Skip to content
PRA/Last Research Update: October 2026
Latest Developments →

Full Zero Click Pegasus Technology, Entire Source Codes & Technical Blueprints. Complete Tech Stack ₿ 0.50 BTC. Contact us.

WhatsApp v. NSO Group

In October 2019, WhatsApp (Meta) sued NSO Group in US federal court for exploiting a vulnerability in WhatsApp's call setup feature to deliver Pegasus to approximately 1,400 targets worldwide. The case set important precedents for holding spyware vendors accountable in US courts.

Last Verified 2026-10-01Author Pegasus Research ArchiveEditor Editorial Team
  • 01WhatsApp sued NSO Group in October 2019 in the Northern District of California
  • 02The lawsuit alleged NSO exploited a WhatsApp call setup vulnerability (CVE-2019-3568) to deliver Pegasus
  • 03Approximately 1,400 targets were affected across multiple countries
  • 04The Ninth Circuit ruled NSO could not claim sovereign immunity, allowing the case to proceed to discovery
  • 05The case established that spyware vendors can be held liable under US law (CFAA and state law claims)

Background

In May 2019, WhatsApp discovered that a vulnerability in its call setup feature was being exploited to deliver Pegasus spyware to targets worldwide. The exploit worked through WhatsApp's VOIP call functionality: an attacker could call the target's WhatsApp, and even if the call was not answered, the exploit would execute and install Pegasus. The calls would often appear as missed calls and were deleted from the call log.

WhatsApp identified approximately 1,400 targets across at least 20 countries, including journalists, human rights activists, lawyers, and political dissidents. The vulnerability was assigned CVE-2019-3568 and was patched in WhatsApp's May 2019 update.

The Lawsuit

On October 29, 2019, WhatsApp Inc. (a subsidiary of Meta/Facebook) filed a lawsuit against NSO Group in the US District Court for the Northern District of California. The complaint alleged:

  • Violation of the Computer Fraud and Abuse Act (CFAA): NSO allegedly accessed WhatsApp's servers without authorization
  • Violation of California's Comprehensive Computer Data Access and Fraud Act: Similar to CFAA under California law
  • Breach of contract: NSO allegedly violated WhatsApp's Terms of Service
  • Trespass: NSO allegedly trespassed on WhatsApp's servers and users' devices

NSO Group's Defense

NSO Group moved to dismiss the lawsuit, arguing:

  • Sovereign immunity: NSO argued that because its products are used by foreign governments, it should be treated as an instrument of those governments and granted sovereign immunity
  • Political question doctrine: NSO argued that the case involved foreign policy decisions that should not be adjudicated by US courts
  • Lack of jurisdiction: NSO argued that US courts did not have jurisdiction over its activities

The Ninth Circuit Ruling

Key Precedent (November 2021)

The US Court of Appeals for the Ninth Circuit ruled against NSO Group, holding that:

  • NSO Group was not entitled to sovereign immunity — a private company does not become a foreign sovereign merely because it contracts with one
  • The political question doctrine did not apply — the case involved standard tort and contract claims that courts can adjudicate
  • WhatsApp's claims could proceed to discovery

This ruling was a landmark precedent: it established that commercial spyware vendors can be held liable in US courts for their products' actions, even when their clients are foreign governments.

Current Status: Verdict, Injunction, and Contempt

Following the Ninth Circuit ruling, the case proceeded to discovery. In late 2024, the district court ruled in favor of WhatsApp. In 2025, a jury awarded WhatsApp $167 million in damages, and the district court entered a permanent injunction barring NSO Group from ever targeting WhatsApp and its users again. The court was unequivocal: NSO violated federal and state laws against hacking.

June 2026: Contempt Filing

On June 8, 2026, WhatsApp announced it was asking the court to hold NSO Group in contempt for violating the permanent injunction. WhatsApp reported that it had caught and disrupted NSO-linked spearphishing attempts — 1-click phishing campaigns using malicious domains to trick people into clicking links to external websites. WhatsApp also caught NSO creating test accounts and groups on WhatsApp, which were taken down.

WhatsApp shared threat indicators (malicious domains: ikhwancast.com, ghazacast.com, fr24cast.com) so that anyone can check if they were targeted by NSO-linked social engineering attempts.

NSO Group's CEO confirmed in court that the company looks for "vectors, or ways to access the phone" beyond WhatsApp, targeting browsers, operating systems, and other applications. Twelve civil rights organizations filed amicus briefs supporting WhatsApp's fight against NSO's appeal of the permanent injunction. WhatsApp also announced a significant contribution to theSpyware Accountability Initiative (SAI), which supports forensic research, user support, and advocacy organizations worldwide.

Source: Meta/WhatsApp, "Fighting Spyware: An Update from WhatsApp," June 8, 2026 (WA-2026-06-08)

FORENSICALLY CONFIRMED

“NSO Group exploited WhatsApp's call feature to deliver Pegasus to ~1,400 targets.”

WhatsApp identified the exploit, attributed it to NSO Group's Pegasus, and documented approximately 1,400 targets. The vulnerability (CVE-2019-3568) was patched in May 2019. In 2025, a jury awarded WhatsApp $167M in damages and a permanent injunction was entered. In 2026, WhatsApp filed for contempt citing continued NSO-linked targeting attempts.

WA-2026-06-08

Significance

  • Accountability precedent: Established that spyware vendors can be sued in US courts for their products' actions
  • No sovereign immunity: Private companies contracting with foreign governments do not get sovereign immunity
  • Platform rights: Technology platforms can sue attackers who abuse their infrastructure
  • Discovery access: Allowed WhatsApp to access internal NSO Group documents through legal discovery
  • Deterrent effect: The case has had a chilling effect on the commercial spyware industry, demonstrating legal risk
A Spy In Your Pocket — Pegasus spyware can secretly access your photos, calls, messages, camera, microphone, GPS and more