/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

Researchers: NSO Group used location data from thousands of unsuspecting people while pitching its COVID-19 contact-tracing tech to governments and journalists

TechCrunch Zack Whittaker

Context & Ripple Effects

NSO's pandemic pivot has been building all year: the firm began marketing a mobile-phone-data tool to track COVID-19's spread in April 2020, claiming countries were already testing it, before researchers found its "Fleming" contact-tracing system sitting unprotected on the internet — which NSO dismissed as just a demo. A [[a:953129|Reuters deep dive documented how cyber-intel firms like Cellebrite, Intellexa, and NSO spent spring 2020 pitching governments]] on repurposing spy tools for epidemiology.

Today's report cuts the legs off the "demo" defense: researchers say real location data from thousands of unsuspecting people flowed through the product while NSO pitched it to governments and journalists, meaning the sales process itself involved unconsented tracking at scale.

First-order effects

  • The "it was only a demo" explanation for the exposed Fleming system no longer holds if live location data from thousands of people was processed — NSO's account of what the product was collapses.
  • Government agencies and journalists who were the pitch audience now have researcher-documented evidence that the vendor's data-handling claims diverged from its actual behavior.

Second-order effects

  • Rival cyber-intel firms named in the same government-pitch cycle — Cellebrite and Intellexa — face intensified due-diligence questions about where their own demo datasets come from.
  • Buyers weighing contact-tracing procurement gain grounds to demand provenance audits of any vendor's underlying data, raising the cost of selling surveillance-adjacent health tools.

Third-order effects

  • If pandemic demand keeps pulling offensive-surveillance firms into bulk-data products, regulatory attention shifts from who the tools target to how the input data was obtained — an open question the current export-control framework barely addresses.
  • Each documented misuse compounds NSO's legal exposure trajectory: with courts already finding it liable for the 2019 hacking of more than 1,400 WhatsApp users across 51 countries, location-data findings give plaintiffs and regulators a second line of attack.

The trend: Spyware vendors' pivot into pandemic public-health markets is turning unvetted data provenance into the next front in the governance fight over commercial surveillance.

Discussion

  • @evacide Eva on x
    This is your regular reminder that NSO Group is bad and @zackwhittaker is good. https://techcrunch.com/...
  • @josephfcox Joseph Cox on x
    Beyond their misleading earlier statement, why would they not use real location data to demonstrate a product. The billion dollar location data industry with dozens of companies is based on very real location data, trading this information everyday. https://twitter.com/...
  • @marietjeschaake Marietje Schaake on x
    What standards to expect from hackers for hire? ↘️ https://twitter.com/...
  • @zackwhittaker Zack Whittaker on x
    The researchers said if the data is real, then NSO “violated the privacy” of 32,000 individuals across Rwanda, Israel, Bahrain, Saudi Arabia and the United Arab Emirates (all said to have used NSO's spyware). NSO, predictably, denied the allegations. More: https://techcrunch.com/…
  • @profcarroll @profcarroll on x
    Adtech location data collected by unknown parties in unknown contexts with unknown consent for unknown purposes proves irresistibly useful for laundering the reputation of a most notorious spyware vendor. #covidwashing https://twitter.com/...