WhatsApp 2019 Targeting Campaign
WhatsApp reported approximately 1,400 users targeted during the documented attack period via a zero-click vulnerability in its calling infrastructure. This became the basis of WhatsApp v. NSO Group.
- 01Evidence status: CONFIRMED
- 02Attack vector: WhatsApp zero-click (CVE-2019-3568)
- 03Spyware: Pegasus
- 04Individuals: 1400
- 05Researcher: WhatsApp / Citizen Lab
What Happened
WhatsApp reported approximately 1,400 users targeted during the documented attack period via a zero-click vulnerability in its calling infrastructure. This became the basis of WhatsApp v. NSO Group.
Evidence
Evidence status: CONFIRMED
Attack vector: WhatsApp zero-click (CVE-2019-3568)
Individuals documented: 1400
“WhatsApp 2019 Targeting Campaign involved Pegasus.”
Researcher: WhatsApp / Citizen Lab. Primary source: META-2019-05.
Attribution
WhatsApp attributed the attack to NSO Group.
What NSO Group Says
NSO Group has stated its technology is licensed to vetted governmental agencies for legitimate law-enforcement and national-security purposes. NSO has not typically commented on individual cases or operators.
Legal Status
WhatsApp v. NSO Group litigation; 2024 liability ruling; 2025 damages and permanent injunction.
