/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

A researcher found NSO Group's contact tracing system, codenamed “Fleming”, unprotected on the Internet, NSO says system was a demo, hence not a security lapse

As countries work to reopen after weeks of lockdown, contact-tracing apps help to understand the spread of the deadly coronavirus strain, COVID-19. Tweets: @lorenzofb , @rj_gallagher , @campuscodi , @malwarejake , @zackwhittaker , @zackwhittaker , and @zackwhittaker Tweets: Lorenzo Franceschi-Bicchierai / @lorenzofb : Uh oh. NSO left a database of location data unprotected on the internet. The company says it was just a demo, but still. https://techcrunch.com/... Ryan Gallagher / @rj_gallagher : Researcher finds unprotected server revealing contact tracing system developed by Israeli spyware company NSO Group; company denies security lapse, says it contained dummy data for demonstration purposes: https://techcrunch.com/... Catalin Cimpanu / @campuscodi : This is what I've heard as well Also, the mystery behind this silly tweet: https://twitter.com/... https://twitter.com/... Jake Williams / @malwarejake : Nothing is ever an issue at NSO... https://twitter.com/... Zack Whittaker / @zackwhittaker : NSO is also accused of selling advanced mobile spyware used by the Saudis to hack into Jeff Bezos' phone (which NSO denies) and allegedly developing a WhatsApp exploit that targeted 1,400 users (which NSO also denies!). Anyway, here's the story for more. https://techcrunch.com/... Zack Whittaker / @zackwhittaker : Whether the data is “real” or not, experts expressed major concerns over the use of centralized location data, fearing that it could become a target for hackers. Also, @jsrailton told me that location data isn't even that good for contact tracing!

TechCrunch Zack Whittaker

Context & Ripple Effects

NSO Group, best known for Pegasus spyware sales in Gulf states worth hundreds of millions, pivoted in spring 2020 to pitching a contact-tracing product: software that uses mobile phone data to monitor and predict COVID-19 spread, with countries already testing it. Fleming is that system — and a researcher has now found an instance of it sitting unprotected on the open internet.

NSO's defense is that the exposed system was merely a demo, not production infrastructure. That framing matters because researchers later reported the company [[a:961578|used location data from thousands of unsuspecting people while pitching its contact-tracing tech to governments and journalists]] — meaning even 'demo' deployments were handling real people's movement data.

First-order effects

  • Governments currently evaluating Fleming demos now have to weigh that the vendor's own exposure controls failed on at least one internet-facing instance, directly undercutting the trust a contact-tracing purchase depends on.

Second-order effects

  • The incident feeds the broader backlash documented against pandemic surveillance: countries that raced to deploy coronavirus-tracking software are already fielding complaints over extensive data mining and poor security practices, giving critics a named example from a top-tier spyware vendor.

Third-order effects

  • If spyware firms keep repackaging interception capabilities as public-health products, the pattern points toward formal procurement scrutiny and export-style oversight for vendors selling epidemiological surveillance to states — a shift NSO's US lobbying rebuff suggests is already hardening.

The trend: Pandemic-era demand is pulling commercial spyware vendors into public-health surveillance, exposing a gap between their sales claims and their operational security.

Discussion

  • @lorenzofb Lorenzo Franceschi-Bicchierai on x
    Uh oh. NSO left a database of location data unprotected on the internet. The company says it was just a demo, but still. https://techcrunch.com/...
  • @rj_gallagher Ryan Gallagher on x
    Researcher finds unprotected server revealing contact tracing system developed by Israeli spyware company NSO Group; company denies security lapse, says it contained dummy data for demonstration purposes: https://techcrunch.com/...
  • @campuscodi Catalin Cimpanu on x
    This is what I've heard as well Also, the mystery behind this silly tweet: https://twitter.com/... https://twitter.com/...
  • @malwarejake Jake Williams on x
    Nothing is ever an issue at NSO... https://twitter.com/...
  • @zackwhittaker Zack Whittaker on x
    NSO is also accused of selling advanced mobile spyware used by the Saudis to hack into Jeff Bezos' phone (which NSO denies) and allegedly developing a WhatsApp exploit that targeted 1,400 users (which NSO also denies!). Anyway, here's the story for more. https://techcrunch.com/..…
  • @zackwhittaker Zack Whittaker on x
    Whether the data is “real” or not, experts expressed major concerns over the use of centralized location data, fearing that it could become a target for hackers. Also, @jsrailton told me that location data isn't even that good for contact tracing! More: https://techcrunch.com/...…
  • @zackwhittaker Zack Whittaker on x
    New: Spyware firm NSO Group secured an unprotected server after it was found online. NSO says it was a demo for its coronavirus contact-tracing system. But experts say any centralized database of citizens' location data poses a security and privacy risk. https://techcrunch.com/..…