In July 2021, a consortium of investigative outlets (the Pegasus Project) dropped the coordinates of the NSO Group’s customer base: a leaked list of 50,000 phone numbers selected for targeting by government clients of the Pegasus spyware — journalists, human-rights defenders, lawyers, opposition politicians, heads of state. Forensic confirmation followed on dozens of phones, and the technical shock was as big as the political one: the latest Pegasus exploits were zero-click — they infected iPhones and Androids without the target tapping, opening, or seeing anything. For a decade, “don’t click suspicious links” had been privacy advice; Pegasus made it folklore.
The Pegasus Project (18 media partners + Amnesty Tech + Citizen Lab, coordinated by Forbidden Stories; 18 July 2021) published a leaked target-selection list of ~50,000 numbers and forensics on hundreds of phones, showing NSO Group’s government clients targeted journalists (incl. Jamal Khashoggi’s circle), activists, lawyers, priests, doctors, opposition leaders, and presidents/macron-class figures. Technical findings: modern Pegasus deployed via zero-click network attacks — iMessage (FORCEDENTRY/KISMET), WhatsApp voice calls, invisible messages — requiring no user interaction, self-destructing traces, running with full OS privileges (kernel on Android, elevated counterparts on iOS), exfiltrating messages, calls, microphone, camera, location. NSO denied misuse (claiming the list wasn’t theirs, all clients vetted, attacks aimed at criminals/terrorists); the evidence — forensic confirmations incl. phones of Khashoggi’s wife/his colleague, and journalists explicitly out of bounds under NSO contract terms in multiple countries — contradicted that. Consequences through 2021-2026: Apple’s BlastDoor/lockdown hardening wave, Facebook’s lawsuit against NSO (WhatsApp exploit, 2019), the US Commerce Dept Entity List (Nov 2021), CIA/NSA-adjacent reporting on client lists, EU PEGA inquiry (2023), Poland/Hungary/Spain/Greece scandals (Catalangate), and the 2024-2026 era of commercial spyware regulation (US EO 2023/2024 restricting government purchase + allied coalition; EU proposals). Pegasus became the nuclear shorthand for the commercial spyware industry’s harms.
What happened
The collaboration worked from a leak of selection data — numbers chosen by (unnamed) NSO clients for possible targeting — obtained by Forbidden Stories/Amnesty and shared with global partners (Guardian, Washington Post, Le Monde, Süddeutsche, etc.). The list itself is “selected for interest”, not “infected”: NSO correctly insisted list-inclusion isn’t proof of infection. But forensic analysis (Amnesty’s MVT toolkit, released open-source) confirmed successful full Pegasus infections on dozens of examined phones of journalists/activists — including numbers around the Khashoggi murder (his wife Hanan Elatr’s and fiancée Hatice Cengiz’s devices targeted per later forensics), Western politicians, and sitting heads of state (France’s Macron among the list-notables).
The political detonation was immediate: India’s opposition stormed parliament (hundreds of Indian numbers listed); Mexico (previous epicentre), Hungary, Poland, Morocco, Azerbaijan, Rwanda, and the UAE faced domestic reckonings; Israel (export-licensing authority for NSO) launched reviews. NSO’s defenses — leak-list isn’t NSO’s, “we save lives”, client-vetting claims — crumbled under contract-language reporting (clients promised targets limited to crime/terror) and the sheer breadth (journalists explicitly out-of-bounds everywhere). The commercial reality — 40+ government clients, publicly-known contracts in the hundreds of millions — stood fully exposed.
The industrial aftermath compounded for years: Pegasus-derived legal actions (WhatsApp v NSO), the US Entity-Listing of NSO (and competitor Candiru), subsequent operator fails (Poland’s illegal use on election politicians; Greece’s Predator/Intellexa ecosystem scandals; Spain’s Catalan surveillance), EU PEGA committee findings (2023: systemic misuse across member states), US executive orders restricting government spyware procurement (2023 positive-list/2024 negative-list), and continued spyware commerce (FinFisher collapse/leak 2022, Intellexa-related sanctions 2024). Zero-click mercenary spyware is now a standing market with a watchdog architecture (Citizen Lab, Amnesty, universities) continuously documenting it.
How it worked
The delivery chains evolved click → network-silent over the 2016–2021 window:
2016-2018 era: spearphishing links, fake app stores,
credential-harvest portals (click needed)
2019: WhatsApp zero-click voice-call exploit (missed call
delivers buffer-overflow payload; logging only later)
2020-2021: iMessage zero-click (KISMET/FORCEDENTRY era)
- no message displayed to victim
- IMNotification+AppleMediaServices parsing chain exploits
- payload escapes BlastDoor-era sandbox (pre-BlastDoor)
- kernel/privilege escalation -> full implant
implant capabilities (Citizen Lab/Amnesty forensics):
- messages/calls/email exfil (incl. encrypted apps' plaintext
at endpoint)
- microphone + camera recording
- location tracking, file harvest, keychain access
- self-destruct, anti-forensics, updates on command
delivery economics: 0-day chains priced in the millions;
clients pay per-target success and subscription tiers
The architectural lesson: endpoint chat/parsing services process unauthenticated attacker input — a permanent 0-day surface. Apple’s response (BlastDoor sandboxing for iMessage, Lockdown Mode in 2022, rapid exploit-klaxon patching) and Google’s equivalent hardening (Play Protect scanning, Android hardening, Pixel exploit-bounty escalation) institutionalised “assume parsing attack” thinking. For targets — reporters, lawyers, dissidents — the operational lesson is device isolation: sensitive work never crosses the phone that receives unsolicited calls/messages, a discipline formalised in our identity-and-targeted-threat guidance.
Impact and numbers
| Metric | Value | Source |
|---|---|---|
| Publication date | 2021-07-18 (Pegasus Project) | consortium articles |
| Numbers in leaked selection list | ~50,000 | Forbidden Stories/Amnesty |
| Confirmed infections (forensic) | Dozens among examined phones; 100s examined | Amnesty/Citizen Lab |
| Client states implicated | Multiple (India, Mexico, Hungary, Poland, Morocco, Azerbaijan, Rwanda, UAE, Bahrain, Togo, Kazakhstan…) | project reporting |
| NSO claimed client count | ~36 agencies / 40+ states over time | NSO statements |
| US Entity List | 2021-11-03 (NSO + Candiru) | Commerce Dept |
| EU PEGA findings | 2023-03 (systemic misuse conclusions) | European Parliament |
Timeline
| Date | Event |
|---|---|
| 2016–2019 | Pegasus evolves click-phishing → WhatsApp zero-click (2019) |
| 2019-10 | Facebook/WhatsApp sue NSO over voice-call exploit |
| 2021-07-18 | Pegasus Project publishes 50k list + forensics |
| 2021-09 | Apple emergency-patches FORCEDENTRY (CVE-2021-30860); Citizen Lab credited |
| 2021-11 | US Commerce Entity Lists NSO Group and Candiru |
| 2022 | Apple sues NSO; Lockdown Mode shipped; Greece/Poland/Spain scandals expand scope |
| 2023–2026 | PEGA findings; US spyware EOs; Intellexa sanctions; market restructures |
Why it still matters in 2026
Pegasus is the hinge event that converted mercenary spyware from open-secret to governed-and-sanctioned market. Its 2026 relevance operates on three axes. Technically, zero-click chains remain the apex intrusion method — every subsequent spyware generation (Predator/Intellexa, Wings/Variston, domestically-developed state tools) inherits the iMessage/messaging-parsing attack economy Pegasus perfected, and defenders’ countermeasures (Lockdown Mode, BlastDoor-class sandboxing, extreme hardening modes) remain reactions to it. Politically, the Project’s methods — leaked targeting data + forensic verification — established the accountability template now routinely applied (2023–2026 identifications across EU/North America), sustained by an institutional watchdog ecosystem. Regulatory, the arc from Entity Listing through PEGA to procurement restrictions (US positive/negative lists, EU proposals) represents the first genuine attempt to govern the industry by demand-side law — imperfect, contested, but real. For every journalist, lawyer, activist, and executive, the operating assumption has permanently shifted: a phone receiving unsolicited communications is a phone that can be owned; treat sensitive work accordingly, as we detail in targeted-attack guidance.
Detection and hardening takeaways
- Use platform extreme-hardening modes when risk warrants. iOS Lockdown Mode and Android’s advanced-protection configurations materially raise zero-click cost; high-risk users (journalists, counsel, dissidents, executives in contested deals) should enable them on daily-driver devices.
- Separate sensitive communications from universal-reach devices. Keep a hardened device for high-value conversations that never installs consumer apps; unsolicited reach (iMessage/WhatsApp/SMS numbers) stays on the burner-side phone, defeating the delivery economics of pay-per-target spyware.
- Forensically check suspected targeting. Amnesty’s MVT (Mobile Verification Toolkit) remains open-source; Apple’s Lockdown-mode block alerts and iOS 16.6+ mercenary-spyware attack notifications notify probable victims — don’t dismiss them as false alarms.
- Enterprises: inventory and segment VIP devices. Board members, M&A-active executives, and general counsel travel into spyware-hosting jurisdictions; MDM-enrolled, app-allowlisted profiles with egress control reduce both delivery and exfil options.
- Track the watchdogs. Citizen Lab, Amnesty Tech, and university trackers publish capability and client updates continuously; their advisories are the earliest actionable signal for which platforms and regions carry elevated risk.
FAQ
Does appearing on the leaked list mean a phone was infected?
No. The 50,000 numbers were those selected for interest by NSO clients — a targeting wishlist. Forensics confirmed actual infections on a subset of examined phones. NSO leaned on this distinction (“the list is not ours”), but the overlap between selections and subsequently-verified infections (plus contract terms) established the targeting pattern beyond reasonable dispute.
What did NSO Group actually admit?
Virtually nothing voluntary. The company asserted client-vetting, crime/terror-only contractual limits, and life-saving utility, while denying the leaked list reflected its systems. It has never publicly acknowledged specific unlawful targets; the evidentiary record (contracts, forensic confirmations, client-country scandals) contradicted its characterisations extensively.
Is Pegasus still operating in 2026?
The company restructured (ownership/branding changes post-sanctions) and its market shrank in Western jurisdictions — but the capability class thrives globally: successor vendors (Intellexa/network, Variston, domestic agencies’ in-house tools) continue winning tenders and being discovered on phones. Zero-click mercenary spyware is a permanent industry in 2026; the defence is layered hardening plus an assumption breach-grade discipline for high-risk personas.
