A researcher found NSO Group's contact tracing system, codenamed “Fleming”, unprotected on the Internet, NSO says system was a demo, hence not a security lapse
As countries work to reopen after weeks of lockdown, contact-tracing apps help to understand the spread of the deadly coronavirus strain, COVID-19. Tweets: @lorenzofb , @rj_gallagher , @campuscodi , @malwarejake , @zackwhittaker , @zackwhittaker , and @zackwhittaker Tweets: Lorenzo Franceschi-Bicchierai / @lorenzofb : Uh oh. NSO left a database of location data unprotected on the internet. The company says it was just a demo, but still. https://techcrunch.com/... Ryan Gallagher / @rj_gallagher : Researcher finds unprotected server revealing contact tracing system developed by Israeli spyware company NSO Group; company denies security lapse, says it contained dummy data for demonstration purposes: https://techcrunch.com/... Catalin Cimpanu / @campuscodi : This is what I've heard as well Also, the mystery behind this silly tweet: https://twitter.com/... https://twitter.com/... Jake Williams / @malwarejake : Nothing is ever an issue at NSO... https://twitter.com/... Zack Whittaker / @zackwhittaker : NSO is also accused of selling advanced mobile spyware used by the Saudis to hack into Jeff Bezos' phone (which NSO denies) and allegedly developing a WhatsApp exploit that targeted 1,400 users (which NSO also denies!). Anyway, here's the story for more. https://techcrunch.com/... Zack Whittaker / @zackwhittaker : Whether the data is “real” or not, experts expressed major concerns over the use of centralized location data, fearing that it could become a target for hackers. Also, @jsrailton told me that location data isn't even that good for contact tracing!
Context & Ripple Effects
NSO Group, best known for Pegasus spyware sales in Gulf states worth hundreds of millions, pivoted in spring 2020 to pitching a contact-tracing product: software that uses mobile phone data to monitor and predict COVID-19 spread, with countries already testing it. Fleming is that system — and a researcher has now found an instance of it sitting unprotected on the open internet.
NSO's defense is that the exposed system was merely a demo, not production infrastructure. That framing matters because researchers later reported the company [[a:961578|used location data from thousands of unsuspecting people while pitching its contact-tracing tech to governments and journalists]] — meaning even 'demo' deployments were handling real people's movement data.
First-order effects
- Governments currently evaluating Fleming demos now have to weigh that the vendor's own exposure controls failed on at least one internet-facing instance, directly undercutting the trust a contact-tracing purchase depends on.
Second-order effects
- The incident feeds the broader backlash documented against pandemic surveillance: countries that raced to deploy coronavirus-tracking software are already fielding complaints over extensive data mining and poor security practices, giving critics a named example from a top-tier spyware vendor.
Third-order effects
- If spyware firms keep repackaging interception capabilities as public-health products, the pattern points toward formal procurement scrutiny and export-style oversight for vendors selling epidemiological surveillance to states — a shift NSO's US lobbying rebuff suggests is already hardening.
The trend: Pandemic-era demand is pulling commercial spyware vendors into public-health surveillance, exposing a gap between their sales claims and their operational security.