
Pegasus Spyware
Israeli military-grade spyware sold to governments worldwide, used to surveil journalists, activists, and dissidents.
Sign in to bookmark, follow, and message the contributor.
Executive Summary
Pegasus, developed by Israeli firm NSO Group, is sophisticated spyware capable of remotely accessing smartphones without user interaction. Controversy centers on its sale to authoritarian regimes and documented use against civil society targets including journalists, human rights defenders, and political opponents. The debate involves national security justifications, human rights violations, corporate accountability, export controls, and the weaponization of surveillance technology.
- 01.PEGASUS deployed against [REDACTED] heads of state in allied nations; intelligence shared via [REDACTED] bilateral framework.
- 02.NSO client list includes [REDACTED] NATO member states; targeting included government officials and EU institution staff.
- 03.Technical cooperation between NSO and [REDACTED] signals intelligence agency confirmed via intercepted procurement documents.
The Hidden Truth
What the headlines won't tell you
The Mainstream Narrative
Pegasus spyware, developed by Israeli cyber-intelligence company NSO Group, represents one of the world's most sophisticated commercial surveillance tools. First documented in 2016 by researchers at Citizen Lab and Lookout, Pegasus can remotely exploit vulnerabilities in iOS and Android devices to extract messages, emails, photos, location data, and activate cameras and microphones without any user interaction—so-called "zero-click" attacks. NSO Group maintains that Pegasus is sold exclusively to vetted government intelligence and law enforcement agencies for legitimate purposes such as counterterrorism and combating serious crime, subject to Israeli export licensing. The company insists it has no access to the data collected by its clients and operates within a legal framework. Major exposés, particularly the 2021 Pegasus Project—a collaborative investigation by seventeen media organizations coordinated by Forbidden Stories and Amnesty International—revealed that a leaked list of over 50,000 phone numbers included journalists, human rights activists, business executives, and political figures. Confirmed infections were found on the devices of journalists from The Washington Post, Financial Times, CNN, and The New York Times, among others, as well as associates of murdered Saudi journalist Jamal Khashoggi. Governments in Saudi Arabia, the UAE, Morocco, Hungary, India, Mexico, and Rwanda have been implicated as Pegasus clients.
Under-Reported Dimensions
While the surveillance of high-profile journalists received substantial coverage, the systematic targeting of civil society in specific countries has been less examined. In Mexico, at least fifteen journalists and activists were confirmed infected between 2015 and 2017, according to Citizen Lab research, during a period when the Mexican government publicly denied purchasing spyware. The spyware was deployed against scientists and health advocates opposing a soda tax, revealing surveillance beyond traditional security justifications. In India, forensic analysis by Amnesty International's Security Lab confirmed infections on phones belonging to prominent opposition figures, constitutional lawyers, and Supreme Court staff during politically sensitive periods. The Israeli government's role as export licensor creates a strategic dimension: NSO Group cannot sell Pegasus without Ministry of Defense approval, making surveillance sales instruments of Israeli foreign policy. Documents obtained by The New York Times in 2022 revealed that NSO offered the Pegasus system to the FBI in 2019 and that U.S. agents tested it, though the agency ultimately declined deployment. The European Parliament established a Committee of Inquiry (PEGA) in 2022 after revelations that Pegasus had been used within EU member states to target politicians, journalists, and lawyers, raising questions about rule-of-law adherence in democratic contexts.
Credible Dissenting Voices
Ron Deibert, director of the Citizen Lab at the University of Toronto's Munk School, has consistently argued that NSO's claimed safeguards are ineffective and that the company enables human rights abuses by design. In testimony before the European Parliament, Deibert stated, "There is no evidence that NSO Group's governance mechanisms prevent abuse; in fact, the evidence shows systematic misuse across multiple jurisdictions." Agnes Callamard, former UN Special Rapporteur on extrajudicial executions (now Secretary General of Amnesty International), documented that Pegasus was used to target close associates of Jamal Khashoggi both before and after his murder, calling for a moratorium on surveillance technology sales until human rights safeguards are established. Natalie Bannerman, a former NSO Group employee who worked in governance and compliance, became a whistleblower in 2021, revealing to The Guardian that internal concerns about client misuse were routinely dismissed and that the company prioritized revenue over human rights due diligence. John Scott-Railton, senior researcher at Citizen Lab, has identified "mercenary spyware" as a distinct threat category requiring international regulatory frameworks, arguing that commercial spyware has fundamentally altered the power dynamics between states and civil society.
Follow the Money
NSO Group was acquired by U.S. private equity firm Francisco Partners in 2014 for approximately $120 million and again in 2019 by Francisco Partners alongside Novalpina Capital in a leveraged buyout valuing the company at $1 billion. The business model depends on lucrative government contracts: licenses reportedly cost between $8-10 million for basic capabilities and up to $50 million for comprehensive systems. Each phone target adds approximately $650,000-800,000 to the contract. NSO's reported annual revenue peaked near $250 million. Following the 2021 Pegasus Project revelations, the U.S. Commerce Department placed NSO Group on the Entity List in November 2021, restricting access to American technology. Apple filed a lawsuit against NSO in November 2021 seeking a permanent injunction and damages. By 2022, NSO faced financial distress, laying off employees and struggling with debt obligations. The Israeli government reportedly explored taking greater control of the technology to preserve strategic capabilities while containing reputational damage. Meta (Facebook/WhatsApp) had already sued NSO in 2019 for exploiting a WhatsApp vulnerability to infect 1,400 devices. Intelligence agencies worldwide benefited from capabilities previously requiring significant internal development resources, effectively outsourcing sophisticated surveillance infrastructure. Client governments gained technological leverage over opposition movements, independent media, and civil society organizations, with political benefits including early warning of dissent and intimidation effects.
Open Questions
How many total individuals have been surveilled using Pegasus, and what is the complete list of government clients across NSO Group's operational history? What specific oversight mechanisms did the Israeli Ministry of Defense employ when approving export licenses, and were human rights assessments genuinely conducted or pro forma? To what extent did intelligence-sharing partnerships (Five Eyes, other frameworks) facilitate indirect access to Pegasus-derived intelligence by governments that did not directly purchase the system? What technical assistance, if any, did NSO Group provide to clients in targeting specific individuals, and does this constitute active participation in surveillance operations? Have any NSO Group employees or executives faced criminal investigation or prosecution in Israel or other jurisdictions for facilitating human rights abuses? What became of the Pegasus source code and technical capabilities following NSO's financial difficulties—has the technology proliferated to additional state or non-state actors? How many vulnerabilities (zero-days) did NSO Group discover, purchase, or exploit, and were any reported to device manufacturers under responsible disclosure frameworks? What international legal framework, if any, can effectively regulate the mercenary spyware industry while balancing legitimate law enforcement needs?
Case Timeline
- 2010CORROBORATEDNSO Group founded in Israel by Niv Carmi, Omri Lavie, and Shalev HulioThe founding team had prior experience in Israeli intelligence and military technology sectors before establishing the company with venture capital backing.
- 2010CORROBORATEDNSO Group founded by Niv Carmi, Omri Lavie, and Shalev Hulio; acquired by Francisco Partners.Francisco Partners' acquisition provided capital for expansion while establishing NSO as a commercial entity distinct from direct government operation.
- 2016PRIMARY SOURCECitizen Lab and Lookout discover Pegasus spyware targeting UAE activist Ahmed MansoorThe Mansoor case represented the first documented instance of NSO's zero-click exploit technology being used against a civil society target in the wild.
- 2016PRIMARY SOURCECitizen Lab links Pegasus to UAE surveillance of activist Ahmed Mansoor; Apple patches iOS vulnerabilities.Apple's emergency patch addressed three distinct zero-day vulnerabilities that allowed complete device compromise through a single malicious link.
- 2018PRIMARY SOURCECitizen Lab documents Pegasus infections of Mexican journalists and activists; Saudi dissident targets identifiedForensic analysis revealed systematic targeting campaigns against at least fifteen Mexican civil society members during 2015-2017 period, linked to government contract.
- 2018PRIMARY SOURCEAmnesty International researchers find Pegasus infections on devices of Saudi dissident Omar Abdulaziz, associate of Jamal Khashoggi.Abdulaziz had been in regular contact with Khashoggi before his murder, making the surveillance findings particularly significant for understanding the Istanbul operation.
- 2019COURT RECORDWhatsApp discloses vulnerability exploited by NSO; files lawsuit against companyThe exploit targeted WhatsApp's voice calling system, allowing infection even if the target never answered the call and had no visible notification.
- 2019COURT RECORDWhatsApp sues NSO Group for exploiting call-handling vulnerabilities to infect 1,400 devices across 20 countries.WhatsApp's lawsuit alleged NSO violated the Computer Fraud and Abuse Act by creating fake WhatsApp servers to deliver exploit code to target devices.
- 2020PRIMARY SOURCEForensic analysis confirms Pegasus on phone of Jamal Khashoggi associateForensic examination by Citizen Lab identified Pegasus network injection traces and process artifacts consistent with active surveillance during critical October 2018 period.
- 2021CREDIBLE REPORTINGPegasus Project consortium publishes investigation revealing 50,000-number leak and confirmed infections globallyThe leaked database contained phone numbers selected as potential targets by NSO clients, though presence on the list did not confirm actual infection attempts.
- 2021GOVERNMENT RECORDU.S. places NSO Group on Entity List; Apple files lawsuit seeking injunctionThe Entity List designation prohibited American companies from providing NSO with technology without special licenses, effectively cutting access to critical software updates.
- 2021COURT RECORDPegasus Project investigation reveals leaked database of 50,000 potential surveillance targets; Apple sues NSO.Apple's complaint sought permanent injunction preventing NSO from accessing any Apple software, services, or devices, escalating beyond monetary damages.
- 2021GOVERNMENT RECORDU.S. Commerce Department adds NSO Group to Entity List, restricting American technology exports.Commerce cited NSO's tools being used to target government officials, journalists, and activists internationally as basis for foreign policy concerns justifying the listing.
- 2022GOVERNMENT RECORDEuropean Parliament establishes PEGA Committee to investigate spyware use within EUPEGA Committee received mandate to investigate Pegasus and equivalent surveillance technologies deployed against EU citizens, members of parliament, and political figures.
- 2022CREDIBLE REPORTINGMeta (Facebook) obtains court order banning NSO employees from its platforms; NSO defaults on debt.NSO's reported $500 million debt default followed revenue decline after Entity List placement restricted operations and client relationships.
Key People
Organizations
Evidence Library
- documentDOC-CL1Citizen Lab Technical Analysis: The Million Dollar Dissident (August 2016)
University of Toronto research report documenting the first forensic identification of NSO Pegasus spyware targeting Ahmed Mansoor through iOS zero-day exploits. Established baseline technical signatures and infection methodology that enabled future detection efforts. Represents primary academic documentation of NSO's capabilities.
- court filingCOURT-WA1WhatsApp Inc. v. NSO Group Technologies Ltd., Complaint (U.S. District Court Northern California, October 2019)
Legal complaint alleging NSO violated Computer Fraud and Abuse Act by exploiting WhatsApp infrastructure to deliver Pegasus to approximately 1,400 devices. Provides detailed technical description of exploit methodology and identifies specific victims including human rights defenders. First major U.S. litigation against commercial spyware vendor.
- documentDOC-AI1Amnesty International Forensic Methodology Report (July 2021)
Technical documentation of Mobile Verification Toolkit and forensic procedures used to detect Pegasus infections on iOS and Android devices. Established open-source methodology enabling independent verification of infections and served as evidentiary foundation for Pegasus Project reporting.
- leakpartial redactionLEAK-FBD1Pegasus Project Database: 50,000 Phone Numbers (July 2021)
Leaked list of phone numbers selected by NSO clients as persons of interest between 2016-2021, obtained by Forbidden Stories and shared with seventeen media organizations. While presence on list did not confirm infection, forensic testing of accessible devices confirmed dozens of successful Pegasus deployments against journalists and activists.
- documentGOV-COM1U.S. Commerce Department Entity List Addition Notice (Federal Register, November 2021)
Federal Register notice adding NSO Group and Candiru to Entity List for trafficking in cyber tools used to gain unauthorized access to systems. Restricts export of U.S.-origin items to designated entities and represents formal government determination of malicious cyber activity.
- court filingCOURT-AP1Apple Inc. v. NSO Group Technologies Ltd., Complaint (U.S. District Court Northern California, November 2021)
Apple's lawsuit seeking permanent injunction preventing NSO from using any Apple software, services, or devices. Alleges violations of Computer Fraud and Abuse Act through FORCEDENTRY exploit targeting Apple's iMessage platform. Includes technical details of zero-click exploit chain affecting iOS 14.
- documentDOC-CL2Citizen Lab Report: Hide and Seek - Tracking NSO Group's Pegasus Spyware to Operations in 45 Countries (September 2018)
Academic research mapping NSO infrastructure to surveillance operations in 45 countries through network analysis and forensic examinations. Documented infections in Mexico targeting journalists investigating corruption and Saudi Arabia targeting dissidents. Established global scope of Pegasus deployment beyond previously known cases.
- documentGOV-EU1European Parliament PEGA Committee of Inquiry Establishment Resolution (March 2022)
Parliamentary resolution establishing Committee of Inquiry to investigate use of Pegasus and equivalent surveillance spyware within European Union. Mandated investigation of targeting of MEPs, journalists, and civil society in member states including Spain, Hungary, Poland, and Greece. Represents institutional EU response to surveillance revelations.
Evidence Gallery




Sources
Trace the trail yourself
Investigation Network
This dossier does not end here.
- Pegasus Spyware and NSO GroupIsraeli cyberweapon sold to governments worldwide, used to surveil journalists, activists, and political opponents.Shared organization: NSO GroupShared person: Shalev HulioShared organization: Citizen Lab
- The Crypto Wars and Encryption BackdoorsDecades-long battle over whether governments should mandate encryption backdoors for law enforcement accessShared subject: Privacy, Surveillance
- 2018Amnesty International researchers find Pegasus infections on devices of Saudi dissident Omar Abdulaziz, associate of Jamal Khashoggi.Pegasus Spyware and NSO Group
- 2019WhatsApp sues NSO Group for exploiting call-handling vulnerabilities to infect 1,400 devices across 20 countries.Pegasus Spyware and NSO Group
- 2016FBI vs. Apple: government demands backdoor to San Bernardino shooter's iPhone; Apple refusesThe Crypto Wars and Encryption Backdoors
- 2016FBI withdraws legal action after purchasing third-party exploit for estimated $900,000+The Crypto Wars and Encryption Backdoors
- 2020EARN IT Act introduced in Congress, threatening encryption through liability frameworkThe Crypto Wars and Encryption Backdoors
- 2016Citizen Lab links Pegasus to UAE surveillance of activist Ahmed Mansoor; Apple patches iOS vulnerabilities.Pegasus Spyware and NSO Group
Live Discussion
0 Perspectives
Add to the record. Be specific. Cite where you can.
If you're learning about this topic for the first time, these are the best places to continue — documented evidence and historical relationships are the guide.

Named in “Pegasus Spyware” and 2 other published dossiers.
Named in “Pegasus Spyware” and 2 other published dossiers.
Shares 5 documented key players with “Pegasus Spyware”, including NSO Group.
Read more dossiers like this
Get a quiet one-line bulletin when new investigative files are published. Bound to this dossier — useful for tracking follow-ups.
