Monday, May 12, 2025
HomeCyber Security NewsNSO Group Ordered to Pay $168 Million to WhatsApp in US Spyware...

NSO Group Ordered to Pay $168 Million to WhatsApp in US Spyware Verdict

Published on

SIEM as a Service

Follow Us on Google News

A federal jury in California has ordered Israeli spyware maker NSO Group to pay approximately $168 million in damages to WhatsApp.

The verdict, delivered on Tuesday, represents a pivotal victory in the ongoing global battle against commercial cyberespionage and sets a new precedent for the accountability of spyware vendors.

The ruling concludes a six-year legal saga between Meta Platforms, the parent company of WhatsApp, and NSO Group, which had used its Pegasus spyware to compromise devices of the messaging app’s users worldwide.

- Advertisement - Google News

At the heart of the dispute were revelations that Pegasus exploited a ‘zero-click‘ vulnerability, enabling the compromise of phones without any action required by the user.

This gave attackers unprecedented access to messages, emails, calls, and even cameras and microphones-putting the privacy of about 1,400 individuals, including journalists, human rights defenders, and government officials across 20 countries, at grave risk.

WhatsApp first filed suit in 2019 after detecting the hacks. The jury awarded $444,719 in compensatory damages to cover WhatsApp’s costs in patching the exploited flaws and a further $167.3 million in punitive damages, designed to deter similar acts of unlawful surveillance in the future.

This landmark decision follows an earlier December ruling by Judge Phyllis Hamilton, who declared that NSO Group had violated anti-hacking statutes and breached WhatsApp’s terms of service.

Meta quickly hailed the jury’s decision as a “significant advancement for privacy and security,” emphasizing it as the first major judicial triumph over the use of unlawful spyware.

WhatsApp’s head, Will Cathcart, described the outcome as a “critical deterrent to the spyware industry against their unlawful activities directed at American companies and our global users.”

The case also served to shine a rare spotlight on the commercial spyware industry. Testimony during the trial revealed that NSO charged its government clients millions to hack target devices and continued updating Pegasus-even after WhatsApp patched vulnerabilities and launched its lawsuit.

NSO Group, meanwhile, has maintained that its technology is intended to combat crime and terrorism, and has stated that it plans to appeal the verdict.

The company argues that the jury was not permitted to consider evidence showing alleged legitimate use of Pegasus by government agencies.

Legal experts and human rights advocates say the verdict is a watershed moment, setting a crucial precedent for how courts might hold spyware vendors accountable for privacy abuses.

Meta has announced it will donate any collected damages to organizations working to defend against spyware threats.

As the global spyware industry expands, this decision is expected to shape the debate on surveillance, privacy, and the obligations of technology companies for years to come.

Setting Up SOC Team? – Download Free Ultimate SIEM Pricing Guide (PDF) For Your SOC Team -> Free Download

Divya
Divya
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Latest articles

Metasploit Update Adds Erlang/OTP SSH Exploit and OPNSense Scanner

The open-source penetration testing toolkit Metasploit has unveiled a major update, introducing four new...

Google Researchers Use Mach IPC to Uncover Sandbox Escape Vulnerabilities

Google Project Zero researchers have uncovered new sandbox escape vulnerabilities in macOS using an...

Cybercriminals Hide Undetectable Ransomware Inside JPG Images

A chilling new ransomware attack method has emerged, with hackers exploiting innocuous JPEG image...

Hackers Exploit Legacy Protocols in Microsoft Entra ID to Bypass MFA and Conditional Access

A sophisticated and highly coordinated cyberattack campaign came to light, as tracked by Guardz...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

Metasploit Update Adds Erlang/OTP SSH Exploit and OPNSense Scanner

The open-source penetration testing toolkit Metasploit has unveiled a major update, introducing four new...

Google Researchers Use Mach IPC to Uncover Sandbox Escape Vulnerabilities

Google Project Zero researchers have uncovered new sandbox escape vulnerabilities in macOS using an...

Cybercriminals Hide Undetectable Ransomware Inside JPG Images

A chilling new ransomware attack method has emerged, with hackers exploiting innocuous JPEG image...