US court document: NSO Group's Pegasus was used to target 1,223 WhatsApp users in 51 countries in a 2019 attack; Mexico led with 456 victims and India had 100
NSO Group's notorious spyware Pegasus was used to target 1,223 WhatsApp users in 51 different countries during a 2019 hacking campaign, according to a new court document.
Context & Ripple Effects
The filing adds a more granular country-by-country record to WhatsApp's long-running account of the 2019 campaign. Earlier coverage put the affected population at roughly 1,400 devices and described WhatsApp's suit against NSO after its investigation; a later disclosure of the two-week attack window reinforced the scale of that incident.
India had already been singled out in WhatsApp's 2019 notification, which said 121 users were targeted, including activists, journalists, and civil-rights lawyers. The court record now situates that national disclosure within a broader cross-border campaign, while showing Mexico as the largest reported concentration.
First-order effects
- The document gives WhatsApp and its legal case a more specific evidentiary account of who was targeted and where, including 456 people in Mexico and 100 in India.
- People and organizations in the named countries gain a clearer basis to assess whether the 2019 campaign affected their communities; the reported India total can be compared with WhatsApp's earlier notice to 121 Indian users.
Second-order effects
- The geographic breakdown increases pressure on NSO and any government customers implicated by the targeting to explain selection, oversight, and redress practices; it also gives civil-society investigators a more focused set of jurisdictions to examine.
- For messaging platforms, the case underscores that a single service vulnerability can create a multinational incident, strengthening the business case for rapid patching, victim notification, and litigation-backed attribution.
Third-order effects
- If court discovery continues to expose operational detail, commercial spyware suppliers may face a less opaque market: platform lawsuits can turn technical incident data into public accountability records.
- The broader structural issue is cross-border governance of dual-use intrusion tools. Whether disclosure produces durable constraints depends on how courts and national authorities act on records like this, not on the filing alone.
The trend: This is one data point in the shift from opaque commercial spyware operations toward platform-led attribution and court-driven disclosure of their cross-border effects.