Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Compliance

NSO Ordered to Stop Hacking WhatsApp, but Damages Cut to $4 Million

The judge ruled that punitive damages of $167 million awarded by a jury were excessive.

WhatsApp security

The latest ruling in the lawsuit filed by WhatsApp against the NSO Group bars the spyware maker from targeting the communication app’s users, but also significantly reduces the punitive damages awarded earlier this year by a jury.

WhatsApp filed a lawsuit against NSO in 2019, after it came to light that a zero-day vulnerability had been exploited to deliver spyware to approximately 1,400 WhatsApp users.

A judge ruled in December 2024 that NSO Group is liable for the hacking of WhatsApp users, and in May 2025 a jury ordered the spyware maker to pay more than $444,000 in compensatory damages and $167 million in punitive damages. 

NSO appealed the jury’s decision, arguing that WhatsApp should not be awarded more than $1.77 million. In addition, WhatsApp has sought an injunction to prevent NSO from targeting its users, which NSO argued would put its entire enterprise at risk and “force it out of business”.

In a ruling dated October 17, US District Court Judge Phyllis Hamilton granted a permanent injunction barring NSO from hacking WhatsApp.

“Essentially, part of what companies such as WhatsApp are ‘selling’ is informational privacy, and any unauthorized access is an interference with that sale,” the judge wrote in the ruling. “Defendants’ conduct serves to defeat one of the purposes of the service being offered by plaintiffs, which constitutes direct harm.”

Advertisement. Scroll to continue reading.

NSO has been ordered to stop reverse engineering WhatsApp and to no longer create new WhatsApp accounts. It must also delete and destroy WhatsApp source code it possesses. 

On the other hand, the ban is limited to WhatsApp and it does not apply to other Meta services such as Instagram and Facebook, as requested in the complaint against NSO. 

“Today’s ruling bans spyware maker NSO from ever targeting WhatsApp and our global users again,” WhatsApp stated following the ruling. “We applaud this decision that comes after six years of litigation to hold NSO accountable for targeting members of civil society.”

While Hamilton sided with WhatsApp on this matter, the judge ruled that the punitive damages awarded by the jury were excessive and reduced the amount from $167 million to just over $4 million, which is nine times the compensatory award, as dictated by rules that limit awards based on misconduct severity.

NSO’s spyware is advertised as a legitimate surveillance tool designed to help government organizations fight terrorism and other types of crime. However, it has often been used by authoritarian regimes to target opponents, including human rights activists and journalists.

The company has denied any wrongdoing, arguing that it is not responsible for how customers use its solutions.

NSO was recently acquired by a group of American investors led by Hollywood producer Robert Simonds in a deal reportedly valued at several tens of millions of dollars. The ownership of NSO has changed several times in recent years, between founders and various private equity firms. The latest acquisition transfers controlling ownership out of Israel. 

Related: Ex-NSO Group CEO’s Security Firm Dream Raises $100M at $1.1B Valuation

Related: Ex-WhatsApp Employee Sues Meta Over Vulnerabilities, Retaliation

Related: Apple Suddenly Drops NSO Group Spyware Lawsuit

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Today’s attackers are no longer breaking in — they’re logging in. Join this live webinar as we break down the modern identity attack chain and examine how recent breaches exploited weaknesses in authentication, identity verification, and access management processes.

Register

AI has accelerated both sides of the fight. Adversaries are weaponizing vulnerabilities faster, while defenders are racing to ship detections and configurations. Join this live webinar as we explore how to prove your controls actually hold against new threats, map your security maturity, and unite breach simulation with automated pentesting into a single, coordinated program.

Register

People on the Move

Stephen Garcia has been named Chief Information Security Officer at BreachRx.

Kasper Lindgaard has been appointed Vice President of Security Strategy at CoreView.

Chaim Mazal has been named Chief Information Security Officer at GitLab.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.