Espionage & Intelligence Operations

NSO Group and Pegasus

Israeli-Licensed Spyware, American Diplomats, and the Variant Built to Break U.S. Phones

Israeli spyware built by Unit 8200 alumni was found on the iPhones of U.S. State Department staff. Washington blacklisted the company, the FBI bought it anyway, and Israel licensed a version engineered specifically to hack American numbers.

In November 2021, Apple began sending threat notifications to people it believed had been hacked by state-grade spyware. Some of those notifications landed on the phones of American diplomats. At least nine, and by the Washington Post’s count eleven, U.S. State Department employees working in Uganda or on Ugandan affairs found that their iPhones had been broken into by Pegasus, the flagship product of the Israeli surveillance firm NSO Group.

It was the first known use of Pegasus against United States government personnel. No American agency has ever formally said who did it. The operator has never been publicly identified, and it is worth being precise about that: the hacking is documented, the attribution is not.

What Pegasus is

Pegasus is a zero-click intrusion tool. It does not require the target to tap a link or open a file. Once it lands, it takes the phone: messages, photographs, location, contacts, and the ability to switch on the microphone and camera. NSO Group, which builds it, was founded and staffed heavily by veterans of Unit 8200, the Israeli military’s signals intelligence corps, and it sells only to government agencies.

That last detail is what separates Pegasus from ordinary commercial software, and it is also where the Israeli state enters the story. Under Israel’s Defense Export Control Law, offensive cyber products cannot be sold abroad without a license from the Defense Export Controls Agency inside the Ministry of Defense. Every Pegasus sale is a licensed export. When the Israeli government wants to restrict where the tool goes, it can, and in November 2021 it did exactly that, cutting the approved customer list from 102 countries to 37 and dropping Saudi Arabia, the UAE, Mexico and Morocco.

This needs stating carefully, because it is the point most easily overstated. There is no court finding and no U.S. government determination that Israel picks NSO’s targets or receives what NSO’s customers collect. The Ministry of Defense says flatly that it does not have access to that data. What is established is narrower and still significant: Israel licenses the exports, holds a veto over who may buy, and has used that authority as an instrument of state.

Washington’s own verdict

On November 3, 2021, the Commerce Department added NSO Group to its Entity List, alongside the Israeli firm Candiru. The finding was made by a committee drawn from Commerce, State, Defense and Energy, and the stated grounds were that the companies had “developed and supplied spyware to foreign governments that used these tools to maliciously target government officials, journalists, businesspeople, activists, academics, and embassy workers.”

The listing bars American firms from supplying NSO with U.S.-origin technology, with no license exceptions and a presumption of denial. It is an export control rather than a financial sanction, so it freezes no assets. But the legal standard it rests on is the thing worth noting. To land on that list, a company must be judged to have acted “contrary to the national security or foreign policy interests of the United States.” That is the United States government’s own conclusion about a company licensed by its closest ally, published in the Federal Register.

Nearly five years on, NSO is still on the list. The company mounted an intensive lobbying campaign for removal, and Israel pressed Washington directly on its behalf. In May 2025 the Trump administration declined.

Phantom

The most consequential fact in this case is not about a hack that happened. It is about a capability that was built and licensed.

NSO’s standing defense against the charge that Pegasus threatens Americans is technical: the software is coded so that it cannot infect a phone with a +1 country code. The documented American victims are largely consistent with that, because they were U.S. persons using foreign numbers or sitting abroad, which is precisely the situation of the diplomats in Kampala.

Then NSO built a version without the restriction. According to reporting by Ronen Bergman and Mark Mazzetti of the New York Times, the variant was called Phantom, it was engineered specifically to defeat the American blocking, and in a demonstration for U.S. officials in Washington it successfully compromised a phone with a District of Columbia area code. It was marketed to American agencies from roughly 2019 into the summer of 2021.

Selling it required permission from the Israeli government, and the Israeli government gave it. Israel issued a special export license authorizing a tool purpose-built to hack United States phone numbers, for sale into the United States. That license is the sharpest available illustration of what the export authority actually means in practice.

The FBI’s turn

The United States was not merely a victim here. It was also, briefly, a customer.

The FBI bought Pegasus in 2019 for a reported five million dollars, and Israeli engineers installed and tested the system at a Bureau facility in New Jersey that June. Over the following two years the Bureau worked through whether to use it. A Criminal Investigative Division memorandum in March 2021 recommended deployment under conditions that remain redacted. In July 2021 the Bureau reversed course and decided to “cease all efforts regarding the potential use of the NSO product,” citing human rights and publicity concerns.

The FBI’s public account is that it bought “a limited license for product testing and evaluation only” and that there was “no operational use in support of any investigation.” Director Christopher Wray told senators the purchase was made “to be able to figure out how bad guys could use it.” When internal documents surfaced showing how far the deliberations had gone, Senator Ron Wyden publicly disputed the completeness of that account.

There is a stranger coda. In April 2023 the Times reported that a U.S. contractor had bought and deployed an NSO geolocation tool called Landmark for the American government, and that White House officials, unaware of it, ordered the FBI to find the buyer. The Bureau’s inquiry established that the ultimate customer was the FBI. The contract had been signed on November 8, 2021, five days after the Entity List designation, through a firm called Riva Networks operating under the cover name “Cleopatra Holdings.” The tool was used to track phones in Mexico. Wray terminated the contract in late April 2023.

What the courts found, and what Israel did about it

Meta sued NSO in 2019 over an exploit that pushed Pegasus onto roughly 1,400 WhatsApp users. NSO argued it was shielded by foreign sovereign immunity as an agent of the states it served. The Ninth Circuit rejected that, and in January 2023 the Supreme Court declined to hear the appeal, leaving NSO answerable in American courts. On December 20, 2024, Judge Phyllis Hamilton granted summary judgment against the company on every claim, finding it liable under the Computer Fraud and Abuse Act, California’s computer crime statute, and for breach of contract.

She also sanctioned NSO for failing to produce discovery, including the Pegasus source code.

The reason it could not produce those documents is the part that belongs in this archive. In July 2020, at NSO’s request, the Israeli government obtained a court order in Tel Aviv allowing officials to search the company’s offices and seize files, and barring NSO from handing documents to any external party without Israeli authorization. The order itself was placed under a gag. The effect, revealed by the Guardian in 2024, was that a foreign government’s intervention prevented an American federal court from obtaining evidence in a case brought by an American company, and the American judge sanctioned the defendant for the resulting failure.

A jury awarded roughly $168 million in May 2025. The number is widely quoted and it is no longer the number: in October 2025 Judge Hamilton cut the punitive award to about $4 million, reasoning that there had not yet been enough cases of unlawful electronic surveillance in the smartphone era to treat the conduct as maximally egregious. She granted a permanent injunction barring NSO from targeting WhatsApp users. In June 2026 Meta returned to court alleging the injunction had already been violated. That motion has not been resolved.

Apple filed its own suit in November 2021 and survived a motion to dismiss in early 2024. Then, in September 2024, Apple asked to drop its own case, saying continued litigation risked exposing its threat intelligence methods and citing the Israeli seizure of NSO’s documents. NSO agreed to the dismissal. No court ever ruled on the merits.

Why it belongs here

Most of this archive is history. This one is current, and it is the clearest modern instance of the pattern the rest of the site documents.

An Israeli company staffed by alumni of Israel’s signals intelligence corps, selling under licenses granted by the Israeli Ministry of Defense, produced a tool that was used against American diplomats. The United States government concluded in writing that the company had acted against American national security and foreign policy interests. Israel then licensed a version engineered to defeat the one technical safeguard protecting American phones, so that it could be sold to American agencies. When an American federal court tried to compel evidence from the company, the Israeli state stepped in and stopped it, and the American judge punished the company for a failure the Israeli government had caused.

What did not follow is the familiar part. There has been no formal attribution of the attacks on the State Department. No Israeli official has faced any consequence in the United States. The single durable American action, the Entity List designation, restricts what American companies may sell to NSO. It does not address what NSO’s product did to Americans.

Sources

  • U.S. Department of Commerce, Bureau of Industry and Security, “Commerce Adds NSO Group and Other Foreign Companies to Entity List for Malicious Cyber Activities,” November 3, 2021; Federal Register doc. 2021-24123, November 4, 2021
  • Reuters, “Exclusive: U.S. State Department phones hacked with Israeli company spyware,” Christopher Bing and Joseph Menn, December 3, 2021
  • WhatsApp Inc. v. NSO Group Technologies Ltd., N.D. Cal. No. 4:19-cv-07123 (Hamilton, J.) — summary judgment December 20, 2024; jury verdict May 6, 2025; permanent injunction and remittitur October 2025
  • NSO Group Technologies Ltd. v. WhatsApp Inc., certiorari denied January 9, 2023 (sovereign immunity rejected)
  • Apple Inc. v. NSO Group Technologies Ltd., N.D. Cal. No. 3:21-cv-09078 (Donato, J.) — motion to dismiss denied January 2024; voluntarily dismissed by Apple September 13, 2024
  • New York Times Magazine, “The Battle for the World’s Most Powerful Cyberweapon,” Ronen Bergman and Mark Mazzetti, January 28, 2022; and subsequent NYT reporting on FBI internal documents (2022) and the Riva Networks / Landmark contract (2023)
  • The Guardian, “Israeli officials seized NSO documents in 2020,” July 25, 2024
  • Executive Order 14093, “Prohibition on Use by the United States Government of Commercial Spyware That Poses Risks to National Security,” March 27, 2023
  • Israel Defense Export Control Law, 5767-2007, and Ministry of Defense Defense Export Controls Agency licensing policy; Calcalist reporting on the November 2021 reduction of the approved export list from 102 to 37 countries
  • Citizen Lab forensic reporting on Pegasus targeting, including the December 2021 analysis of Hanan Elatr Khashoggi’s device
  • Washington Post, “Pegasus spyware maker rebuffed in efforts to get off trade blacklist,” May 20, 2025