Sources: in November 2021, five days after Joe Biden put NSO on a Commerce Department blocklist, a US government front company licensed NSO's geolocation tool
The Biden administration has been trying to choke off use of hacking tools made by the Israeli firm NSO.
What changed today: per the New York Times, five days after that blocklisting took effect, a US government front company licensed NSO's geolocation tool — meaning the same administration restricting the vendor was also acquiring from it, through an intermediary. That reframes the earlier finding that the FBI had bought but never deployed Pegasus from an abandoned purchase into evidence of a more durable procurement channel running parallel to the sanctions policy.
First-order effects
Commerce's blocklist of NSO is exposed as porous by design: a US government entity accessed NSO technology days after the listing, directly undercutting the department's stated goal of choking off use of NSO's hacking tools.
NSO faces a credibility crisis with both audiences at once — Western clients who bought on the promise of legitimate use, and US officials who now have documented proof the firm sold into the very government sanctioning it.
Second-order effects
Congressional overseers and watchdogs get a concrete case study for auditing how spyware licenses flow through front companies, putting pressure on Commerce to either tighten the blocklist's exemptions or explain them.
Other commercial-spyware vendors on the November sanctions list gain an argument that the controls are selectively enforced, complicating allied coordination against the spyware trade that NSO's client-misuse scandal had started.
Third-order effects
If front-company procurement proves standard practice, export-control regimes against surveillance tech will be understood as managing — not preventing — government access, pushing oversight debates from whether agencies buy these tools to under what disclosure they do.
The episode points toward structural separation between public anti-spyware diplomacy and quiet intelligence demand, which will shape how democracies regulate an industry whose biggest buyer may be their own security services.
The trend: Governments are increasingly pursuing a dual track on commercial spyware — publicly sanctioning vendors like NSO while privately procuring their tools through intermediaries — making export controls a management instrument rather than a prohibition.
NEW: Days after the White House in 2021 blacklisted NSO, the notorious Israeli hacking firm, a secret contract was signed for a hacking tool. The contract states that the USG is the user. A thread https://www.nytimes.com/...
NSO Group-#Pegasus, gave the U.S. government access to a geolocation tool that can covertly track mobile phones around the world without the phone user's knowledge or consent. It specifically against targets of its choice in #Mexico. https://www.nytimes.com/...
The Biden administration has been trying to end the use of spyware made by the Israeli firm NSO. It turns out that not every part of the government got the message. A secret government contract violates the public policy, and still appears to be active. https://www.nytimes.com/..…
The 🇺🇸 USG is comprised of *18* very large, well resourced, big budget intel agencies that explore, test, and procure many surveillance tools, products and services. I'd be more shocked if NSO & its various front companies *had not* made at least some deal, somewhere...
Painful investigation about the use of NSO's spyware by the US. The new Executive Order should make that impossible now, but only when enforcement is meaningful ↘️ https://www.nytimes.com/...
A front company in New Jersey signed the contract for the unknown gov agency. The company - “Cleopatra Holdings” - is actually Riva Networks, the same company the FBI used two years earlier to purchase Pegasus. https://twitter.com/...
“...Novalpina had to address concern within American spy agencies that the tools posed a counterintelligence risk — that they might contain back doors that would allow Mossad or other Israeli intelligence services to gain access to American secrets....” https://www.nytimes.com/..…
The Biden administration banned any U.S. government use of highly intrusive spyware developed by the Israeli firm, NSO Group. The spyware has been used to hack the phones of dissidents and journalists. Some part of the US government didn't get the message. https://www.nytimes.com…
Wow. “Asked about the contract, White House officials said it was news to them.” And ODNI wouldn't comment. Someone appears to be violating the rules here... Great reporting. https://twitter.com/...
Under the NSO contract, U.S. officials had access to a special portal that let them to type in mobile phone numbers. The Landmark geolocation tool then pinpointed the phone's specific location at that moment without the phone user's knowledge. https://www.nytimes.com/...
New reporting by @ronenbergman and @MarkMazzettiNYT says the U.S. government purchased a surveillance tool from NSO called Landmark. The tool allows the operator to identify someone's location based on their phone number. https://www.nytimes.com/...
“Landmark”, the product bought here, is not a hacking tool. It is a surveillance tool based on SS7 (see our coverage here https://www.vice.com/...). Sounds pedantic, but it's a key distinction when governments are clamping down on commercial spyware. Landmark is not that. https:/…
As I wrote in my book, a lot of these sales take advantage of the siloed nature of US government. Most US agencies don't realize their neighbors have already paid for the same tool. Or in this case, the White House didn't know about this sale of NSO even as it restricted its sale
Biden administration has been trying to choke off use of hacking tools made by Israeli firm NSO. It turns out that not every part of government has gotten message: A secret contract violates the administration's own policy, and still appears to be active. https://www.nytimes.com/…
In Nov 2021, Biden admin blacklisted NSO. Days later, NSO's U.S. affiliate entered into contract with “Cleopatra Holdings” — Riva Networks — to give U.Sgov access to NSO's geolocation tool. Fake “Bill Malone” signed the deal. This is the address listed👇 https://www.nytimes.com/..…
Read the whole story. These front companies and fake signatories are why it's so hard to track the flow of spyware and zero days to governments around the world. This reads like a map. https://www.nytimes.com/...