The Pegasus Project, a collaboration of 17 media organisations coordinated by Forbidden Stories with technical support from Amnesty International, reported that NSO Group’s Pegasus spyware had been used to target journalists, activists, and political figures.
What happened
- The investigation was based on a leaked list of more than 50,000 phone numbers believed to be of interest to NSO clients.
- Amnesty’s Security Lab found forensic traces of Pegasus on a number of phones, including those of journalists.
- Reporters identified numbers linked to heads of state and to people close to murdered journalist Jamal Khashoggi.
- NSO Group denied the allegations; in November 2021 the US government added it to its trade blacklist.
Why it mattered
The revelations triggered investigations in several countries and wider scrutiny of the commercial spyware industry. The European Parliament later set up a committee of inquiry into the use of Pegasus and similar spyware in EU countries.
Lessons for organisations
Keep mobile operating systems updated, consider enhanced protections such as Apple’s Lockdown Mode for high-risk staff, and include mobile devices in threat monitoring. Staff who travel to high-risk countries may need separate, clean devices.
Source: Amnesty International USA
Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.