Skip to main content

Facebook lawsuit may increase accountability for spyware makers

Facebook has sued the NSO Group, a security software maker, alleging it was responsible for using the WhatsApp message platform to spread spyware earlier this year. The lawsuit claims the NSO Group used WhatsApp servers to deliver spyware to 1,400 mobile devices between April and May, allowing it to decrypt private messages. Facebook wants an injunction against the NSO Group barring it from using WhatsApp or Facebook services, along with damages and costs.

While at first, the lawsuit seems to be focused around how the NSO Group interfered with the service, used WhatsApp servers without authorization, and additionally broke the terms of service, the lawsuit has wider implications. A later section states the NSO Group used the spyware, “to target attorneys, journalists, human rights activists, political dissidents, diplomats, and other senior foreign government officials.”

The NSO Group has responded to the lawsuit with a statement that concentrates solely on this accusation, stating that it provides its technology to licensed government intelligence and law enforcement agencies, and that its software is expressly made to target terrorism and serious crime. “We consider any other use of our products than to prevent serious crime and terrorism a misuse, which is contractually prohibited,” the company said.

Pegasus spyware

The software installed by the NSO Group, known as Pegasus, is “among some of the most sophisticated spyware available on the market,” according to Citizen Lab, a human rights research group that has investigated the attack. Once installed, it can steal critical data including passwords, contacts, calendars, messages, and can even monitor live calls. The software can also use the microphone, GPS, and camera to further spy on the phone’s owner.

Prior to the WhatsApp hack, the NSO Group’s Pegasus software had also been linked to repeated surveillance attempts against a Moroccan investigative journalist and a human rights lawyer, Amnesty Tech uncovered in October. Amnesty International is also suing the NSO Group. Danna Ingleton, program director at Amnesty Tech, wrote at the time:

“NSO is not currently able to prevent governments from unlawfully using its surveillance technology as tools to abuse human rights. Instead of attempting to whitewash human rights violations associated with NSO products, the company must urgently put in place more effective due diligence processes to stop its spyware being abused.”

In a statement given to the Committee to Protect Journalists (CPJ) following Amnesty Tech’s report, an NSO Group spokesperson said its products are “not tools to surveil dissidents or human rights activists. That’s why contracts with all of our customers enable the use of our products solely for the legitimate purposes of preventing and investigating crime and terrorism. If we ever discover that our products were misused in breach of such a contract, we will take appropriate action.”

Accountability

Following the earlier exposure, the NSO Group introduced a new Human Rights Policy and added three high profile new advisers to its team. However, this new high profile lawsuit, brought about by one of the biggest and most known technology companies in the world, may prompt the NSO Group and other firms offering similar products, to take even further action to prevent misuse and increase accountability.

“This is the first time that an encrypted messaging provider is taking legal action against a private entity that has carried out this type of attack against its users,” WhatsApp wrote in a statement, emphasizing the significance of the lawsuit.

Digital Trends spoke to Joshua Long, Chief Security Analyst at Intego Security about the potential industry implications.

“Attributing an attack to a particular attacker is often a difficult task,” Long told us.

Although not a legal expert, Long pointed out that hopes for a wide industry change may be premature.

“Given that the lawsuit, perhaps incorrectly, identifies NSO Group as the perpetrator of the May 2019 attacks that exploited WhatsApp’s software, and that NSO Group presumably makes, or has the potential to make, more money from its nation-state clients than any monetary damages for which the court might find NSO Group liable, and that there are countless methods for installing Pegasus spyware aside from exploiting WhatsApp vulnerabilities; it is difficult to imagine how this suit could have any meaningful impact on the operations of the NSO Group or any companies that offer similar products and services.”

Andy Boxall
Senior Mobile Writer
Andy is a Senior Writer at Digital Trends, where he concentrates on mobile technology, a subject he has written about for…
Facebook reveals the cause of Monday’s global outage
The Facebook home page on a screen.

Facebook has revealed the cause of one of the worst service outages ever to hit the social networking site.

The downtime occurred on Monday, October 4, and affected billions of users globally for around six hours. It also knocked out other Facebook-owned services such as Messenger, Instagram, and WhatsApp.

Read more
This is how much Facebook’s outage is thought to have cost it
facebook hacked

It wasn’t just Facebook’s reputation that took a massive hit on Monday after its site went down globally along with Facebook Messenger, Instagram, and WhatsApp, which it also operates.

The company's ad revenue was also affected during the unexpected outage that some experts are saying is the worst to ever hit Facebook.

Read more
Facebook, WhatsApp, and Instagram are back after several hours offline
facebook hacked

Well, here's one way to start a week off on the wrong foot: Facebook, Facebook Messenger, WhatsApp, and Instagram were all down for several hours on Monday. Yes, completely down. Starting at roughly 9 a.m. PT, Downdetector started to show a sharp spike in reports of outages -- though as we look back, users were discussing unsent messages and broken apps even earlier.

As of 4 p.m. PT, the services had for the most part returned to working order, albeit with some cobwebs left to shake out, leaving everyone collectively scratching their heads and wondering how an outage of this scale happened.

Read more