Loading...

Politician Investigating Spyware Abuses Has His Phone Hacked With Pegasus

Key takeaways

  • NSO Group has faced unprecedented financial penalties in recent months as courts worldwide hold the cyber-arms company accountable for third-party exploitation of its Pegasus platform.
  • NSO Group’s clients in Europe have weaponized Pegasus against political opponents and civil society figures, prompting formal investigations and legal action.
  • Pegasus’s effectiveness as a surveillance tool stems from its exploitation of zero-click vulnerabilities that require no user interaction to compromise a device.
  • The May 2025 WhatsApp verdict signals that U.S. courts are prepared to impose substantial financial penalties on spyware manufacturers, likely encouraging additional civil litigation from victims and technology companies.

A politician leading investigations into spyware misuse discovered his own smartphone was infiltrated with Pegasus, the Israeli-developed surveillance tool manufactured by NSO Group, exposing the irony of state-sponsored hacking targeting those who seek accountability. The incident underscores how Pegasus—licensed exclusively to government security and law enforcement agencies worldwide since NSO Group’s founding in 2010—continues to breach phones running iOS and Android despite mounting legal consequences and International scrutiny. The case adds momentum to a growing wave of civil litigation and forensic evidence demonstrating that NSO’s technology, marketed as a counterterrorism and crime-fighting tool, has systematically targeted journalists, activists, dissidents, and political figures across multiple continents.

A Spyware Manufacturer Faces Mounting Legal Liability

NSO Group has faced unprecedented financial penalties in recent months as courts worldwide hold the cyber-arms company accountable for third-party exploitation of its Pegasus platform. In May 2025, a U.S. district court ordered NSO to pay $167 million in punitive damages and $444,719 in statutory damages—totaling approximately $167.4 million—to Meta and WhatsApp after a jury found the company’s violation of the Computer Fraud and Abuse Act “flagrant.” The verdict followed a December 2024 ruling that held NSO liable for hacking 1,400 WhatsApp users’ devices via Pegasus, marking a watershed moment in civil accountability for mercenary spyware manufacturers.

These legal setbacks represent a dramatic reversal for a company that has long maintained its innocence regarding human rights violations. NSO Group has stated: “Our technology was not associated in any way with [Jamal] Khashoggi’s murder. The company said it was on a life-saving mission preventing terror attacks and serious crimes.” Despite such denials, forensic evidence consistently demonstrates widespread abuse of the platform by government clients for political surveillance, blackmail campaigns, and intimidation of critics and opponents.

A Leaked Database Exposes 50,000 Targets Worldwide

The scope of Pegasus’s reach became undeniable when a leaked database revealed 50,000 phone numbers entered into NSO Group’s targeting system, exposing over 1,000 confirmed individuals from 50 or more countries as victims of surveillance. The database, uncovered by a consortium of international media outlets including The Wire, The Guardian, and the Washington Post in July 2021, identified politicians, heads of state, business executives, activists, and more than 180 journalists from outlets including CNN, The New York Times, and Al Jazeera as targets. The leak, dubbed “The Pegasus Project,” documented how governments paid NSO vast sums to spy on critics and political opponents rather than pursuing legitimate law enforcement objectives.

Forensic analysis by Amnesty International’s Security Lab has confirmed the identities and attack timelines of numerous high-profile victims. Siddharth Varadarajan, Founding Editor of The Wire, was targeted with Pegasus on his iPhone four times, with the most recent attack occurring on October 16, 2023, amid an unprecedented crackdown on journalists in India. Anand Mangnale, South Asia Editor at the Organized Crime and Corruption Reporting Project, was also confirmed as a Pegasus victim, illustrating how the spyware has systematically compromised investigative journalists across South Asia.

Political Targeting in Europe and Central America Drives New Lawsuits

NSO Group’s clients in Europe have weaponized Pegasus against political opponents and civil society figures, prompting formal investigations and legal action. In Poland, Pegasus was deployed predominantly for political purposes targeting critics of the ruling party; in Hungary, over 300 individuals including activists, journalists, lawyers, entrepreneurs, an opposition politician, and a former minister were confirmed as victims. The European Parliament’s Committee of Inquiry concluded that Pegasus and similar spyware tools facilitated systematic human rights violations in EU Member States through blackmail, smear campaigns, intimidation, and harassment tied to corruption.

Central American journalists have taken NSO to court directly. Roman Gressier, a journalist from El Faro, a Salvadoran news outlet, had his phone hacked with Pegasus four times before joining 17 colleagues in suing NSO Group in U.S. federal court under the Computer Fraud and Abuse Act. The journalists are seeking an injunction to stop NSO from operating in El Salvador and demanding the court compel NSO to disclose evidence of its spying activities, signaling a broader shift toward holding spyware manufacturers liable in foreign jurisdictions.

Technical Architecture: Zero-Click Exploits Enable Silent Infiltration

Pegasus’s effectiveness as a surveillance tool stems from its exploitation of zero-click vulnerabilities that require no user interaction to compromise a device. The spyware leverages a zero-click zero-day iMessage vulnerability codenamed FORCEDENTRY (CVE-2021-30860), which bypasses iOS’s BlastDoor security framework to deploy surveillance code silently. Combined with the Trident iOS exploits (CVE-2016-4655, CVE-2016-4656, CVE-2016-4657), Pegasus can jailbreak iPhones covertly and install persistent surveillance software capable of extracting messages, calls, photos, emails, and activating microphones and cameras without any indication to the device owner.

This technical sophistication explains why Pegasus has proven so difficult to detect and why victims often remain unaware of compromise for extended periods. Amnesty International responded by developing the Mobile Verification Toolkit (MVT), a forensic tool that helps users identify whether their iPhones or Android devices have been infected by Pegasus. The MVT works on iOS versions 7 through 14.6 and allows iPhone users to create complete backups once indicators of compromise are discovered, though NSO Group continues to deny widespread abuse despite mounting forensic evidence.

What Comes Next: Litigation and Regulatory Pressure Intensify

The May 2025 WhatsApp verdict signals that U.S. courts are prepared to impose substantial financial penalties on spyware manufacturers, likely encouraging additional civil litigation from victims and technology companies. Meta’s successful case against NSO has established a legal precedent that may embolden journalists, activists, and civil society organizations to pursue their own claims in federal court, potentially exposing NSO to billions in additional liability across multiple jurisdictions. Simultaneously, the European Parliament’s findings have prompted regulatory scrutiny in Brussels, where lawmakers are considering restrictions on spyware sales and stricter export controls on cyber-arms technology.

The targeting of a politician investigating spyware abuses exemplifies the circular nature of NSO’s abuse: those seeking accountability become targets themselves, creating additional evidence of misconduct and strengthening the case against the company. As forensic investigations continue and legal precedents accumulate, NSO Group faces an increasingly untenable position as a global manufacturer of surveillance tools, with courts, regulators, and civil society organizations converging on the conclusion that Pegasus has facilitated systematic human rights violations regardless of NSO’s stated intentions.

Written by
Marcus Feldman

Marcus Feldman analyzes cryptocurrency and blockchain markets — price movements, protocol upgrades, and the regulatory shifts reshaping crypto exchanges worldwide.