Pegasus Myths vs Facts
Pegasus is surrounded by myths, misconceptions, and sensationalism. This page separates verified facts from common myths, with each claim labeled by its evidentiary status.
- 01Pegasus is real, documented, and forensically confirmed — not a conspiracy theory
- 02Being on a target list does not mean a device was infected — only forensic analysis confirms infection
- 03End-to-end encryption does not protect against device-level compromise
- 04Factory resetting destroys forensic evidence — do not do it if you suspect infection
- 05Standard antivirus apps cannot detect Pegasus — specialized forensic tools are required
Common Myths and the Facts
| Myth | Fact | Evidence Status |
|---|---|---|
| Pegasus is a conspiracy theory | Pegasus is real and forensically confirmed by multiple independent researchers | FORENSICALLY CONFIRMED |
| Only important people get targeted | Journalists, activists, lawyers, and family members of targets have all been confirmed as victims | FORENSICALLY CONFIRMED |
| Being on the target list means you were infected | The list shows selection for potential targeting — not confirmed infection | REPORTED |
| End-to-end encryption protects you from Pegasus | Pegasus reads messages on-device after decryption, bypassing encryption entirely | FORENSICALLY CONFIRMED |
| Only iPhones are targeted | Both iOS and Android devices have been confirmed as Pegasus targets | FORENSICALLY CONFIRMED |
| You can tell if your phone is infected by battery drain | Battery drain has many causes and is not proof of infection | NOT INDEPENDENTLY VERIFIED |
| Antivirus apps can detect Pegasus | Standard mobile antivirus cannot detect Pegasus — specialized forensic tools are needed | FORENSICALLY CONFIRMED |
| Factory reset will fix it | Factory reset removes the spyware but destroys forensic evidence | FORENSICALLY CONFIRMED |
| Pegasus only works on old phones | Pegasus has been documented on the latest iOS and Android versions, sometimes before patches are available | FORENSICALLY CONFIRMED |
| NSO Group can see all the data collected | NSO claims it does not operate the technology or access client data — but this is disputed | DISPUTED |
| Pegasus is the only mercenary spyware | Multiple vendors exist: Candiru, Cytrox/Intellexa, Quadream, and others | FORENSICALLY CONFIRMED |
| Lockdown Mode makes you immune | Lockdown Mode significantly reduces risk but is not a guarantee — a 2024 variant bypassed it | FORENSICALLY CONFIRMED |
| Only governments use Pegasus | NSO states it sells only to governments, but the full client list is not public | REPORTED |
| Pegasus can be removed by deleting a message | Pegasus is a full system compromise — deleting a message does not remove it | FORENSICALLY CONFIRMED |
| You would know if you were targeted | Zero-click attacks leave no visible trace — victims typically have no idea | FORENSICALLY CONFIRMED |
Detailed Myth-Busting
Myth: "Pegasus is just a conspiracy theory"
Pegasus has been documented and forensically confirmed by multiple independent, reputable research organizations, including:
- Citizen Lab (University of Toronto's Munk School) — multiple peer-reviewed reports since 2016
- Amnesty International Security Lab — developed MVT and performed forensic analysis for the Pegasus Project
- Lookout — co-discovered the Trident exploit chain in 2016
- Forbidden Stories — coordinated the Pegasus Project with 80+ journalists from 17 media organizations
- Google TAG (Threat Analysis Group) — has independently documented Pegasus and related spyware
The evidence includes device forensics, network analysis, exploit code analysis, and NSO Group's own legal responses to lawsuits. Pegasus is not a theory — it is one of the most thoroughly documented surveillance tools in history.
Myth: "Being on the target list means you were infected"
The leaked Pegasus Project database contained 50,000+ phone numbers selected by NSO clients as potential targets. Being on this list means the operator was interested in surveilling that person. It does not mean the device was successfully infected.
Forensic confirmation of infection requires laboratory analysis of the device itself. Of the 50,000+ numbers on the list, a subset has been forensically confirmed as infected. Many numbers on the list may represent attempted but unsuccessful infections, or numbers that were selected but never actually targeted.
Myth: "End-to-end encryption protects me"
End-to-end encryption (E2EE) protects messages in transit between devices. But once a message arrives on the target's phone, it is decrypted for display. Pegasus reads the decrypted message directly from the device's memory or storage — after the encryption has been removed.
No encryption standard — no matter how strong — can protect against this. The vulnerability is physical access to the device, not a weakness in the encryption. Signal, WhatsApp, iMessage, and all other E2EE apps are equally vulnerable to Pegasus.
Myth: "I would know if I was targeted"
Zero-click Pegasus attacks are specifically designed to leave no visible trace. The target receives a message, the exploit fires automatically, the message is silently deleted, and the phone is compromised — all without the user ever knowing anything happened.
There is no notification, no visible message, no app icon, and no obvious sign of compromise. This is why tools like Apple Threat Notifications and MVT are so important — they are among the few ways to detect targeting without forensic expertise.
Myth: "Factory reset will fix it"
A factory reset will remove Pegasus from the device, but it also destroys all forensic evidence that could confirm the infection, identify the exploit used, and support legal action. If you suspect you are targeted:
- Do NOT factory reset — preserve evidence
- Create an encrypted backup of the device
- Update the OS to patch known vulnerabilities
- Enable Lockdown Mode (iOS)
- Contact professional forensic investigators
See the Incident Response guide for full instructions.
Myth: "Antivirus apps can detect Pegasus"
Standard mobile antivirus apps are designed to detect common malware — not advanced mercenary spyware like Pegasus. Pegasus operates at the system level, uses encrypted communications, and includes anti-forensic features specifically designed to evade detection.
Detecting Pegasus requires specialized forensic tools like MVT (Mobile Verification Toolkit), which analyzes device backups and logs for indicators of compromise. Even MVT can produce false negatives — a clean scan does not guarantee the device was never infected.
Myth: "Lockdown Mode makes you immune"
Lockdown Mode significantly reduces the attack surface for zero-click exploits by disabling high-risk features. However, in 2024, Citizen Lab documented a Pegasus variant ("LOCKDOWN-LESS") that exploited a vulnerability even on devices with Lockdown Mode enabled. Apple patched this vulnerability, but the incident shows that Lockdown Mode is a defense-in-depth measure, not an absolute barrier.
Lockdown Mode should be combined with other measures: OS updates, hardware security keys, and professional forensic checks for high-risk users.
