WhatsApp wins legal victory against NSO Group in Pegasus hacking case
Unlock the Editorâs Digest for free
Roula Khalaf, Editor of the FT, selects her favourite stories in this weekly newsletter.
WhatsApp has prevailed against Israeli spyware maker NSO Group in a US lawsuit over NSOâs abuse of the messaging app to enable the infiltration of the phones of journalists, activists and dissidents with its Pegasus hacking tool.Â
A judge in the Northern District of California ruled on Friday that NSO breached hacking laws and the terms of its service agreement with WhatsApp by using the messaging platform to inject more than 1,000 devices with its Pegasus spyware.Â
The ruling in the civil case did not address the rights of the individuals whose phones had been hacked, but it hands a victory to technology groups seeking to prevent their platforms from being abused by groups targeting their users.
It is also a win for Apple, Amazon and other tech giants that supported WhatsAppâs case.Â
âThe court finds no merit in the arguments raisedâ by NSO Group, judge Phyllis Hamilton ruled. The summary judgment means an upcoming trial will cover only the question of damages, rather than whether NSO can be held liable for its actions.
âAfter five years of litigation, weâre grateful for todayâs decision,â WhatsApp said. âNSO can no longer avoid accountability for their unlawful attacks on WhatsApp, journalists, human rights activists and civil society.âÂ
NSO Group did not immediately respond to a request for comment.Â
Pegasus can read encrypted messages stored on a phone, turn on its camera and microphone remotely and track its location. Its use has been tied to human rights abuses and the US Department of Commerce has blacklisted the Israeli company.Â
The legal case was launched after a 2019 Financial Times report that coincided with WhatsAppâs discovery that its services had been hacked by NSO and Pegasus.Â
The ruling said NSO Group did not dispute that it âmust have reverse-engineered and/or decompiled the WhatsApp softwareâ in order to hack phones, but had raised the possibility that it did so before agreeing to WhatsAppâs terms of service.Â
However, the judge found, âcommon sense dictates that [NSO] must have first gained accessâ to the WhatsApp software and NSO had offered âno plausible explanationâ for how it could have done so without agreeing to the terms of service. It ruled in favour of WhatsAppâs claim that NSO had violated federal and state hacking laws.Â
The judge also found that NSO had ârepeatedly failed to produce relevant discoveryâ, including in relation to the Pegasus source code.
âThis sets a precedent that will be cited for years to come,â said John Scott-Railton, a researcher at the University of Torontoâs Citizen Lab who has investigated the use of Pegasus.Â
âThis is the most-watched case about mercenary spyware and everyone is going to take note. I predict this will have a chilling effect on other shady spyware companiesâ efforts to enter the US market, and investorsâ interest in backing their hacking,â he said.
https://www.ft.com/__origami/service/image/v2/images/raw/https%3A%2F%2Fd1e00ek4ebabms.cloudfront.net%2Fproduction%2Fcba2c157-f8e2-4436-bcfc-67bf38a1a4a3.jpg?source=next-article&fit=scale-down&quality=highest&width=700&dpr=1
2024-12-21 10:14:33