French Government Ministers Bugged

The mobile phones of at least five French ministers and a diplomatic advisor to President Emmanuel Macron have been found to infected by the Israeli-made Pegasus spyware. The five ministers targeted are Education Minister Jean-Michel Blanquer, Territorial Cohesion Minister Jacqueline Gourault, Agriculture Minister Julien Denormandie, Housing Minister Emmanuelle Wargon and Overseas Territories Minister Sebastien Lecornu, Mediapart said.

This comes two months after it was revealed that the phone numbers of Macron, other government ministers and top French officials appeared in a leaked database being invesigated  by  journalists at Mediapart.

There is no evidence that the phones of the five cabinet members were successfully hacked, but the Mediapart allegations indicate that the devices were targeted with the powerful spyware known as Pegasus, which is made by NSO Group. The Israeli company is now at the center of an international spying scandal with suspicions that the Israeli government may also play a role.

Pegasus can switch on a phone’s camera or microphone and harvest its data, and was at the center of a storm in July after a list of about 50,000 potential surveillance targets worldwide including Heads of State became known. 

The NSO Group claims it has no connection to the leaked database and that the tens of thousands of numbers contained in the list are not the targets of NSO’s customers, which includes numerous governments around the world. It has also denied that Macron was ever targeted by Pegasus spyware and in a statement NSO Group said: “We stand by our previous statements regarding French government officials. They are not and have never been Pegasus targets. We won’t comment on anonymous source allegations.”

Although NSO Group say that the purpose of this powerful spyware is to investigate serious crime, not to target members of civil society, the Mediapart investigation has revealed that global clients of NSO Group have used their syware to hack human rights activists, journalists and lawyers. Forensic analysis of their devices at the end of July had revealed the presence of “suspect traces” of the spyware, according to a report by French state intelligence services.  

The alleged victims have not responded for requests to comment and some of them are understood  to have referred Mediapart investigators to France’s Secretariat-General for defence and national security (SGDSN), which also declined comment. The Élysée Palace also said it would not comment on “long and complex investigations which are still ongoing”.

In July, Le Monde newspaper reported that evidence of an attempted hacking was found on the phone of the former French  environment minister Francois de Rugy, with the attempt allegedly originating in Morocco and  Morocco's intelligence services were also accused of being behind the hacking of journalists in France.

The Israeli cybersecurity industry's exports were valued at $6.85 billion in 2020 and includes a number of world leading companies who have access to a trained talent pool from the nation's secretive military' intelligence units who are adept at transfering their know-how to the private sector.

France 24:      Mediapart:           TimesofIsrael:       Guardian:       TimesofIndia:     NPR:   Sada ElBalad

You Might Also Read: 

Apple's Emergency Patch For NSO Hack:

 

« Phishing Scam - Attackers Impersonate US Dept. of Transport
Medical Devices Need Better Cyber Security »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

North Infosec Testing (North IT)

North Infosec Testing (North IT)

North IT (North Infosec Testing) are an award-winning provider of web, software, and application penetration testing.

DigitalStakeout

DigitalStakeout

DigitalStakeout enables cyber security professionals to reduce cyber risk to their organization with proactive security solutions, providing immediate improvement in security posture and ROI.

NordLayer

NordLayer

NordLayer is an adaptive network access security solution for modern businesses — from the world’s most trusted cybersecurity brand, Nord Security. 

Practice Labs

Practice Labs

Practice Labs is an IT competency hub, where live-lab environments give access to real equipment for hands-on practice of essential cybersecurity skills.

XYPRO Technology

XYPRO Technology

XYPRO is the market leader in HPE Non-Stop Security, Risk Management and Compliance.

Privacy Professor

Privacy Professor

Privacy Professor provides information privacy, security and compliance services, tools and products to organizations in a wide range of industries.

Allgress

Allgress

Allgress solutions converge disparate risk silos across enterprise networks and automate governance, risk and compliance management processes.

Zentera Systems

Zentera Systems

Zentera's CoIP (Cloud over IP) solution offers enterprise-grade networking and security for the emerging cloud ecosystem.

CyberSecurity Malaysia

CyberSecurity Malaysia

CyberSecurity Malaysia is the national cyber security specialist agency under the Ministry of Science, Technology and Innovation (MOSTI).

IGX Global

IGX Global

IGX Global is a provider of information network and security integration services and products.

FedRAMP

FedRAMP

FedRAMP, is a government-wide program that provides a standardized approach to security assessment, authorization, and continuous monitoring for cloud products and services.

Zamna

Zamna

Zamna (formerly VChain Technology) is an award-winning software company building GDPR compliant identity platforms for the aviation industry.

Quantum Generation

Quantum Generation

Quantum Cyber Security for a new age of communications. We are developing the largest decentralized orbital, and ground quantum mesh network based on blockchain technology.

BrandShelter

BrandShelter

BrandShelter specializes in providing online brand protection for companies and trademark owners.

Siemens

Siemens

Siemens Industrial Security Services provide solutions for cybersecurity in automation environments based on the recommendations of the international standard IEC 62443.

Cyber Coaching

Cyber Coaching

Cyber Coaching is a community for enhancing technical cyber skills, through unofficial certification training, cyber mentorship, and personalised occupational transition programs.

Electrosoft Services

Electrosoft Services

Electrosoft provide mature, innovative technology-based services and solutions to power critical IT programs and keep our nation safe from cybersecurity attacks.

Cyber Security Works (CSW)

Cyber Security Works (CSW)

Cyber Security Works is your organization’s early cybersecurity warning system to help prevent attacks before they happen.

Invicti Security

Invicti Security

Invicti Security is an AppSec leader transforming the way web applications are secured.

European Union Agency for Network and Information Security (ENISA)

European Union Agency for Network and Information Security (ENISA)

The European Union Agency for Cybersecurity, ENISA, is the Union’s agency dedicated to achieving a high common level of cybersecurity across Europe.

Huntr

Huntr

Huntr provides a single place for security researchers to submit vulnerabilities, to ensure the security and stability of AI/ML applications.