/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Sources: in November 2021, five days after Joe Biden put NSO on a Commerce Department blocklist, a US government front company licensed NSO's geolocation tool

The Biden administration has been trying to choke off use of hacking tools made by the Israeli firm NSO.

New York Times

Context & Ripple Effects

The report lands at the end of a year-long escalation between Washington and NSO. In mid-2021, NSO temporarily blocked several government clients worldwide while investigating possible misuse of its tools; weeks later, Commerce announced rules banning export or resale of hacking tools like Pegasus to countries of concern, and in November the department formally sanctioned NSO alongside three other spyware vendors.

What changed today: per the New York Times, five days after that blocklisting took effect, a US government front company licensed NSO's geolocation tool — meaning the same administration restricting the vendor was also acquiring from it, through an intermediary. That reframes the earlier finding that the FBI had bought but never deployed Pegasus from an abandoned purchase into evidence of a more durable procurement channel running parallel to the sanctions policy.

First-order effects

  • Commerce's blocklist of NSO is exposed as porous by design: a US government entity accessed NSO technology days after the listing, directly undercutting the department's stated goal of choking off use of NSO's hacking tools.
  • NSO faces a credibility crisis with both audiences at once — Western clients who bought on the promise of legitimate use, and US officials who now have documented proof the firm sold into the very government sanctioning it.

Second-order effects

  • Congressional overseers and watchdogs get a concrete case study for auditing how spyware licenses flow through front companies, putting pressure on Commerce to either tighten the blocklist's exemptions or explain them.
  • Other commercial-spyware vendors on the November sanctions list gain an argument that the controls are selectively enforced, complicating allied coordination against the spyware trade that NSO's client-misuse scandal had started.

Third-order effects

  • If front-company procurement proves standard practice, export-control regimes against surveillance tech will be understood as managing — not preventing — government access, pushing oversight debates from whether agencies buy these tools to under what disclosure they do.
  • The episode points toward structural separation between public anti-spyware diplomacy and quiet intelligence demand, which will shape how democracies regulate an industry whose biggest buyer may be their own security services.

The trend: Governments are increasingly pursuing a dual track on commercial spyware — publicly sanctioning vendors like NSO while privately procuring their tools through intermediaries — making export controls a management instrument rather than a prohibition.

Discussion

  • @markmazzettinyt Mark Mazzetti on x
    NEW: Days after the White House in 2021 blacklisted NSO, the notorious Israeli hacking firm, a secret contract was signed for a hacking tool. The contract states that the USG is the user. A thread https://www.nytimes.com/...
  • @dorisgomora Doris Gomora on x
    NSO Group-#Pegasus, gave the U.S. government access to a geolocation tool that can covertly track mobile phones around the world without the phone user's knowledge or consent. It specifically against targets of its choice in #Mexico. https://www.nytimes.com/...
  • @nytimes @nytimes on x
    The Biden administration has been trying to end the use of spyware made by the Israeli firm NSO. It turns out that not every part of the government got the message. A secret government contract violates the public policy, and still appears to be active. https://www.nytimes.com/..…
  • @rondeibert @rondeibert on x
    The 🇺🇸 USG is comprised of *18* very large, well resourced, big budget intel agencies that explore, test, and procure many surveillance tools, products and services. I'd be more shocked if NSO & its various front companies *had not* made at least some deal, somewhere...
  • @jonathandata1 Jonathan Scott on x
    Who is going to tell @nytimes that an SS7 monitoring tool is NOT a hacking tool? It does NOT hack into your device. https://twitter.com/...
  • @marietjeschaake @marietjeschaake on x
    Painful investigation about the use of NSO's spyware by the US. The new Executive Order should make that impossible now, but only when enforcement is meaningful ↘️ https://www.nytimes.com/...
  • @kimzetter Kim Zetter on x
    A front company in New Jersey signed the contract for the unknown gov agency. The company - “Cleopatra Holdings” - is actually Riva Networks, the same company the FBI used two years earlier to purchase Pegasus. https://twitter.com/...
  • @evacide Eva on x
    Spyware for me but not for thee. https://twitter.com/...
  • @arifcrafiq Arif Rafiq on x
    “...Novalpina had to address concern within American spy agencies that the tools posed a counterintelligence risk — that they might contain back doors that would allow Mossad or other Israeli intelligence services to gain access to American secrets....” https://www.nytimes.com/..…
  • @kenroth Kenneth Roth on x
    The Biden administration banned any U.S. government use of highly intrusive spyware developed by the Israeli firm, NSO Group. The spyware has been used to hack the phones of dissidents and journalists. Some part of the US government didn't get the message. https://www.nytimes.com…
  • @ericgeller Eric Geller on x
    Wow. “Asked about the contract, White House officials said it was news to them.” And ODNI wouldn't comment. Someone appears to be violating the rules here... Great reporting. https://twitter.com/...
  • @avischarf Avi Scharf on x
    Under the NSO contract, U.S. officials had access to a special portal that let them to type in mobile phone numbers. The Landmark geolocation tool then pinpointed the phone's specific location at that moment without the phone user's knowledge. https://www.nytimes.com/...
  • @runasand Runa Sandvik on x
    New reporting by @ronenbergman and @MarkMazzettiNYT says the U.S. government purchased a surveillance tool from NSO called Landmark. The tool allows the operator to identify someone's location based on their phone number. https://www.nytimes.com/...
  • @josephfcox Joseph Cox on x
    “Landmark”, the product bought here, is not a hacking tool. It is a surveillance tool based on SS7 (see our coverage here https://www.vice.com/...). Sounds pedantic, but it's a key distinction when governments are clamping down on commercial spyware. Landmark is not that. https:/…
  • @nicoleperlroth Nicole Perlroth on x
    As I wrote in my book, a lot of these sales take advantage of the siloed nature of US government. Most US agencies don't realize their neighbors have already paid for the same tool. Or in this case, the White House didn't know about this sale of NSO even as it restricted its sale
  • @shibleytelhami Shibley Telhami on x
    Biden administration has been trying to choke off use of hacking tools made by Israeli firm NSO. It turns out that not every part of government has gotten message: A secret contract violates the administration's own policy, and still appears to be active. https://www.nytimes.com/…
  • @avischarf Avi Scharf on x
    In Nov 2021, Biden admin blacklisted NSO. Days later, NSO's U.S. affiliate entered into contract with “Cleopatra Holdings” — Riva Networks — to give U.Sgov access to NSO's geolocation tool. Fake “Bill Malone” signed the deal. This is the address listed👇 https://www.nytimes.com/..…
  • @nicoleperlroth Nicole Perlroth on x
    Read the whole story. These front companies and fake signatories are why it's so hard to track the flow of spyware and zero days to governments around the world. This reads like a map. https://www.nytimes.com/...
  • @cooperq @cooperq on x
    SS7 is the underpinning of our entire world wide phone system and it's a security nightmare. https://twitter.com/...