Facebook sues NSO Group for alleged WhatsApp hack
Full article764 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
WhatsApp’s investigation traced WhatsApp accounts used in a sweeping attack on mobile users to NSO Group.
Facebook, which owns the popular messaging application WhatsApp, has sued software surveillance vendor NSO Group, alleging that the Israeli company violated a federal anti-hacking law.
The lawsuit filed in a federal court Tuesday alleges that NSO Group violated the Computer Fraud and Abuse Act when NSO’s custom malware was deployed on some 1,400 mobile devices with WhatsApp installed during a sweeping attack in April and May. At least 100 human rights advocates, journalists, and other members of civil society around the world were targeted in the attack, according to WhatsApp.
WhatsApp’s investigation traced user accounts employed by the attackers back to NSO Group, and uncovered computer servers that were previously associated with the Israeli vendor, according to Will Cathcart, head of WhatsApp.
“This should serve as a wake-up call for technology companies, governments and all internet users,” Cathcart wrote in an op-ed for The Washington Post. “Tools that enable surveillance into our private lives are being abused…”
In a statement, NSO Group vowed to fight the lawsuit. “In the strongest possible terms, we dispute today’s allegations and will vigorously fight them.”
The company has denied involvement in the attack, which was first reported in May by the Financial Times. The spyware developed by NSO Group could be used to infect anyone’s phone by calling them, the story alleged.
“We consider any other use of our products than to prevent serious crime and terrorism a misuse, which is contractually prohibited,” NSO Group’s statement said. “We take action if we detect any misuse.”
In recent years, NSO Group’s signature spyware, known as Pegasus, has been used to target journalists, anticorruption watchdogs and political dissidents in countries like Mexico and Morocco, according to researchers. NSO Group says it lawfully sells its technology to governments to combat terrorism and organized crime. But despite NSO Group’s pledge to more rigorously adhere to human rights standards last month, human rights advocates remain skeptical of that commitment.
For his part, Cathcart said NSO Group’s claim that it has no insight into the targets of its spyware undercuts the vendor’s new human rights pledge.
Cathcart also called on tech companies to collaborate more closely to protect human rights by sharing technical information to build more secure systems.
“Governments and companies need to do more to protect vulnerable groups and individuals from these [mobile] attacks,” Cathcart wrote.
You can read the full complaint below.
UPDATE: 05:39 p.m. EDT: This story has been updated with a statement from NSO Group.
[documentcloud url=”http://www.documentcloud.org/documents/6532387-Gov-Uscourts-Cand-350613-1-0.html” responsive=true]
More Scoops
Meta accuses NSO Group of defying spyware injunction, files contempt of court complaint
The company said it spotted a spearphishing campaign linked to the Israeli spyware maker targeting WhatsApp users, despite a court order prohibiting it.
One House Democrat is pressing Commerce on the government’s spyware use
FBI, CISA issue PSA on Russian intelligence campaign to target messaging apps
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
Jail time for Maine child in 764 marks turning point in federal law enforcement
Technology
FCC proposes public scorecard to rate telecoms on anti-robocall efforts
Wyden seeks upgraded NSA security guidance on commercial VPN use
The Collective Cyber Defense letter wrote your next vendor questionnaire
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Threats
Chinese espionage groups swarm to exploit triple-link chain of zero-days
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Election official says Tina Peters would be consultant, won’t have access to election systems
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/facebook-nso-group-whatsapp-cfaa/