Surveillance Spyware Targeted At Journalists In Mexico

The messages arrived at a familiar moment of crisis for Mexico’s fragile journalist community, another reporter killed in the line of duty.

Javier Valdez, a prominent investigative reporter, had been shot dead only a day earlier. Then came a sudden breakthrough: According to a text message received by his colleagues, his killers had been detained.

Despite the tragedy, his co-workers were suspicious. More than 90 percent of murders go unsolved in Mexico. How did the authorities solve the case so soon?

More likely, they worried, the text messages were an attempt to infiltrate their smartphones, part of a pattern of hacking attempts involving sophisticated spying technology bought by the Mexican government.

They were Right

The messages were infected with a spyware known as Pegasus, which the Mexican government purchased from an Israeli cyber arms dealer called the NSO Group, according to a forensic analysis by the Citizen Lab at the Munk School at the University of Toronto.

A simple click on the links embedded in the messages would have infected the cellphones with spyware powerful enough to break through encrypted messaging, monitor emails and remotely activate the camera and microphone.

Someone was trying to spy on Mr. Valdez’s closest friends and colleagues the day after he was killed last year, most likely the Mexican government, according to those targeted.

“I believe they wanted to search our conversations and messages for clues to the murder of Javier, but we are absolutely against this,” said Ismael Bojórquez, the co-founder and news director of Rio Doce, the news organization where Mr. Valdez worked. 

“Nothing obtained illegally should be used in an investigation, and especially not from those who are involved professionally and emotionally to the victim.”

The illegal use of the surveillance technology in Mexico first emerged during the administration of Mr. Peña Nieto, which bought the spyware on the condition that it be used only to target terrorists and criminals.

But in the last year and a half, the Citizen Lab has confirmed nearly two dozen highly questionable targets, including some of Mexico’s most prominent journalists, human rights lawyers and anticorruption activists.

When news of the surveillance erupted last year, the Mexican government denounced the spying and opened a federal investigation into any misuse of the technology.

But the federal investigation has gone nowhere. Not a single individual has been punished for abusing the system.

Well aware of the scandal, Mr. Bojórquez said he had little faith in the messages he was receiving. He and another target, the news director, Andres Villareal, refused to click on the links. They had reason to be suspicious.

The men were running one of the few independent news groups in the nation, dedicated to covering organized crime and exposing the underbelly of Mexico’s vast nexus of crime and corruption.

Their work made them few friends. Threats came with the territory, and not just from organised crime. Government data show that public officials are responsible for the greatest number of assaults and attacks on journalists.

But Mr. Valdez’s work and international profile, they figured, protected him. He was known and beloved by local and foreign journalists alike, and was the recipient of awards and recognition globally.

His death and the subsequent targeting of newsroom leaders exposed two of the most devastating risks to the freedom of expression in Mexico today.

One is the physical threats to journalists and, by extension, freedom of speech in Mexico. More than 47 journalists have been killed since Mr. Peña Nieto took office in late 2012, 15 of them after Mr. Valdez’s death in May of last year, according to Article 19, a journalist protection group.

“We believed that a journalist as prestigious as Javier was untouchable,” Mr. Bojórquez said.

“When they killed Javier, we understood from that point on that they could kill anyone,” he added. “We understood that the paradigm had been broken.”

The second risk is a separate but connected facet of the rule of law in Mexico: There is essentially near total impunity when it comes to how it is broken or applied, a dynamic underscored by the use of illegal spyware to intimidate and spy on pro-democracy voices.

Dating back to 2016, the target list has been a who’s who of Mexico’s most prominent voices aiming to bring accountability to the nation, including the directors at Rio Doce.

Mr. Bojórquez said he and others had become aware of the government’s potent spyware in February 2017, when the Citizen Lab and The New York Times published articles outlining its illicit use against backers of a nationwide soda tax.

The investigations detailed the purchase of the spyware by the Mexican government, and included details about its proper use. The Israeli company claimed it had sold the software only to governments, and said it had measures in place to ensure that its clients followed the ethical guidelines stipulated in purchasing agreements.

Mexico’s government was deeply embarrassed by the scandal. And yet months after the attempted hacking of doctors and activists promoting a tax on sugary drinks in Mexico, which is suffering a diabetes crisis, the targeting did not stop.

Mexico has become an emblem of problematic use of spyware. In a series of articles in 2017, The Times and the Citizen Lab detailed the extensive use of the malware against journalists, minors, human rights lawyers, politicians and anticorruption activists. It also included critics of the president.

The NSO Group claimed that it monitored abuses of its software and intervened to stop clients from targeting people who did not fall within the permitted categories.

But even after suspicious targeting was unveiled in February 2017, operators in Mexico continued their illicit spying.

A new government comes into office in the next week, arriving on a wave of popular support. But whether the status of journalists will change in the country, and whether their targeting and abuse, and state overreach will subside, is an open question.

“A change in government does not mean there will be a change in the context of impunity or aggressions against journalists,” Mr. Bojórquez said. “If there is no change to the impunity, the murder of journalists will continue.” 

New York Times:

You Might Also Read:

Spyware Proliferates To 45 Countries

« GCHQ Doesn't Always Tell Vendors If Their Software Is Vulnerable
Artificial Intelligence Or Deep Learning? What's The Difference? »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

Syxsense

Syxsense

Syxsense brings together endpoint management and security for greater efficiency and collaboration between IT management and security teams.

The PC Support Group

The PC Support Group

A partnership with The PC Support Group delivers improved productivity, reduced costs and protects your business through exceptional IT, telecoms and cybersecurity services.

LockLizard

LockLizard

Locklizard provides PDF DRM software that protects PDF documents from unauthorized access and misuse. Share and sell documents securely - prevent document leakage, sharing and piracy.

Practice Labs

Practice Labs

Practice Labs is an IT competency hub, where live-lab environments give access to real equipment for hands-on practice of essential cybersecurity skills.

MIRACL

MIRACL

MIRACL provides the world’s only single step Multi-Factor Authentication (MFA) which can replace passwords on 100% of mobiles, desktops or even Smart TVs.

NQA Certification

NQA Certification

NQA provides certification to a range of ISO standards including ISO 27001 for information security management.

Eversheds Sutherland

Eversheds Sutherland

Eversheds Sutherland is a global multinational law practice offering a full range of commercial and IT law services including Privacy, Data Protection and Cyersecurity.

The Media Trust

The Media Trust

The Media Trust continuously scans websites, ad tags and mobile apps and alerts on anomalies affecting websites and visitors.

Quadron  Cybersecurity Services

Quadron Cybersecurity Services

Quadron Cybersecurity Services is a specialist in digital security, data and system protection.

Smart Contract Security Alliance

Smart Contract Security Alliance

The Smart Contract Security Alliance supports the blockchain ecosystem by building standards for smart contract security and smart contract audits.

AXELOS

AXELOS

AXELOS develops best practice frameworks and methodologies used globally by professionals working primarily in IT management and cyber resilience.

Estio Training

Estio Training

Estio Training is a specialist digital and IT apprenticeships provider, dedicated to introducing new skills and developing existing talent in businesses across the UK.

Ensighten

Ensighten

Ensighten is a leader in Website Security & Privacy Compliance. Protect your website from malicious attacks, monitor & detect vulnerabilities, protect consumer data.

Yoti

Yoti

Yoti offer a suite of business solutions that span identity verification, age estimation, e-signing and AI anti-spoofing technologies.

NTT Group

NTT Group

NTT offers agile, scalable technology services to bring it all together seamlessly, securely, and sustainably. We help you adopt a holistic security approach across your network, clouds, applications.

1898 & Co

1898 & Co

Keep your critical assets secure with a comprehensive portfolio of services from high-level assessments to fully managed security services designed for operational technology applications.

LANCOM Systems

LANCOM Systems

LANCOM Systems is the leading European manufacturer of secure, reliable and future-proof networking (WAN, LAN, WLAN) and firewall solutions for the public and private sectors.

Censinet

Censinet

Censinet provides the first and only third-party risk management platform for healthcare organizations to manage the threats to patient care that exist within an expanding ecosystem.

Curatrix Technologies

Curatrix Technologies

Curatrix Technologies is a Managed IT Service provider based in Hampshire, UK, providing high quality and reliable Managed IT Services since 2015.

Association for Uncrewed Vehicle Systems International (AUVSI)

Association for Uncrewed Vehicle Systems International (AUVSI)

AUVSI is the world's largest nonprofit organization dedicated to the advancement of uncrewed systems and robotics. Focus areas include cyber security for uncrewed systems and robotics.

ActiveFence

ActiveFence

ActiveFence enables Trust & Safety teams to be proactive about online integrity so they can keep their users safe from online harm – across content formats, languages, and abuse areas.