Sources: FBI has probed Israeli spyware vendor NSO Group for its possible role in hacks of US residents, companies and intel gathering on governments since 2017
(Reuters) - The FBI is investigating the role of Israeli spyware vendor NSO Group Technologies in possible hacks on American residents …
Context & Ripple Effects
NSO Group's public line — that it builds hacking tools but never spies with them itself — was already fraying before this report: in US lawsuits, court documents allegedly showed the company snooping on calls to close sales, and an Israeli indictment charged an employee with trying to sell stolen Pegasus source code. The Reuters sourcing adds a federal dimension: the FBI has been probing NSO's possible role in hacks of American residents and companies since 2017.
That probe turned out to be a leading indicator. Within two years, Israel opened its own investigation and visited NSO's Tel Aviv office over Pegasus abuse allegations, the company temporarily blocked several government clients worldwide while auditing misuse, and a sweeping investigation found Pegasus deployed by the CIA, UAE, Mexico and Saudi Arabia — with the FBI having bought Pegasus but never deploying it.
First-order effects
- NSO faces direct US legal exposure: a multi-year FBI probe into hacks of American residents and companies puts any US sales ambitions and existing relationships under federal scrutiny.
- The company's 'we don't spy' defense, already undercut by court filings in the 2018 lawsuits, now has to survive a criminal-level investigation rather than just civil discovery.
Second-order effects
- Government clients inherit the reputational and legal risk: NSO's own client-blocking review and Israel's domestic investigation signal that buyer states must audit deployments or distance themselves publicly.
- Named users such as the CIA, UAE, Mexico and Saudi Arabia face pressure to justify Pegasus operations against their own citizens and allies, complicating future procurement from Western vendors.
Third-order effects
- If the pattern holds, commercial spyware vendors shift from lightly-scrutinized exporters to targets of criminal investigation by customer-state governments, raising the compliance bar across the sector.
- The FBI's buy-but-don't-use posture suggests Western law enforcement increasingly treats offensive hacking tools as investigative subjects rather than procurement options — a structural split between buyers and regulators.
The trend: Governments are pivoting from being covert customers of commercial spyware to investigating the vendors themselves, with national investigations and client audits replacing quiet procurement.