Citizen Lab: the iPhone of Ben Hubbard, an American reporter for NYT, was hacked in 2020 and 2021, likely by Saudi Arabia using NSO's Pegasus; NSO denies claim
Invasive hacking software sold to countries to fight terrorism is easily abused. Researchers say my phone was hacked twice, probably by Saudi Arabia. Source: The Citizen Lab .
New York TimesBen Hubbard
Context & Ripple Effects
Ben Hubbard is not an incidental victim: he covers Saudi Arabia for the New York Times, and his phone was hit twice, in 2020 and again in 2021 — meaning the campaign resumed even after the first compromise was later discovered. Citizen Lab's attribution lands on a pattern it has already documented: the same lab traced Saudi use of Pegasus against Jeff Bezos' phone, caught zero-click iMessage exploits hitting Al Jazeera reporters on iOS 13.5.1, and reported NSO deals worth hundreds of millions of dollars across Gulf states.
What is new here is the target class: a working American correspondent at a US newsroom, not an activist or a foreign rival. That widens the blast radius from 'dissidents abroad' to the Western press corps itself, which changes how the story reads inside American media and policy circles.
First-order effects
Hubbard and NYT now operate under confirmed device compromise spanning two years, forcing source-communication practices to assume phone-level surveillance; NSO's public denial puts it back on defense over whether it can police its own government customers.
Second-order effects
The finding pressures Apple to keep hardening iOS and expand its breach-notification program — the mechanism that later flagged Thai activists and rights supporters in Citizen Lab's follow-up work — because every confirmed Pegasus case is a marketing problem for its security posture.
Third-order effects
If state customers keep aiming 'terrorism-fighting' tools at journalists, the spyware industry faces structural responses beyond naming-and-shaming: export-control pressure, litigation risk from platforms like Apple, and news organizations treating mobile devices as hostile endpoints by default.
The trend: Commercial spyware is migrating from dissident surveillance toward Western journalists and executives, pushing platform vendors into the role of de facto counterintelligence providers.
NEW: iPhone of @NYTBen was hacked with #Pegasus spyware *after* he complained to NSO Group about previous targeting. THREAD Our @citizenlab investigation: https://citizenlab.ca/... https://twitter.com/...
After yet another hacking scare, I decided to work with @citizenlab to see what they could find. Had I been hacked? With what? By whom? What, if any, of my info was stolen? Here are the results, with a number of questions left unanswered. https://www.nytimes.com/...
This is so fucked up and so beyond scary. I don't even know the solution b/c even if you have a separate device, you can still be a target https://citizenlab.ca/...
As we see with the NSO Group hacks, Apple's process misses defects that put its customers in mortal danger. For obvious reasons, companies aren't good stewards who gets to criticize their products, and how. 26/
4/ You'd think NSO Group would have taken some kind of action given the negative publicity but... @billmarczak's latest forensic analysis finds that in the past 2 years, @NYTBen was *repeatedly* hacked with #Pegasus spyware using zero-click exploits. https://twitter.com/...
Apple has patched that bug, thankfully, but it's certainly not the last defect that will creep into the Iphone's operating systems (indeed, similar defects might lurk in current versions). 21/
3/ A member of the @nytimes tech security team later found another #Pegasus infection attempt from 2018. Here it is, inviting him to cover a protest at the #Saudi embassy in Washington DC. Clicking on the link would infect his device with the spyware. https://twitter.com/...
In the two attempts in 2018, it appeared that Saudi Arabia had launched the attacks because they came from servers run by an operator who had previously targeted a number of Saudi activists. https://www.nytimes.com/...
Rather than directing its fire against security researchers who find and disclose its bugs, Apple should follow Whatsapp's lead and sue the NSO Group for exploiting its technology: https://www.vice.com/... 32/
Beirut bureau chief @NYTBen writes about how he was hacked, twice probably by Saudi Arabia. How finding definite answers even by experts was elusive. How we are all vulnerable in this global game of hacking. https://www.nytimes.com/...
2/ It began in 2018: @NYTBen shared a suspicious message with my colleague @billmarczak. It was a #Pegasus infection attempt. We @citizenlab attributed it to #SaudiArabia. Ben wrote it up & complained to NSO Group. NSO issued a predictable denial. https://twitter.com/...
5/ Of course, NSO Group has again issued a denial. Truth is: as long as NSO helps autocrats hack...they will keep infecting journalists. #Pegasus spyware enables these enemies of democracy to export their wretched repression around the globe. https://twitter.com/...
Most recently, Apple attacked @CorelliumHQ, a tool that allows independent security researchers to investigate the inner workers of Apple's software to uncover defects. https://www.technologyreview.com/ ... (Apple lost the suit, thankfully) 29/
It should terminate the accounts - personal and commercial - associated with NSO Group employees and executives and permanently bar them from using its services. 33/
I am a victim of spyware. My photos were stolen&used to smear me across social media and the press. No one should have to go through this. No journalist, activist, academic or citizen should feel unsafe just for owning a phone. We need to fight for the right to privacy! https://t…
Not surprised the least that @NYTBen was also hacked by Saudi government through Pegasus. I was also in their list since 2018 and only traces belonging to this year, numerous times between February to July https://www.nytimes.com/...
‘I have been writing about Saudi Arabia for years & published a book last year about Crown Prince Mohammed bin Salman, so Saudi Arabia might have reasons for wanting to peek inside my phone (...) Did they steal my contacts so they could arrest my sources?’ https://www.nytimes.com…
6/ Remember the #pegasusproject? Yeah, @NYTBen 's number is on that list of potential targets, too. Along with @nytimes colleague @azamsahmed who extensively reported on Pegasus in Mexico. July report by @ronenbergman & @PatrickKingsley: https://www.nytimes.com/... https://twitte…
“As long as we store our lives on devices that have vulnerabilities, and surveillance companies can earn millions of dollars selling ways to exploit them, our defenses are limited, especially if a government decides it wants our data.” https://www.nytimes.com/...
Israeli spyware NSO Group “canceled its contracts with Saudi Arabia” after Saudis killed Khashoggi. NSO resumed the following year with “contractual restrictions.” It cancelled again when the Saudis used its spyware to hack phones of 36 Al Jazeera staff. https://www.nytimes.com/.…
7/ @NYTBen in his own words. If we don't reign in the spyware industry now, this fear, harm and uncertainty will become awfully commonplace. https://www.nytimes.com/... https://twitter.com/...
Read @NYTBen's account of our investigation of how we discovered his phone was hacked with Pegasus @nytimes: I Was Hacked. The Spyware Used Against Me Makes Us All Vulnerable. https://www.nytimes.com/...