/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Research: Pegasus attacks on Mexican activists and reporters from 2019-2021 used 0-click exploits, after Mexico's president called Pegasus a thing of the past

Key Takeaways  — Mexican digital rights organization R3D (Red en los Defensa de los Derechos Digitales) …

The Citizen Lab

Context & Ripple Effects

R3D's finding lands in a country with the deepest documented Pegasus footprint: an earlier investigation traced how Mexico became the spyware's first client and most prolific user, and the attorney general's office has since opened a probe into a ~$23M purchase by the prior administration and whether NSO sold it legally.

The 2019-2021 window matters because it runs through the period when Mexico's president publicly dismissed Pegasus as a thing of the past — and the same zero-click technique R3D documents had already been caught hitting Al Jazeera reporters via iMessage in 2020. Later reporting showed the practice persisted, including the targeting of Alejandro Encinas while he investigated military abuses.

First-order effects

  • Mexican activists and reporters now have forensic evidence that 0-click infections — which require no user interaction and leave victims no way to detect the attack — were used against them during 2019-2021, directly contradicting the president's public claim that Pegasus was retired.

Second-order effects

  • The attorney general's investigation into the prior administration's purchase gains concrete deployment evidence, raising the legal question of whether NSO's sales to Mexico complied with the terms under which it was licensed.
  • Apple's patch cycle becomes the de facto defense: Citizen Lab later documented NSO deploying at least three new zero-click hacks against iPhones on iOS 15 and early iOS 16 before Apple fixed the flaws, so Mexican targets' security depends on vendor fixes outpacing NSO's exploit chain.

Third-order effects

  • If the pattern holds, commercial spyware operates as a standing instrument of state surveillance that survives changes in administration and public denials — with civil-society forensics groups like R3D and Citizen Lab serving as the only effective check on deployments governments officially claim to have ended.

The trend: Governments publicly disavow commercial spyware while procurement and deployment continue, leaving forensic researchers as the counterweight to official denials.

Discussion

  • @jsrailton John Scott-Railton on x
    BREAKING: journalists & human rights defenders hacked with #Pegasus in 🇲🇽#Mexico. Years *after* spyware scandals & new President's promise that abuses were over. THREAD 1/ Report by @R3Dmx https://ejercitoespia.r3d.mx/ We @citizenlab did forensic validation: https://citizenlab.ca…
  • @sflcin @sflcin on x
    Mexican digital rights organization @R3Dmx has identified more Pegasus infections in Mexico, against journalists and a human rights defender taking place between 2019-2021. These cases differ from previous findings. #Pegasus #Surveillance #Mexico https://citizenlab.ca/...
  • @jsrailton John Scott-Railton on x
    9/ A key detail: while previous Pegasus cases @citizenlab investigated in #Mexico involved finding SMS messages and 1-click attacks... these latest cases were zero-click attacks. No action was required on the part of the victims to be infected. https://twitter.com/...
  • @diazbriseno @diazbriseno on x
    The same Mexican Army that the US trusts for containing migration is also deploying Pegasus spyware vs journos & activists. Like in the Saudi case, the US Govt will find it hard to publicly criticize a Govt like AMLO's upon which it depends on. https://twitter.com/...
  • @risj_oxford @risj_oxford on x
    Mexican journalists and activists were monitored through the use of Pegaus spyware in 2019-21, despite the government saying the technology had been discontinued, an investigation by @citizenlab finds https://citizenlab.ca/...