John Scott-Railton Profile picture
May 6 14 tweets 5 min read Read on X
BREAKING: jury awards massive $167 million in punitive damages against spyware company NSO Group.

Precedent-setting win against the notorious #Pegasus spyware maker.

Congratulations to @WhatsApp on sticking this case through since 2019. Some thoughts 1/
2/ After years of every trick & delay tactic it only took a California jury one days deliberation to the heart of the matter:

NSO makes millions hacking mostly-🇺🇸American tech companies... so that dictators can hack dissidents.

Their conduct deserved to be punished.
3/ NSO Group emerges from the trial severely damaged.

The verdict ($167,256,000 punitive, $440K+ compensatory) is big enough to make your eyes water.

The case is ALSO a huge blow to NSO's secrecy, with their business splashed all over a courtroom.

This will scare customers...
4/ Rewind to 2019.

About this time (April-May) @WhatsApp catches NSO Group hacking its users with #Pegasus across the messenger.

They investigated.

We @citizenlab also helped to investigate the victims get in touch with the many activists journalists etc.

There were many. Image
5/ Prior to @WhatsApp engaging, NSO acted the playground bully.

Targeting victims that dared speak up & researchers like us.

Suddenly, the bully met their match.

To the eternal credit of leadership at Meta & WhatsApp, they stuck this fight out & carried this case across the finish line.
6/ Back in 2019 no country had sanctioned NSO Group...

There had been no parliamentary hearings, no hearings in congress, no serious investigations.

WhatsApp's lawsuit helped carry momentum at a critical time, and showed governments that their tech sectors were in the crosshairs from mercenary spyware too...
7/ WhatsApp's choice to notify was also hugely consequential.

A LOT of cases were first surfaced from these notifications.

With dissidents around the world suddenly learning that dictators were snooping in their phones...with NSO Group's help.

They also set the tone for notifications that followed...
8/ Transparency: Note that I made a slight typo in Tweet #3: correct punitive damages are: $167,254,000 (not $167,256,000).
9/ A sidebar to this verdict for us @citizenlab.

One of NSO's many tactics was to leverage the case badger us researchers for months to try and extract information.

It never worked, but it is a reminder of the kinds of tactics that these firms prefer...instead of coming clean.

theintercept.com/2024/05/06/peg…Image
10/ For a long time there a handful of us doing mercenary spyware research.

Having @WhatsApp independently do serious investigating & publicly attribute hacking to NSO Group was huge for helping the rest of the world see the severity of the issue.

Thankfully, today this has changed.
11/ Ultimately, we wouldn't be here without civil society investigations of mercenary spyware... and alarm raising.

Thankfully today there's a whole accountability ecosystem growing around this work.

Dozens of orgs engaging.

Numbers are growing.

Pictured: just some of usImage
@WhatsApp @citizenlab 13/ For me personally, watching a jury of regular citizens see right through NSO's mendacity & hypocrisy and to the need to protect privacy... amazing.
14/ OH WOW, @WhatsApp is publishing the transcribed NSO Group Depositions.

This is an unprecedented view for investigators into NSO's business, exploit development, operations & financials.

Nothing like this has ever been made public about any spyware company.

about.fb.com/wp-content/upl…
about.fb.com/wp-content/upl…
about.fb.com/wp-content/upl…
about.fb.com/wp-content/upl…Image
Image
Image
Image
@WhatsApp @citizenlab 15/ WHOA: @whatsapp states intention to donate to support digital rights groups working to support targets of spyware attacks.

about.fb.com/news/2025/05/w…Image

• • •

Missing some Tweet in this thread? You can try to force a refresh
 

Keep Current with John Scott-Railton

John Scott-Railton Profile picture

Stay in touch and get notified when new unrolls are available from this author!

Read all threads

This Thread may be Removed Anytime!

PDF

Twitter may remove this content at anytime! Save it as PDF for later use!

Try unrolling a thread yourself!

how to unroll video
  1. Follow @ThreadReaderApp to mention us!

  2. From a Twitter thread mention us with a keyword "unroll"
@threadreaderapp unroll

Practice here first or read more on our help page!

More from @jsrailton

May 1
Friends don't let friends get their eyeballs scanned to buy a coffee.

Sam Altman's Orwellian "Tools for Humanity" says this dystopia machine could help distinguish between #AI agents & humans... or verify at Point of Sale..or..?

Looks to me like a big biometric data grab 1/ Image
2/ Surely they didn't just start with the idea of invasively harvesting eyeball scans...and then look around for potential justifications.

And then add in some AI hype.

Right? Image
3/ Throwback to Tools for Humanity's previous (but non-portable, guys!) eye-scanning thing: WorldCoin.

Remember that? A global biometric data grab rife with documented exploitation in Africa & Latin America.

Still not clear what real value it delivered to the ppl who gave up their biometrics.Image
Image
Image
Read 4 tweets
Apr 28
Fear is dictatorship glue.

You can't imprison everyone with a dissenting thought.

Or inconvenient factual observation.

But fear teaches self censorship. It's a scalable system of control.

The autocrat's challenge is to keep the fear going. 1/ A detention center’s interrogation rooms — Untersuchungshaftanstalt Hohenschönhausen, Vernehmungstrakt (2004) (© Daniel & Geo Fuchs) Image source: https://hyperallergic.com/151019/mundane-horror-in-abandoned-stasi-spaces/
2/ In the 20th century, keeping fear alive required massive human investment.

Informants... archives...exemplary punishments... information control.

Looked like a linear scale.

A post-cold war school of thought said: once everyone is connected, these systems won't work. Hohenschönhausen investigation prison: monitoring room Daniel & Geo Fuchs  Via https://www.ibtimes.co.uk/stasi-secret-rooms-communist-east-germanys-eerie-interrogation-cells-haunted-prisons-1467734
BStU Zentralarchiv Berlin archives (2004) (© Daniel & Geo Fuchs)  URL: https://hyperallergic.com/151019/mundane-horror-in-abandoned-stasi-spaces/
"There are several images of staged Stasi arrests carried out for training purposes. Dissidents, in some case already serving long prison terms, were sometimes made to re-enact their own arrest for the camera.  " Simon Menner BSTU Source: https://www.bbc.com/news/world-europe-23986385
3/ But tech isn't, by nature, a dictatorship antidote.

It can be an expedient.

Just ask China.

In 20 years the CCP empirically developed technologies & private sector partnerships for scaling fear and self censorship to >1.4 billion ppl.

Log scale. A display shows surveillance technology capable of analyzing body motion for specific actions like fighting, theft or fall during Security China 2018 in Beijing, China, Tuesday, Oct. 23, 2018.  Photo/Ng Han Guan
Surveillance cameras are mounted on a post at Tiananmen Square as snow falls in Beijing, China, on Thursday, Feb. 14, 2019. Qilai Shen  https://www.cnbc.com/2021/01/15/huawei-ai-firms-filed-to-patent-tech-that-could-identify-uighurs-report-says.html
Read 6 tweets
Mar 19
🚨NEW REPORT: first forensic confirmation of #Paragon mercenary spyware infections in #Italy...

Known targets: Activists & journalists.

We also found deployments around the world. Including ...Canada?

And a lot more... Thread on our @citizenlab investigation 1/Image
Image
2/ So #Paragon makes zero-click spyware marketed as better than NSO's Pegasus...

Harder to find...

...And more ethical too!

This caught our attention @citizenlab & we were skeptical.

By @iblametom forbes.com/sites/thomasbr…Image
Image
Image
3/ We got a tip about a single bit of #Paragon infrastructure & my brilliant colleague @billmarczak developed a technique to fingerprint some of the mercenary spyware infrastructure (both victim-facing & customer side) globally.

So much for invisibility.

What we found startled us.

citizenlab.ca/2025/03/a-firs…Image
Image
Image
Image
Read 18 tweets
Feb 6
BREAKING: #Paragon reportedly terminates spyware contract with #Italy.

Right on heels of reported targeting of journalist & activists in Italy.

BIG DEAL: puts Italian government in the hot seat, since they denied knowing about it only hours ago.👇
Image
2/ Read this slowly.

The implication is clear: the Italian government was a #Paragon customer & had their contract terminated...

Even as @GiorgiaMeloni's office was issuing denials.

Likely to make the scandal worse.

Exceptional reporting from The Guardian
theguardian.com/technology/202…Image
Image
3/ Big picture:

#Paragon's carefully constructed image of being a clean mercenary spyware company that wasn't susceptible to abuses has been replaced by a more familiar tale of...

Abuses...

And #Italy is now saddled with an unfolding crisis around spyware abuse.
Read 7 tweets
Feb 1
NEW: @WhatsApp says Israeli mercenary spyware company #Paragon targeted scores of users around world.

The infection happened with no interaction. No link to click or attachment to open.

This is called a "zero-click" attack.

WA says targets included journalists & members of civil society.

They dismantled the attack vector & notified users.

Good.

We at @citizenlab shared some info instrumental to their investigation of the vector.

This is a BIG deal. Here's why 1/Image
Image
Image
Image
2/ For a few years the only source of information about #Paragon... has been Paragon.

They marketed themselves as the anti-NSO.

(NSO makes the notorious #Pegasus spyware)

It's easier to frame yourself as virtuous in the spyware game if nobody can look over your shoulder.

By @iblametom
forbes.com/sites/thomasbr…

By @RonanFarrow
newyorker.com/magazine/2022/…Image
Image
Image
Image
3/ Late last year, partly on the strength of their promised virtue #Paragon seemed closer than ever to landing the industrys juiciest of prices.

Market access into the USA.

This is the goal of a lot of spyware companies & their investors...

At the time, there simply were no pesky reports on Paragon that showed anything might be other than rosy.

Story @criticalvas
wired.com/story/ice-para…Image
Read 12 tweets
Jan 23
NEW: US seeks extradition of Israeli private spy over sprawling hacking against 🇺🇸American nonprofits.

Amit Forlit's alleged customer? US lobbying firm @DCIGroup... representing @exxonmobil

Extradition filings in UK give fresh peek into this wild case 1/Image
Image
Image
Image
2/ The case was triggered back in 2018, when US-based nonprofits targeted by hackers requested that @citizenlab notify the authorities.

In 2020, we went public with the investigation, alongside @jc_stubbs @razhael & @Bing_Chris 👇

3/ Fast forward to today's efforts to extradite Amit Forlit, who was arrested at Heathrow last year.

He's actually the second Israeli private investigator charged in this massive hacking scheme targeting Americans.

The first, Aviram Azari, was arrested in 2019, convicted & is serving out his sentence.

justice.gov/usao-sdny/pr/i…Image
Image
Image
Read 7 tweets

Did Thread Reader help you today?

Support us! We are indie developers!


This site is made by just two indie developers on a laptop doing marketing, support and development! Read more about the story.

Become a Premium Member ($3/month or $30/year) and get exclusive features!

Become Premium

Don't want to be a Premium member but still want to support us?

Make a small donation by buying us coffee ($5) or help with server cost ($10)

Donate via Paypal

Or Donate anonymously using crypto!

Ethereum

0xfe58350B80634f60Fa6Dc149a72b4DFbc17D341E copy

Bitcoin

3ATGMxNzCUFzxpMCHL5sWSt4DVtS8UqXpi copy

Thank you for your support!

Follow Us!

:(