/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Citizen Lab: the iPhone of Ben Hubbard, an American reporter for NYT, was hacked in 2020 and 2021, likely by Saudi Arabia using NSO's Pegasus; NSO denies claim

Invasive hacking software sold to countries to fight terrorism is easily abused.  Researchers say my phone was hacked twice, probably by Saudi Arabia. Source: The Citizen Lab .

New York Times Ben Hubbard

Context & Ripple Effects

Ben Hubbard is not an incidental victim: he covers Saudi Arabia for the New York Times, and his phone was hit twice, in 2020 and again in 2021 — meaning the campaign resumed even after the first compromise was later discovered. Citizen Lab's attribution lands on a pattern it has already documented: the same lab traced Saudi use of Pegasus against Jeff Bezos' phone, caught zero-click iMessage exploits hitting Al Jazeera reporters on iOS 13.5.1, and reported NSO deals worth hundreds of millions of dollars across Gulf states.

What is new here is the target class: a working American correspondent at a US newsroom, not an activist or a foreign rival. That widens the blast radius from 'dissidents abroad' to the Western press corps itself, which changes how the story reads inside American media and policy circles.

First-order effects

  • Hubbard and NYT now operate under confirmed device compromise spanning two years, forcing source-communication practices to assume phone-level surveillance; NSO's public denial puts it back on defense over whether it can police its own government customers.

Second-order effects

  • The finding pressures Apple to keep hardening iOS and expand its breach-notification program — the mechanism that later flagged Thai activists and rights supporters in Citizen Lab's follow-up work — because every confirmed Pegasus case is a marketing problem for its security posture.

Third-order effects

  • If state customers keep aiming 'terrorism-fighting' tools at journalists, the spyware industry faces structural responses beyond naming-and-shaming: export-control pressure, litigation risk from platforms like Apple, and news organizations treating mobile devices as hostile endpoints by default.

The trend: Commercial spyware is migrating from dissident surveillance toward Western journalists and executives, pushing platform vendors into the role of de facto counterintelligence providers.

Discussion

  • @jsrailton John Scott-Railton on x
    NEW: iPhone of @NYTBen was hacked with #Pegasus spyware *after* he complained to NSO Group about previous targeting. THREAD Our @citizenlab investigation: https://citizenlab.ca/... https://twitter.com/...
  • @nytben @nytben on x
    After yet another hacking scare, I decided to work with @citizenlab to see what they could find. Had I been hacked? With what? By whom? What, if any, of my info was stolen? Here are the results, with a number of questions left unanswered. https://www.nytimes.com/...
  • @film_girl Chriscreama Warren on x
    This is so fucked up and so beyond scary. I don't even know the solution b/c even if you have a separate device, you can still be a target https://citizenlab.ca/...
  • @nytben @nytben on x
    And here is @citizenlab's more technical write up of what they found. https://citizenlab.ca/...
  • @doctorow Cory Doctorow on x
    As we see with the NSO Group hacks, Apple's process misses defects that put its customers in mortal danger. For obvious reasons, companies aren't good stewards who gets to criticize their products, and how. 26/
  • @jsrailton John Scott-Railton on x
    4/ You'd think NSO Group would have taken some kind of action given the negative publicity but... @billmarczak's latest forensic analysis finds that in the past 2 years, @NYTBen was *repeatedly* hacked with #Pegasus spyware using zero-click exploits. https://twitter.com/...
  • @doctorow Cory Doctorow on x
    Apple has patched that bug, thankfully, but it's certainly not the last defect that will creep into the Iphone's operating systems (indeed, similar defects might lurk in current versions). 21/
  • @jsrailton John Scott-Railton on x
    3/ A member of the @nytimes tech security team later found another #Pegasus infection attempt from 2018. Here it is, inviting him to cover a protest at the #Saudi embassy in Washington DC. Clicking on the link would infect his device with the spyware. https://twitter.com/...
  • @adamgoldmannyt Adam Goldman on x
    In the two attempts in 2018, it appeared that Saudi Arabia had launched the attacks because they came from servers run by an operator who had previously targeted a number of Saudi activists. https://www.nytimes.com/...
  • @doctorow Cory Doctorow on x
    Rather than directing its fire against security researchers who find and disclose its bugs, Apple should follow Whatsapp's lead and sue the NSO Group for exploiting its technology: https://www.vice.com/... 32/
  • @farnazfassihi Farnaz Fassihi on x
    Beirut bureau chief @NYTBen writes about how he was hacked, twice probably by Saudi Arabia. How finding definite answers even by experts was elusive. How we are all vulnerable in this global game of hacking. https://www.nytimes.com/...
  • @jsrailton John Scott-Railton on x
    2/ It began in 2018: @NYTBen shared a suspicious message with my colleague @billmarczak. It was a #Pegasus infection attempt. We @citizenlab attributed it to #SaudiArabia. Ben wrote it up & complained to NSO Group. NSO issued a predictable denial. https://twitter.com/...
  • @jsrailton John Scott-Railton on x
    5/ Of course, NSO Group has again issued a denial. Truth is: as long as NSO helps autocrats hack...they will keep infecting journalists. #Pegasus spyware enables these enemies of democracy to export their wretched repression around the globe. https://twitter.com/...
  • @doctorow Cory Doctorow on x
    Most recently, Apple attacked @CorelliumHQ, a tool that allows independent security researchers to investigate the inner workers of Apple's software to uncover defects. https://www.technologyreview.com/ ... (Apple lost the suit, thankfully) 29/
  • @doctorow Cory Doctorow on x
    It should terminate the accounts - personal and commercial - associated with NSO Group employees and executives and permanently bar them from using its services. 33/
  • @ghadaoueiss @ghadaoueiss on x
    I am a victim of spyware. My photos were stolen&used to smear me across social media and the press. No one should have to go through this. No journalist, activist, academic or citizen should feel unsafe just for owning a phone. We need to fight for the right to privacy! https://t…
  • @ragipsoylu @ragipsoylu on x
    Not surprised the least that @NYTBen was also hacked by Saudi government through Pegasus. I was also in their list since 2018 and only traces belonging to this year, numerous times between February to July https://www.nytimes.com/...
  • @dr_ulrichsen Kristian Ulrichsen on x
    ‘I have been writing about Saudi Arabia for years & published a book last year about Crown Prince Mohammed bin Salman, so Saudi Arabia might have reasons for wanting to peek inside my phone (...) Did they steal my contacts so they could arrest my sources?’ https://www.nytimes.com…
  • @doctorow Cory Doctorow on x
    These are the scariest kinds of security defects, since there's nothing you, as the owner of an Iphone, can do to defend yourself against them. 20/
  • @akiperitz Aki Peritz on x
    Did those amoral businessmen of NSO Group specifically say that US emails & IP “couldn't be infected by their spyware https://twitter.com/...
  • @jsrailton John Scott-Railton on x
    6/ Remember the #pegasusproject? Yeah, @NYTBen 's number is on that list of potential targets, too. Along with @nytimes colleague @azamsahmed who extensively reported on Pegasus in Mexico. July report by @ronenbergman & @PatrickKingsley: https://www.nytimes.com/... https://twitte…
  • @adam_k_levin Adam Levin on x
    “As long as we store our lives on devices that have vulnerabilities, and surveillance companies can earn millions of dollars selling ways to exploit them, our defenses are limited, especially if a government decides it wants our data.” https://www.nytimes.com/...
  • @kenroth Kenneth Roth on x
    Israeli spyware NSO Group “canceled its contracts with Saudi Arabia” after Saudis killed Khashoggi. NSO resumed the following year with “contractual restrictions.” It cancelled again when the Saudis used its spyware to hack phones of 36 Al Jazeera staff. https://www.nytimes.com/.…
  • @jsrailton John Scott-Railton on x
    7/ @NYTBen in his own words. If we don't reign in the spyware industry now, this fear, harm and uncertainty will become awfully commonplace. https://www.nytimes.com/... https://twitter.com/...
  • @citizenlab @citizenlab on x
    Read @NYTBen's account of our investigation of how we discovered his phone was hacked with Pegasus @nytimes: I Was Hacked. The Spyware Used Against Me Makes Us All Vulnerable. https://www.nytimes.com/...
  • @zittrain Jonathan Zittrain on x
    Amazing work by @RonDeibert and @citizenlab tracking the hacking of journalists' iPhones by government(s) https://twitter.com/...
  • @gossithedog Kevin Beaumont on x
    this area probably needs regulating by governments. https://twitter.com/...