Pegasus NSO clients spying disclosures prompt political rows across world
Revelations about the use of spying tools sold to governments by NSO Group sparked furious political rows across the world on Monday after evidence emerged to suggest the surveillance firmâs clients may have sought to target their political opponents.
Amid growing concern over the apparent abuse of NSOâs powerful phone-hacking spyware, Pegasus, Amazon confirmed it had already cut some of its ties to the Israeli surveillance company. The stock price of Apple dipped amid worries about the privacy and security of its handsets.
NSO claims its surveillance tools are sold to carefully vetted government clients who are only permitted to use them for legitimate investigations into crime and terrorism. However, the Pegasus project, a consortium of media including the Guardian, revealed that:
Quick GuideWhat is in the Pegasus project data? ShowWhat is in the data leak?
The data leak is a list of more than 50,000 phone numbers that, since 2016, are believed to have been selected as those of people of interest by government clients of NSO Group, which sells surveillance software. The data also contains the time and date that numbers were selected, or entered on to a system. Forbidden Stories, a Paris-based nonprofit journalism organisation, and Amnesty International initially had access to the list and shared access with 16 media organisations including the Guardian. More than 80 journalists have worked together over several months as part of the Pegasus project. Amnestyâs Security Lab, a technical partner on the project, did the forensic analyses.
What does the leak indicate?
The consortium believes the data indicates the potential targets NSOâs government clients identified in advance of possible surveillance. While the data is an indication of intent, the presence of a number in the data does not reveal whether there was an attempt to infect the phone with spyware such as Pegasus, the companyâs signature surveillance tool, or whether any attempt succeeded. The presence in the data of a very small number of landlines and US numbers, which NSO says are âtechnically impossibleâ to access with its tools, reveals some targets were selected by NSO clients even though they could not be infected with Pegasus. However, forensic examinations of a small sample of mobile phones with numbers on the list found tight correlations between the time and date of a number in the data and the start of Pegasus activity â" in some cases as little as a few seconds.
What did forensic analysis reveal?
Amnesty examined 67 smartphones where attacks were suspected. Of those, 23 were successfully infected and 14 showed signs of attempted penetration. For the remaining 30, the tests were inconclusive, in several cases because the handsets had been replaced. Fifteen of the phones were Android devices, none of which showed evidence of successful infection. However, unlike iPhones, phones that use Android do not log the kinds of information required for Amnestyâs detective work. Three Android phones showed signs of targeting, such as Pegasus-linked SMS messages.
Amnesty shared âbackup copiesâ of four iPhones with Citizen Lab, a research group at the University of Toronto that specialises in studying Pegasus, which confirmed that they showed signs of Pegasus infection. Citizen Lab also conducted a peer review of Amnestyâs forensic methods, and found them to be sound.
Which NSO clients were selecting numbers?
While the data is organised into clusters, indicative of individual NSO clients, it does not say which NSO client was responsible for selecting any given number. NSO claims to sell its tools to 60 clients in 40 countries, but refuses to identify them. By closely examining the pattern of targeting by individual clients in the leaked data, media partners were able to identify 10 governments believed to be responsible for selecting the targets: Azerbaijan, Bahrain, Kazakhstan, Mexico, Morocco, Rwanda, Saudi Arabia, Hungary, India, and the United Arab Emirates. Citizen Lab has also found evidence of all 10 being clients of NSO.
What does NSO Group say?
You can read NSO Groupâs full statement here. The company has always said it does not have access to the data of its customersâ targets. Through its lawyers, NSO said the consortium had made âincorrect assumptionsâ about which clients use the companyâs technology. It said the 50,000 number was âexaggeratedâ and the list could not be a list of numbers âtargeted by governments using Pegasusâ. The lawyers said NSO had reason to believe the list accessed by the consortium âis not a list of numbers targeted by governments using Pegasus, but instead, may be part of a larger list of numbers that might have been used by NSO Group customers for other purposesâ. After further questions, the lawyers said the consortium was basing its findings âon misleading interpretation of leaked data from accessible and overt basic information, such as HLR Lookup services, which have no bearing on the list of the customers' targets of Pegasus or any other NSO products ... we still do not see any correlation of these lists to anything related to use of NSO Group technologiesâ.
What is HLR lookup data?
The term HLR, or home location register, refers to a database that is essential to operating mobile phone networks. Such registers keep records on the networks of phone users and their general locations, along with other identifying information that is used routinely in routing calls and texts. Telecoms and surveillance experts say HLR data can sometimes be used in the early phase of a surveillance attempt, when identifying whether it is possible to connect to a phone. The consortium understands NSO clients have the capability through an interface on the Pegasus system to conduct HLR lookup inquiries. It is unclear whether Pegasus operators are required to conduct HRL lookup inquiries via its interface to use its software; an NSO source stressed its clients may have different reasons â" unrelated to Pegasus â" for conducting HLR lookups via an NSO system.
At least 50 people close to Mexicoâs president, Andrés Manuel López Obrador â" such as his wife, children, aides and doctor â" were included in the list of possible targets when he was an opposition politician.
Rahul Gandhi, the most prominent political rival of the Indian prime minister, Narendra Modi, was twice selected as a potential target in leaked phone number data.
Carine Kanimba, the American daughter of Paul Rusesabagina, the imprisoned Rwandan activist who inspired the film Hotel Rwanda, has been the victim of multiple attacks using NSO spyware, according to a forensic analysis of her mobile phone, although Rwanda denies it has the NSO technology.
The whistleblower Edward Snowden said he feared Pegasus was potentially so powerful that it and spyware like it should be banned from international sale. âIf they find a way to hack one iPhone, theyâve found a way to hack all of them,â Snowden said, arguing spyware should be treated in a similar way to nuclear weapons where trade in the technology is heavily restricted.
04:55Appleâs stock price fell 2.4% by lunchtime amid concerns that NSOâs Pegasus software can infiltrate and take over the latest versions of iPhones without a single click from their owner. The spyware software, which can also infect Android devices, can secretly extract and monitor the contents of a device, potentially turning on its microphone for surveillance purposes.
Apple insists it leads the industry in security innovation and that iPhones are âthe safest, most secure consumer mobile device on the marketâ.
Amazon said it had stopped providing network services for NSO once it had learned of potential abuses of its technology, confirming it âacted quickly to shut down the relevant infrastructure and accountsâ.
Q&AWhat is the Pegasus project?ShowThe Pegasus project is a collaborative journalistic investigation into the NSO Group and its clients. The company sells surveillance technology to governments worldwide. Its flagship product is Pegasus, spying software â" or spyware â" that targets iPhones and Android devices. Once a phone is infected, a Pegasus operator can secretly extract chats, photos, emails and location data, or activate microphones and cameras without a user knowing.
Forbidden Stories, a Paris-based nonprofit journalism organisation, and Amnesty International had access to a leak of more than 50,000 phone numbers selected as targets by clients of NSO since 2016. Access to the data was then shared with the Guardian and 16 other news organisations, including the Washington Post, Le Monde, Die Zeit and Süddeutsche Zeitung. More than 80 journalists have worked collaboratively over several months on the investigation, which was coordinated by Forbidden Stories.
Meanwhile, the revelations about possible political espionage prompted a backlash in numerous countries.
The former Mexican president Felipe Calderón said he was subject to âan unjustifiable violationâ of his rights when he learned he may have been selected for potential targeting, not long after his wife, Margarita Zavala, announced a run for the presidency with the rightwing National Action party in 2015. Zavala and members of her campaign team were also selected for potential targeting, according to the leaked data.
In Hungary, where Viktor Orbánâs government stands accused of using NSOâs hacking software against journalists, opposition MPs said they would convene an extraordinary meeting of parliamentâs national security committee to discuss the allegations.
âIf any part of this is true, even half of it, itâs one of the deepest national security scandals I have seen,â said the opposition MP Péter Ungár, who sits on the committee.
In response, Hungaryâs deputy prime minister, Katalin Novák, said she âwould not like to comment on press rumoursâ, while the foreign minister, Péter Szijjártó, said Hungarian foreign intelligence did not use Pegasus, and he was ânot awareâ as to whether domestic agencies used it.
European leaders also voiced anxiety about the deployment of NSO in Europe, with one calling for MEPs to hold their own inquiry. âNo more âdeeply concernedâ... the EU has a dictatorship growing inside of it,â wrote the MEP, former Belgian prime minister and longtime Orbán critic, Guy Verhofstadt, on Twitter, in response to the Pegasus project allegations. âWe need a full inquiry by the European parliament!â
âFreedom of the press is a core value of the European Union,â said the European Commission chief, Ursula von der Leyen, on Monday while on a visit to Prague. She said if the allegations were true, âit is completely unacceptableâ.
In India, the opposition Congress party accused Narendra Modiâs government of being the âdeployer and executorâ of a âspying racketâ.
Gandhi said: âIf your information is correct, the scale and nature of surveillance you describe goes beyond an attack on the privacy of individuals. It is an attack on the democratic foundations of our country. It must be thoroughly investigated and those responsible be identified and punished.â
The Indian government denied any wrongdoing. The IT minister, Ashwini Vaishnaw, denied the âover-the-topâ media reports, which he described as âan attempt to malign Indian democracy and its well-established institutionsâ. But a few hours later it emerged that Vaishnaw was also among those whose numbers had been selected as a potential target, back in 2017, before he was an elected MP.
NSO Group has always said it does not have access to the data of its customersâ targets. In statements issued through its lawyers, NSO said that the Pegasus project reporting consortium had made âincorrect assumptionsâ about which clients used the companyâs technology. It said the leaked data could not be a list of numbers âtargeted by governments using Pegasusâ.
In his first public comments since media the disclosures began, Shalev Hulio, the founder and chief executive of NSO, said he continued to dispute that the leaked data âhas any relevance to NSOâ, but added that he was âvery concernedâ about the reports and promised to investigate them all. âWe understand that in some circumstances our customers might misuse the system,â he said.
0 Response to "Pegasus NSO clients spying disclosures prompt political rows across world"
Post a Comment