasus after investigators documented infections on phones used by officials, reporters, executives, and activists.
The affected people and organizations must treat the examined devices as compromised communications channels rather than merely suspected targets.
Second-order effects
The India-specific findings increase pressure on governments implicated by the target lists to explain surveillance practices involving political opponents and civil society.
The concentration of confirmed infections in the Amnesty Security Lab's examined iPhones raises the stakes for mobile-device security teams and vendors confronting sophisticated spyware attempts.
Third-order effects
The Israeli inquiry signals that commercial spyware suppliers may increasingly be judged on whether they can prevent customer abuse, not solely on the technical capability of their products.
As forensic confirmation becomes central to these cases, the market for high-end mobile surveillance faces a more durable accountability challenge involving vendors, state customers, and independent security labs.
The trend: Commercial spyware is moving from opaque targeting allegations toward forensic verification and greater scrutiny of vendor oversight.
Military-grade Israeli spyware was used in attempted and successful hacks of 37 smartphones belonging to journalists, human rights activists, business executives and the fiancee of murdered Saudi journalist Jamal Khashoggi, a global investigation finds. https://www.washingtonpost…
Government of India: “Reports [of Pegasus hacking] had no factual basis and were categorically denied by all parties, including WhatsApp.” Meanwhile, actual head of WhatsApp: https://twitter.com/...
This groundbreaking reporting from @Guardian, @WashingtonPost, and many others demonstrates what we and others have been saying for years: NSO's dangerous spyware is used to commit horrible human rights abuses all around the world and it must be stopped. https://www.theguardian.c…
India, Hungary, Morocco, Azerbaijan: as part of the #PegasusProject, @FbdnStories and 16 media organizations have identified more than 180 journalists around the world, all selected as potential targets of spyware. Our investigation: https://forbiddenstories.org/ ...
There are certain industries, certain sectors, from which there is no protection. We don't allow a commercial market in nuclear weapons. If you want to protect yourself you have to change the game, and the way we do that is by ending this trade. https://www.theguardian.com/ ...
Citizen Lab, the org that partially laid the groundwork for WhatsApp's lawsuit against NSO, did a peer review of Amnesty's methodology and found it to be sound. They had done 4 blind tests too and came to the same conclusions.👇 https://citizenlab.ca/...
@SushantSin @Snowden Omar Radi, a Moroccan journalist who exposed government corruption and was hacked by an NSO client believed to be the Moroccan government ( https://www.theguardian.com/ ...), was sentenced today to 6 years in prison: https://cpj.org/...
Amazon shuts down some NSO Group infrastructure. Comes after researchers found clear links between Amazon's CloudFront product and real world hacks using NSO, including on a French human rights lawyer https://www.vice.com/...
BREAKING: Thousands of iPhones have potentially been compromised. Our forensic analysis has uncovered irrefutable evidence that through iMessage zero-click attacks, NSO's spyware has successfully infected iPhone 11 and iPhone 12 models. #PegasusProject https://www.amnesty.org/...
Forget autocratic governments that didn't have much of a reputation to begin with. The #PegasusProject also has ripped apart @Apple's balderdash over iPhone security- perhaps the ONLY area that was allegedly superior to Android phones. Will Cupertino folks explain the tall lies? …
NSO Group has said repeatedly that its surveillance tools do not work against smartphones based in the United States, but Americans traveling overseas and using foreign cellphones may not enjoy that protection. https://www.washingtonpost.com/ ...
Shocking, yes, by normal standards — but should we really be shocked by these revelations about India's authoritarian regime? Who else but the Union government or its agencies could have done this? https://www.theguardian.com/ ...
NEW from the Pegasus Project: An NSO client we believe was Narendra Modi's government hacked an opposition campaign manager during this year's West Bengal elections and identified Rahul Gandhi, his friends and staff as possible surveillance targets https://www.theguardian.com/ ..…
Citizen Lab (@citizenlab) peer-reviewed the above report by Amnesty and the methodology used by Amnesty, and have stated that the findings are sound. https://citizenlab.ca/... 4/4
Amazing work by @AmnestyTech and its media partners! The team and the journos had access to over 50k phone numbers of people of interest by clients of spyware company #NSO. It includes world leaders, activists and journalists. https://www.amnesty.org/...