Jury orders NSO to pay $167 million for hacking WhatsApp users

Date:

Share:

A jury has awarded WhatsApp $167 million in punitive damages in a case the company brought against Israel-based NSO Group for exploiting a software vulnerability that hijacked the phones of thousands of users.

The verdict, reached Tuesday, comes as a major victory not just for Meta-owned WhatsApp but also for privacy- and security-rights advocates who have long criticized the practices of NSO and other exploit sellers. The jury also awarded WhatsApp $444 million in compensatory damages.

Clickless exploit

WhatsApp sued NSO in 2019 for an attack that targeted roughly 1,400 mobile phones belonging to attorneys, journalists, human-rights activists, political dissidents, diplomats, and senior foreign government officials. NSO, which works on behalf of governments and law enforcement authorities in various countries, exploited a critical WhatsApp vulnerability that allowed it to install NSO’s proprietary spyware Pegasus on iOS and Android devices. The clickless exploit worked by placing a call to a target’s app. A target did not have to answer the call to be infected.

“Today’s verdict in WhatsApp’s case is an important step forward for privacy and security as the first victory against the development and use of illegal spyware that threatens the safety and privacy of everyone,” WhatsApp said in a statement. “Today, the jury’s decision to force NSO, a notorious foreign spyware merchant, to pay damages is a critical deterrent to this malicious industry against their illegal acts aimed at American companies and the privacy and security of the people we serve.”

NSO created WhatsApp accounts in 2018 and used them a year later to initiate calls that exploited the critical vulnerability on phones, which, among others, included 100 members of “civil society” from 20 countries, according to an investigation research group Citizen Lab performed on behalf of WhatsApp. The calls passed through WhatsApp servers and injected malicious code into the memory of targeted devices. The targeted phones would then use WhatsApp servers to connect to malicious servers maintained by NSO.

Source link

Subscribe to our magazine

━ more like this

How to Harness Prime Day Traffic Without Slashing Prices

Opinions expressed by Entrepreneur contributors are their own. Amazon Prime Day means different things to different people....

The Funniest Death by Dinosaur in Each ‘Jurassic Park’ Movie

Deep in the jungle of Isla Nublar, game warden Robert Muldoon instructs a group of park employees on how to handle the transfer of...

34 Early 4th Of July Fashion Sales 2025 To Shop

Fourth of July fashion sales are firing up like all the barbecues and fireworks we’re going to enjoy over the holiday weekend. And unlike...

“Teddy Blonde” Is The Low-Effort Hair Color For Summer

That said, it’s still hair color, so with that in mind, how often do you need to refresh teddy blonde? “To start with, I...

The 'Old Secretariat' in Panaji, India

Panaji, the capital of Goa, features a fantastic riverfront along the Mandovi River, which flows past the city and into the Arabian Sea....