Operational notes Observatory

NSO v WhatsApp: hacking a platform finally has its day in court

5 min read

The neoclassical facade of a courthouse with Corinthian columns and pediment, in black and white
Disputes over surveillance tools end up here, years after the tools were used.

For years, the commercial spyware market operated in a grey area: tools sold to governments, used against journalists and activists, with no court to establish who was answerable for what. That grey area closed in a federal courtroom in California. NSO Group, the Israeli company that makes the Pegasus spyware, has been found liable for the attack that compromised the devices of roughly 1,400 WhatsApp users in 2019 — and a jury put a figure on the bill: more than $167 million in punitive damages. It is the first time a commercial spyware maker has been found liable by a US court. Here are the verified facts, and then the lesson — one that concerns not only surveillance vendors, but anyone whose executives carry a smartphone.

The facts, in order

  • The attack (2019): between April and May 2019, Pegasus was installed on the phones of roughly 1,400 WhatsApp users by exploiting a vulnerability in the call function — a “zero-click” attack, requiring no action whatsoever from the victim. Among the identified targets: journalists, human rights activists, diplomats. WhatsApp discovered the intrusion, blocked it, and in October 2019 sued NSO in California.
  • Liability (December 2024): after five years of procedural battle, federal judge Phyllis Hamilton definitively established NSO’s liability for violating the Computer Fraud and Abuse Act, California’s law on unauthorised computer access, and WhatsApp’s terms of service. The court also sanctioned NSO for failing to hand over Pegasus’s source code as ordered.
  • The verdict (May 2025): a jury ordered NSO to pay $167.25 million in punitive damages, plus roughly $444,000 in compensatory damages.
  • NSO’s defence: the company has always maintained that it sells Pegasus only to selected governments and agencies, to counter terrorism and serious crime, and it called the damages “excessive and unconstitutional”, announcing it would appeal.
  • The injunction (October 2025): the same judge reduced the punitive damages to roughly $4 million — applying constitutional limits on the ratio to compensatory damages — but imposed a permanent injunction on NSO: no more attacks on WhatsApp, and deletion of the code obtained unlawfully. NSO welcomed the reduction, noting that the injunction does not concern its government clients. The appeal is ongoing.

The final financial reckoning will be decided on appeal. But the legal precedent is already written, and it will not change: hacking a platform to conduct surveillance is a wrong that gets paid for in court, whoever the end client may be.

Lesson one: “we only sell to governments” is no shield

NSO’s central argument — that responsibility lies with whoever uses the tool, not with whoever makes it — did not hold up. The court looked at who had materially breached WhatsApp’s systems to install the spyware, and at the terms of service accepted to access them. It is a principle that technology buyers should read in reverse: the chain of responsibility between supplier, tool and end use exists, and is enforceable. This holds for spyware just as it does for AI: when you adopt a system, you need to know in writing who answers for what — how it is built, on what data, with what limits on use. It is why our approach starts from the client retaining control of the system, not from blind delegation to the supplier; and it is the same logic that European rules are now making mandatory: documented responsibilities, not declared ones.

Lesson two: an executive’s smartphone is a business risk

The most important technical detail of the case is “zero-click”: the victims made no mistake whatsoever. No link opened, no attachment. Receiving a call was enough. This demolishes the idea that mobile security is a matter of user training: against a sophisticated actor, your chief executive’s device is a reachable target even if they do everything right. And that device carries negotiations, pricing, intellectual property, litigation. Security for top-tier phones — forced updates, separation between personal and corporate devices, advanced protection modes for high-risk travel, periodic checks — is not intelligence-agency paranoia: it is ordinary risk management, on the same footing as insurance cover. For those operating in sensitive sectors such as defence, it is also a reliability requirement towards clients.

Lesson three: terms of service are a contract, and courts enforce them

Among the grounds for the ruling is the breach of WhatsApp’s terms of service: NSO had created accounts on the platform to use as a beachhead. It looks like a technicality; it is a signal: platforms’ terms of use — the ones nobody reads — are contracts that courts enforce, in both directions. For a company this means two things. First: when your systems or your suppliers integrate with third-party platforms, those platforms’ usage limits become your constraints, to be mapped before building critical processes on top of them. Second: your own terms and contracts are a tool of active defence — WhatsApp won partly thanks to its own. Anyone designing systems that operate within business processes must be able to answer a simple question: does this data flow breach the terms of any link in the chain?

What to do

  1. Treat top-tier devices as critical infrastructure: inventory, immediate updates, personal/corporate separation, advanced protections for those travelling to high-risk areas.
  2. Map the chain of responsibility of your technology suppliers: who is answerable if the tool causes harm or breaches a regulation? It must be written into the contract.
  3. Catalogue the terms of service of the platforms you depend on: integrations, APIs, automations — check that the use you make of them (or that a supplier makes on your behalf) stays within the rules.
  4. Plan for the compromise scenario: if an executive’s phone had been under surveillance for six months, what would be exposed? The answer guides what to encrypt, segregate, and keep off that channel altogether.

Want a concrete assessment of your devices’ exposure and your technology supply chain? Half an hour with one of our experts for the first map.

Sources