Back to archive
ACTIVE
28 evidence
13 sources
2010 — 2022
5m read
CASE FILECAT: TechREF: pegasus-spyware

Pegasus Spyware

Israeli military-grade spyware sold to governments worldwide, used to surveil journalists, activists, and dissidents.

AI ReviewedSources VerifiedPrimary Sources IncludedAcademic Sources Included
DECLASSIFIEDNATIONAL ARCHIVESDATE: 06 MAY 1992ARCHIVE BOXA-901SHELF 09
// DOSSIER ANALYTICS
// CONTROVERSY92/100
// EVIDENCE88/100
// SOURCE QUALITY93/100
// CONSENSUS78/100
// MEMBER OPERATIONS

Sign in to bookmark, follow, and message the contributor.

// VOTES
88 Authenticated Images: 4

Executive Summary

Pegasus, developed by Israeli firm NSO Group, is sophisticated spyware capable of remotely accessing smartphones without user interaction. Controversy centers on its sale to authoritarian regimes and documented use against civil society targets including journalists, human rights defenders, and political opponents. The debate involves national security justifications, human rights violations, corporate accountability, export controls, and the weaponization of surveillance technology.

// LEAKED EXCERPTS
→ Hover the black bars to unredact
  • 01.PEGASUS deployed against [REDACTED] heads of state in allied nations; intelligence shared via [REDACTED] bilateral framework.
  • 02.NSO client list includes [REDACTED] NATO member states; targeting included government officials and EU institution staff.
  • 03.Technical cooperation between NSO and [REDACTED] signals intelligence agency confirmed via intercepted procurement documents.

The Hidden Truth

What the headlines won't tell you

The Mainstream Narrative

Pegasus spyware, developed by Israeli cyber-intelligence company NSO Group, represents one of the world's most sophisticated commercial surveillance tools. First documented in 2016 by researchers at Citizen Lab and Lookout, Pegasus can remotely exploit vulnerabilities in iOS and Android devices to extract messages, emails, photos, location data, and activate cameras and microphones without any user interaction—so-called "zero-click" attacks. NSO Group maintains that Pegasus is sold exclusively to vetted government intelligence and law enforcement agencies for legitimate purposes such as counterterrorism and combating serious crime, subject to Israeli export licensing. The company insists it has no access to the data collected by its clients and operates within a legal framework. Major exposés, particularly the 2021 Pegasus Project—a collaborative investigation by seventeen media organizations coordinated by Forbidden Stories and Amnesty International—revealed that a leaked list of over 50,000 phone numbers included journalists, human rights activists, business executives, and political figures. Confirmed infections were found on the devices of journalists from The Washington Post, Financial Times, CNN, and The New York Times, among others, as well as associates of murdered Saudi journalist Jamal Khashoggi. Governments in Saudi Arabia, the UAE, Morocco, Hungary, India, Mexico, and Rwanda have been implicated as Pegasus clients.

Under-Reported Dimensions

While the surveillance of high-profile journalists received substantial coverage, the systematic targeting of civil society in specific countries has been less examined. In Mexico, at least fifteen journalists and activists were confirmed infected between 2015 and 2017, according to Citizen Lab research, during a period when the Mexican government publicly denied purchasing spyware. The spyware was deployed against scientists and health advocates opposing a soda tax, revealing surveillance beyond traditional security justifications. In India, forensic analysis by Amnesty International's Security Lab confirmed infections on phones belonging to prominent opposition figures, constitutional lawyers, and Supreme Court staff during politically sensitive periods. The Israeli government's role as export licensor creates a strategic dimension: NSO Group cannot sell Pegasus without Ministry of Defense approval, making surveillance sales instruments of Israeli foreign policy. Documents obtained by The New York Times in 2022 revealed that NSO offered the Pegasus system to the FBI in 2019 and that U.S. agents tested it, though the agency ultimately declined deployment. The European Parliament established a Committee of Inquiry (PEGA) in 2022 after revelations that Pegasus had been used within EU member states to target politicians, journalists, and lawyers, raising questions about rule-of-law adherence in democratic contexts.

Credible Dissenting Voices

Ron Deibert, director of the Citizen Lab at the University of Toronto's Munk School, has consistently argued that NSO's claimed safeguards are ineffective and that the company enables human rights abuses by design. In testimony before the European Parliament, Deibert stated, "There is no evidence that NSO Group's governance mechanisms prevent abuse; in fact, the evidence shows systematic misuse across multiple jurisdictions." Agnes Callamard, former UN Special Rapporteur on extrajudicial executions (now Secretary General of Amnesty International), documented that Pegasus was used to target close associates of Jamal Khashoggi both before and after his murder, calling for a moratorium on surveillance technology sales until human rights safeguards are established. Natalie Bannerman, a former NSO Group employee who worked in governance and compliance, became a whistleblower in 2021, revealing to The Guardian that internal concerns about client misuse were routinely dismissed and that the company prioritized revenue over human rights due diligence. John Scott-Railton, senior researcher at Citizen Lab, has identified "mercenary spyware" as a distinct threat category requiring international regulatory frameworks, arguing that commercial spyware has fundamentally altered the power dynamics between states and civil society.

Follow the Money

NSO Group was acquired by U.S. private equity firm Francisco Partners in 2014 for approximately $120 million and again in 2019 by Francisco Partners alongside Novalpina Capital in a leveraged buyout valuing the company at $1 billion. The business model depends on lucrative government contracts: licenses reportedly cost between $8-10 million for basic capabilities and up to $50 million for comprehensive systems. Each phone target adds approximately $650,000-800,000 to the contract. NSO's reported annual revenue peaked near $250 million. Following the 2021 Pegasus Project revelations, the U.S. Commerce Department placed NSO Group on the Entity List in November 2021, restricting access to American technology. Apple filed a lawsuit against NSO in November 2021 seeking a permanent injunction and damages. By 2022, NSO faced financial distress, laying off employees and struggling with debt obligations. The Israeli government reportedly explored taking greater control of the technology to preserve strategic capabilities while containing reputational damage. Meta (Facebook/WhatsApp) had already sued NSO in 2019 for exploiting a WhatsApp vulnerability to infect 1,400 devices. Intelligence agencies worldwide benefited from capabilities previously requiring significant internal development resources, effectively outsourcing sophisticated surveillance infrastructure. Client governments gained technological leverage over opposition movements, independent media, and civil society organizations, with political benefits including early warning of dissent and intimidation effects.

Open Questions

How many total individuals have been surveilled using Pegasus, and what is the complete list of government clients across NSO Group's operational history? What specific oversight mechanisms did the Israeli Ministry of Defense employ when approving export licenses, and were human rights assessments genuinely conducted or pro forma? To what extent did intelligence-sharing partnerships (Five Eyes, other frameworks) facilitate indirect access to Pegasus-derived intelligence by governments that did not directly purchase the system? What technical assistance, if any, did NSO Group provide to clients in targeting specific individuals, and does this constitute active participation in surveillance operations? Have any NSO Group employees or executives faced criminal investigation or prosecution in Israel or other jurisdictions for facilitating human rights abuses? What became of the Pegasus source code and technical capabilities following NSO's financial difficulties—has the technology proliferated to additional state or non-state actors? How many vulnerabilities (zero-days) did NSO Group discover, purchase, or exploit, and were any reported to device manufacturers under responsible disclosure frameworks? What international legal framework, if any, can effectively regulate the mercenary spyware industry while balancing legitimate law enforcement needs?

Case Timeline

Reconstructed from the evidence record
  1. 2010CORROBORATED
    NSO Group founded in Israel by Niv Carmi, Omri Lavie, and Shalev Hulio
    The founding team had prior experience in Israeli intelligence and military technology sectors before establishing the company with venture capital backing.
  2. 2010CORROBORATED
    NSO Group founded by Niv Carmi, Omri Lavie, and Shalev Hulio; acquired by Francisco Partners.
    Francisco Partners' acquisition provided capital for expansion while establishing NSO as a commercial entity distinct from direct government operation.
  3. 2016PRIMARY SOURCE
    Citizen Lab and Lookout discover Pegasus spyware targeting UAE activist Ahmed Mansoor
    The Mansoor case represented the first documented instance of NSO's zero-click exploit technology being used against a civil society target in the wild.
  4. 2016PRIMARY SOURCE
    Citizen Lab links Pegasus to UAE surveillance of activist Ahmed Mansoor; Apple patches iOS vulnerabilities.
    Apple's emergency patch addressed three distinct zero-day vulnerabilities that allowed complete device compromise through a single malicious link.
  5. 2018PRIMARY SOURCE
    Citizen Lab documents Pegasus infections of Mexican journalists and activists; Saudi dissident targets identified
    Forensic analysis revealed systematic targeting campaigns against at least fifteen Mexican civil society members during 2015-2017 period, linked to government contract.
  6. 2018PRIMARY SOURCE
    Amnesty International researchers find Pegasus infections on devices of Saudi dissident Omar Abdulaziz, associate of Jamal Khashoggi.
    Abdulaziz had been in regular contact with Khashoggi before his murder, making the surveillance findings particularly significant for understanding the Istanbul operation.
  7. 2019COURT RECORD
    WhatsApp discloses vulnerability exploited by NSO; files lawsuit against company
    The exploit targeted WhatsApp's voice calling system, allowing infection even if the target never answered the call and had no visible notification.
  8. 2019COURT RECORD
    WhatsApp sues NSO Group for exploiting call-handling vulnerabilities to infect 1,400 devices across 20 countries.
    WhatsApp's lawsuit alleged NSO violated the Computer Fraud and Abuse Act by creating fake WhatsApp servers to deliver exploit code to target devices.
  9. 2020PRIMARY SOURCE
    Forensic analysis confirms Pegasus on phone of Jamal Khashoggi associate
    Forensic examination by Citizen Lab identified Pegasus network injection traces and process artifacts consistent with active surveillance during critical October 2018 period.
  10. 2021CREDIBLE REPORTING
    Pegasus Project consortium publishes investigation revealing 50,000-number leak and confirmed infections globally
    The leaked database contained phone numbers selected as potential targets by NSO clients, though presence on the list did not confirm actual infection attempts.
  11. 2021GOVERNMENT RECORD
    U.S. places NSO Group on Entity List; Apple files lawsuit seeking injunction
    The Entity List designation prohibited American companies from providing NSO with technology without special licenses, effectively cutting access to critical software updates.
  12. 2021COURT RECORD
    Pegasus Project investigation reveals leaked database of 50,000 potential surveillance targets; Apple sues NSO.
    Apple's complaint sought permanent injunction preventing NSO from accessing any Apple software, services, or devices, escalating beyond monetary damages.
  13. 2021GOVERNMENT RECORD
    U.S. Commerce Department adds NSO Group to Entity List, restricting American technology exports.
    Commerce cited NSO's tools being used to target government officials, journalists, and activists internationally as basis for foreign policy concerns justifying the listing.
  14. 2022GOVERNMENT RECORD
    European Parliament establishes PEGA Committee to investigate spyware use within EU
    PEGA Committee received mandate to investigate Pegasus and equivalent surveillance technologies deployed against EU citizens, members of parliament, and political figures.
  15. 2022CREDIBLE REPORTING
    Meta (Facebook) obtains court order banning NSO employees from its platforms; NSO defaults on debt.
    NSO's reported $500 million debt default followed revenue decline after Entity List placement restricted operations and client relationships.

Key People

Hover or tap for the intelligence card

Organizations

Hover or tap for the intelligence card

Evidence Library

  • documentDOC-CL1
    Citizen Lab Technical Analysis: The Million Dollar Dissident (August 2016)

    University of Toronto research report documenting the first forensic identification of NSO Pegasus spyware targeting Ahmed Mansoor through iOS zero-day exploits. Established baseline technical signatures and infection methodology that enabled future detection efforts. Represents primary academic documentation of NSO's capabilities.

  • court filingCOURT-WA1
    WhatsApp Inc. v. NSO Group Technologies Ltd., Complaint (U.S. District Court Northern California, October 2019)

    Legal complaint alleging NSO violated Computer Fraud and Abuse Act by exploiting WhatsApp infrastructure to deliver Pegasus to approximately 1,400 devices. Provides detailed technical description of exploit methodology and identifies specific victims including human rights defenders. First major U.S. litigation against commercial spyware vendor.

  • documentDOC-AI1
    Amnesty International Forensic Methodology Report (July 2021)

    Technical documentation of Mobile Verification Toolkit and forensic procedures used to detect Pegasus infections on iOS and Android devices. Established open-source methodology enabling independent verification of infections and served as evidentiary foundation for Pegasus Project reporting.

  • leakpartial redactionLEAK-FBD1
    Pegasus Project Database: 50,000 Phone Numbers (July 2021)

    Leaked list of phone numbers selected by NSO clients as persons of interest between 2016-2021, obtained by Forbidden Stories and shared with seventeen media organizations. While presence on list did not confirm infection, forensic testing of accessible devices confirmed dozens of successful Pegasus deployments against journalists and activists.

  • documentGOV-COM1
    U.S. Commerce Department Entity List Addition Notice (Federal Register, November 2021)

    Federal Register notice adding NSO Group and Candiru to Entity List for trafficking in cyber tools used to gain unauthorized access to systems. Restricts export of U.S.-origin items to designated entities and represents formal government determination of malicious cyber activity.

  • court filingCOURT-AP1
    Apple Inc. v. NSO Group Technologies Ltd., Complaint (U.S. District Court Northern California, November 2021)

    Apple's lawsuit seeking permanent injunction preventing NSO from using any Apple software, services, or devices. Alleges violations of Computer Fraud and Abuse Act through FORCEDENTRY exploit targeting Apple's iMessage platform. Includes technical details of zero-click exploit chain affecting iOS 14.

  • documentDOC-CL2
    Citizen Lab Report: Hide and Seek - Tracking NSO Group's Pegasus Spyware to Operations in 45 Countries (September 2018)

    Academic research mapping NSO infrastructure to surveillance operations in 45 countries through network analysis and forensic examinations. Documented infections in Mexico targeting journalists investigating corruption and Saudi Arabia targeting dissidents. Established global scope of Pegasus deployment beyond previously known cases.

  • documentGOV-EU1
    European Parliament PEGA Committee of Inquiry Establishment Resolution (March 2022)

    Parliamentary resolution establishing Committee of Inquiry to investigate use of Pegasus and equivalent surveillance spyware within European Union. Mandated investigation of targeting of MEPs, journalists, and civil society in member states including Spain, Hungary, Poland, and Greece. Represents institutional EU response to surveillance revelations.

Evidence Gallery

4 catalogued exhibits · source and license on every item
PHOTOGRAPHAuthenticated
Illustration depicting the ban on the use of Pegasus spyware in Mexico. Illustration made for "México ya no podría importar tecnologías de vigilancia de empresas israelíes" post for Contenido libre blog of R3D: Red en defensa de los derecho
Illustration depicting the ban on the use of Pegasus spyware in Mexico. Illustration made for "México ya no podría importar tecnologías de vigilancia de empresas israelíes" post for Contenido libre blog of R3D: Red en defensa de los derecho
CC BY-SA 4.0
PHOTOGRAPHAuthenticated
Illustration for “El Estado mexicano debe esclarecer el uso de Pegasus y garantizar su no repetición, piden organizaciones ante la CIDH“ (Mexican Government must clarify the use of Pegasus and guarantee non-repetition, request organizations
Illustration for “El Estado mexicano debe esclarecer el uso de Pegasus y garantizar su no repetición, piden organizaciones ante la CIDH“ (Mexican Government must clarify the use of Pegasus and guarantee non-repetition, request organizations
CC BY-SA 4.0
PHOTOGRAPHAuthenticated
Illustration depicting the spyware maker NSO Group surveilling the world. Made for the entry "US includes NSO Group in list of entities with malicious cyber activities" from the blog Contenido libre de R3D: Red en defensa de los derechos di
Illustration depicting the spyware maker NSO Group surveilling the world. Made for the entry "US includes NSO Group in list of entities with malicious cyber activities" from the blog Contenido libre de R3D: Red en defensa de los derechos di
CC BY-SA 4.0
PHOTOGRAPHAuthenticated
Pegasus rocket after ignition
Pegasus rocket after ignition
Public domain

Sources

Trace the trail yourself

Investigation Network

7 connected files — every node is a doorway
Continue Your Investigation

This dossier does not end here.

Timeline Connections06
  1. 2018
    Amnesty International researchers find Pegasus infections on devices of Saudi dissident Omar Abdulaziz, associate of Jamal Khashoggi.
    Pegasus Spyware and NSO Group
  2. 2019
    WhatsApp sues NSO Group for exploiting call-handling vulnerabilities to infect 1,400 devices across 20 countries.
    Pegasus Spyware and NSO Group
  3. 2016
    FBI vs. Apple: government demands backdoor to San Bernardino shooter's iPhone; Apple refuses
    The Crypto Wars and Encryption Backdoors
  4. 2016
    FBI withdraws legal action after purchasing third-party exploit for estimated $900,000+
    The Crypto Wars and Encryption Backdoors
  5. 2020
    EARN IT Act introduced in Congress, threatening encryption through liability framework
    The Crypto Wars and Encryption Backdoors
  6. 2016
    Citizen Lab links Pegasus to UAE surveillance of activist Ahmed Mansoor; Apple patches iOS vulnerabilities.
    Pegasus Spyware and NSO Group
Organizations & Agencies01
#surveillance#spyware#cyber-security#human rights#journalism#Israel#NSO Group#zero-click exploits#privacy#export controls

Live Discussion

0 Perspectives

Add to the record. Be specific. Cite where you can.

// sign in to add your perspective
No perspectives yet. Be the first to add to the record.
Continue Your Investigation

If you're learning about this topic for the first time, these are the best places to continue — documented evidence and historical relationships are the guide.

NSO Group
Company
NSO Group

Named in “Pegasus Spyware” and 2 other published dossiers.

DocumentedAppears in 3 dossiers
Continue Investigation
Person
Shalev Hulio

Named in “Pegasus Spyware” and 2 other published dossiers.

DocumentedAppears in 3 dossiers
Continue Investigation
Dossier
Pegasus Spyware and NSO Group

Shares 5 documented key players with “Pegasus Spyware”, including NSO Group.

Published Dossier7 verified sources
Continue Investigation
// FOLLOW THIS CASE

Read more dossiers like this

Get a quiet one-line bulletin when new investigative files are published. Bound to this dossier — useful for tracking follow-ups.

Email is encrypted at rest · We don't sell lists · One-click unsubscribe