Researchers: NSO Group used location data from thousands of unsuspecting people while pitching its COVID-19 contact-tracing tech to governments and journalists
Context & Ripple Effects
NSO's pandemic pivot has been building all year: the firm began marketing a mobile-phone-data tool to track COVID-19's spread in April 2020, claiming countries were already testing it, before researchers found its "Fleming" contact-tracing system sitting unprotected on the internet — which NSO dismissed as just a demo. A [[a:953129|Reuters deep dive documented how cyber-intel firms like Cellebrite, Intellexa, and NSO spent spring 2020 pitching governments]] on repurposing spy tools for epidemiology.
Today's report cuts the legs off the "demo" defense: researchers say real location data from thousands of unsuspecting people flowed through the product while NSO pitched it to governments and journalists, meaning the sales process itself involved unconsented tracking at scale.
First-order effects
- The "it was only a demo" explanation for the exposed Fleming system no longer holds if live location data from thousands of people was processed — NSO's account of what the product was collapses.
- Government agencies and journalists who were the pitch audience now have researcher-documented evidence that the vendor's data-handling claims diverged from its actual behavior.
Second-order effects
- Rival cyber-intel firms named in the same government-pitch cycle — Cellebrite and Intellexa — face intensified due-diligence questions about where their own demo datasets come from.
- Buyers weighing contact-tracing procurement gain grounds to demand provenance audits of any vendor's underlying data, raising the cost of selling surveillance-adjacent health tools.
Third-order effects
- If pandemic demand keeps pulling offensive-surveillance firms into bulk-data products, regulatory attention shifts from who the tools target to how the input data was obtained — an open question the current export-control framework barely addresses.
- Each documented misuse compounds NSO's legal exposure trajectory: with courts already finding it liable for the 2019 hacking of more than 1,400 WhatsApp users across 51 countries, location-data findings give plaintiffs and regulators a second line of attack.
The trend: Spyware vendors' pivot into pandemic public-health markets is turning unvetted data provenance into the next front in the governance fight over commercial surveillance.