Project Torogoz (El Salvador)
Citizen Lab and Access Now reported 35 individuals and 37 devices targeted July 2020 to November 2021, including journalists and civil-society members, with one-click links, zero-click infection, and data exfiltration evidence.
- 01Evidence status: FORENSICALLY CONFIRMED
- 02Attack vector: KISMET / FORCEDENTRY (one-click and zero-click)
- 03Spyware: Pegasus
- 04Individuals: 35
- 05Devices: 37
- 06Researcher: Citizen Lab / Access Now
What Happened
Citizen Lab and Access Now reported 35 individuals and 37 devices targeted July 2020 to November 2021, including journalists and civil-society members, with one-click links, zero-click infection, and data exfiltration evidence.
Evidence
Evidence status: FORENSICALLY CONFIRMED
Attack vector: KISMET / FORCEDENTRY (one-click and zero-click)
Individuals documented: 35
Devices documented: 37
“Project Torogoz (El Salvador) involved Pegasus.”
Researcher: Citizen Lab / Access Now. Primary source: CL-TOROGOZ.
Attribution
Attributed to a Pegasus operator by Citizen Lab.
What NSO Group Says
NSO Group has stated its technology is licensed to vetted governmental agencies for legitimate law-enforcement and national-security purposes. NSO has not typically commented on individual cases or operators.
Legal Status
2026: El Faro journalists' lawsuit against NSO Group dismissed September 30, 2026; plaintiffs stated intent to appeal.
