Pegasus Spyware Maker Fined

Your phone could become a criminal’s tool, silently spilling your texts, calls, and photos to a shadowy hacker - all without you clicking a single link. This serious threat is created by Pegasus, the infamous spyware developed by Israel’s NSO Group, which targeted 1,400 WhatsApp users in 2019.

Now, the Israeli firm behind Pegasus, NSO Group, has been ordered to pay Meta $444,000 damages for this hacking attack that took place that year. 

For years, the Israeli spyware company NSO Group has quietly equipped governments with potent tools to hack phones and monitor dissidents. However, a jury in California recently awarded Meta Platforms (formerly Facebook) over $167 million (£125 million) in damages from NSO Group for exploiting WhatsApp in 2019.

Meta created a webpage announcing the jury’s decision, stating that it “is a critical deterrent to this malicious industry” aimed at combatting illegal acts against American companies and users worldwide.

“Six years ago, we detected and stopped an attack by the notorious spyware developer NSO against WhatsApp and its users, and today, our court case has made history as the first victory against illegal spyware that threatens the safety and privacy of everyone,” Meta announced on May 6th. 

Additionally, Meta described this ruling as “an important step forward for privacy and security, marking the first victory against the development and use of illegal spyware that threatens everyone’s safety and privacy.”

Pegasus is malicious software that can be installed remotely on mobile phones to access microphones, cameras, and other personal data without user consent.  Based in Tel Aviv, NSO Group has developed and sold  their technology around the word, and has faced accusations of enabling authoritarian regimes to monitor journalists, activists, and political figures

Meta stated that this case signifies “the first victory against the development and use of illegal spyware.” NSO, in response, said it would “carefully examine the verdict's details and pursue appropriate legal remedies, including further proceedings and an appeal.”

This case is notable as the first time a developer of spyware has been held responsible for exploiting vulnerabilities in smartphone platforms.

NSO claims its products are intended solely for use against serious criminals and terrorists. However, there are ongoing allegations that some governments have used the technology to target individuals they consider threats to national security.

Pegasus became the center of global controversy in 2021 when a leaked list of 50,000 phone numbers of suspected victims was revealed to major media outlets. The leak identified politicians, heads of state, business executives, activists, members of Arab royal families, and over 180 journalists.

This legal battle has spanned six years and involves multiple major tech companies. Apple previously filed a similar lawsuit against NSO Group but withdrew it in 2024 to avoid exposing its internal security systems. In contrast, Meta’s case resulted in a court ruling in their favor - an uncommon win against a surveillance vendor.

While this case may mark a turning point in how courts and tech companies confront the spyware industry, the fight against digital surveillance tools remains ongoing.

Silicon  |   BBC  |   Meta  |    Medium  |    Techloy  |  neowin  |  Hacker News 

Image: Ideogram 

You Might Also Read: 

Russian Hackers Exploit Mobile Browser Vulnerabilities:


If you like this website and use the comprehensive 8,000-plus service supplier Directory, you can get unrestricted access, including the exclusive in-depth Directors Report series, by signing up for a Premium Subscription.

  • Individual £5 per month or £50 per year. Sign Up
  • Multi-User, Corporate & Library Accounts Available on Request

Cyber Security Intelligence: Captured Organised & Accessible


 

« How Ransomware's Industrialization Impacts SOC Operational Tempo
Large-Scale Data Exposure Discovered »

Infosecurity Europe
CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

Alvacomm

Alvacomm

Alvacomm offers holistic VIP cybersecurity services, providing comprehensive protection against cyber threats. Our solutions include risk assessment, threat detection, incident response.

North Infosec Testing (North IT)

North Infosec Testing (North IT)

North IT (North Infosec Testing) are an award-winning provider of web, software, and application penetration testing.

Resecurity

Resecurity

Resecurity is a cybersecurity company that delivers a unified platform for endpoint protection, risk management, and cyber threat intelligence.

Authentic8

Authentic8

Authentic8 transforms how organizations secure and control the use of the web with Silo, its patented cloud browser.

Syxsense

Syxsense

Syxsense brings together endpoint management and security for greater efficiency and collaboration between IT management and security teams.

Delphix

Delphix

Delphix is the industry leader for DevOps test data management.

Metasploit

Metasploit

Metasploit penetration testing software helps find security issues, verify vulnerabilities and manage security assessments.

Assured Data Protection

Assured Data Protection

Assured Data Protection specialises in data protection and disaster recovery services for large SME and enterprise organisations.

Alliance for Cyber Security (ACS)

Alliance for Cyber Security (ACS)

An alliance of all major players in the field of cyber security in Germany with a mission to strengthen Germany’s resistance to cyber-attacks.

Cybersecurity Innovation Hub

Cybersecurity Innovation Hub

The main objective of the Hub is to bring cybersecurity and other advanced technologies closer to companies and as a result help to increase their performance as Industry 4.0.

ioXt Alliance

ioXt Alliance

The ioXt Alliance is a group of manufacturers, industry alliances and government organizations dedicated to harmonizing best security practices in a highly connected world.

Rigado

Rigado

Rigado's mission is to enable commercial IoT success by providing high-performance secure and scalable wireless edge connectivity and network infrastructure.

Hexaware Technologies

Hexaware Technologies

Hexaware is an automation-led next-generation service provider delivering excellence in IT, BPO and Consulting services.

US Digital Corps

US Digital Corps

The U.S. Digital Corps is a new two-year fellowship for early-career technologists where you will work every day to make a difference in critical impact areas including cybersecurity.

SharkStriker

SharkStriker

SharkStriker is a US based managed security services provider with SOCs and offices across the globe.

EtherAuthority

EtherAuthority

EtherAuthority's engineering team has been helping blockchain businesses to secure their smart contract based assets since 2018.

Secure Halo

Secure Halo

Secure Halo has been protecting the intellectual assets and sensitive information of the federal government and private sector for 20+ years, through our proactive approach to risk and cybersecurity.

Finlaw Associates

Finlaw Associates

Finlaw Associates is a trusted cybercrime law firm providing a wide range of taxation, legal, advisory and regulatory services to the financial, commercial and industrial communities.

Mother Technologies

Mother Technologies

From Datacentre to Desktop, Mother Technologies has been delivering IT Support, Telecoms, Cybersecurity and Connectivity services to businesses across Scotland and beyond since 2002.

The Aerospace Corporation

The Aerospace Corporation

The Aerospace Corporation is playing a key role in advancing space cybersecurity through innovative prototypes that can quickly detect and mitigate cyber threats.

Securaa

Securaa

Securaa is a comprehensive No Code Security Automation Platform. Smarter Security with Clarity and Control.