Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Tracking & Law Enforcement

NSO Turns to US Supreme Court for Immunity in WhatsApp Suit

The Israeli spyware maker NSO Group is turning to the U.S. Supreme Court as it seeks to head off a high-profile lawsuit filed by the WhatsApp messaging service.

The Israeli spyware maker NSO Group is turning to the U.S. Supreme Court as it seeks to head off a high-profile lawsuit filed by the WhatsApp messaging service.

In a filing to the Supreme Court, NSO said it should be recognized as a foreign government agent and therefore be entitled to immunity under U.S. law limiting lawsuits against foreign countries. The request appeals a pair of earlier federal court rulings that rejected similar arguments by the Israeli company.

WhatsApp parent Facebook, now called Meta Platforms Inc., sued NSO in 2019 for allegedly targeting some 1,400 users of its encrypted messaging service with highly sophisticated spyware. It is trying to block NSO from Facebook platforms and servers and seeks unspecified damages.

Granting sovereign immunity to NSO would greatly hinder WhatsApp’s case. It also could provide protection from a potentially risky discovery process that could reveal its customers and technological secrets. NSO is seeking to have the entire case dismissed.

In its petition, NSO said that lower courts have given mixed opinions on sovereign immunity over the years and that it was crucial for the Supreme Court to rule on an issue that has great national security implications for governments around the world.

“Many nations, including the United States, rely on private contractors to conduct or support core governmental activities,” it wrote in the April 6 filing. “If such contractors can never seek immunity … then the United States and other countries may soon find their military and intelligence operations disrupted by lawsuits against their agents.”

NSO’s flagship product, Pegasus, allows operators to covertly infiltrate a target’s mobile phone, gaining access to messages and contacts, the camera and microphone and location history. It says that it sells the product only to government law enforcement agencies to catch criminals and terrorists and that all sales are approved by Israel’s Defense Ministry. It does not identify its clients.

But critics say a number of clients, including Saudi Arabia, the United Arab Emirates, Jordan and Poland, have abused the system to snoop on critics and stifle dissent. WhatsApp says at least 100 of the users connected to its lawsuit were journalists, rights activists and civil society members.

Advertisement. Scroll to continue reading.

[ Read: Google: Pegasus Zero-Click ‘Most Technically Sophisticated Exploit Ever Seen’ ]

NSO says it has no control over how its clients use the product and no access to the data they collect, though it claims it has safeguards in place to prevent abuses. Critics say the safeguards are insufficient.

“NSO’s spyware invades the rights of citizens, journalists, and human rights activists around the globe and their attacks must be stopped,” WhatsApp said in a statement.

“Two United States courts have already rejected NSO’s contrived bid for immunity and we believe there is no reason for the Supreme Court to hear their last-ditch attempt to avoid accountability,” it said, adding that multiple human rights groups and tech companies have said granting immunity to spyware companies “would be dangerous for the world.”

The WhatsApp case is among a series of legal battles plaguing NSO. Apple last year filed a lawsuit that it says aims to prevent NSO from breaking into products. It claimed Pegasus had affected a small number of iPhone users worldwide, calling NSO’s employees “amoral 21st century mercenaries.”

NSO last year also was blacklisted by the U.S. Commerce Department, limiting its access to U.S. technology. U.S. officials said the company’s products were complicit in “transnational repression.”

NSO appears to face a formidable challenge. For starters, the Supreme Court agrees to consider just 1% or so of the requests put before it.

It could be months before the court decides whether to review the case. But even if it does, NSO would have to convince the court that it is a state agent and entitled to immunity.

Eugene Kontorovich, an Israeli-American professor at the George Mason University Scalia Law School and director of its Center for the Middle East and International Law, said it was a “very interesting” and “very serious” case. But he said he was skeptical NSO would prevail.

“They’re a software company. They create a product that’s been licensed to foreign governments and which governments can use,” he said. “An agent usually is something of a much higher standard.”

RelatedIsrael Spyware Firm NSO Operates in Shadowy Cyber World

RelatedJournalists’ Phones Hacked via iMessage Zero-Day Exploit

Related: Spyware by Israel’s NSO Used Against Journalist: Amnesty

Related: Israel Court Rejects Amnesty Petition Against Spyware Firm NSO

 

Related: NSO Group: Israeli Firm Accused of Cyberespionage

Written By

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join the session as we discuss the challenges and best practices for cybersecurity leaders managing cloud identities.

Register

SecurityWeek’s Ransomware Resilience and Recovery Summit helps businesses to plan, prepare, and recover from a ransomware incident.

Register

Expert Insights

Related Content

Cybercrime

Daniel Kelley was just 18 years old when he was arrested and charged on thirty counts – most infamously for the 2015 hack of...

Cybercrime

No one combatting cybercrime knows everything, but everyone in the battle has some intelligence to contribute to the larger knowledge base.

Cybercrime

The FBI dismantled the network of the prolific Hive ransomware gang and seized infrastructure in Los Angeles that was used for the operation.

Ransomware

The Hive ransomware website has been seized as part of an operation that involved law enforcement in 10 countries.

Privacy

Employees of Chinese tech giant ByteDance improperly accessed data from social media platform TikTok to track journalists in a bid to identify the source...

CISO Strategy

The SEC filed charges against SolarWinds and its CISO over misleading investors about its cybersecurity practices and known risks.

Cybercrime

A global cyber espionage campaign has resulted in the networks of many organizations around the world becoming compromised after the attackers managed to breach...

Ransomware

US government reminds the public that a reward of up to $10 million is offered for information on cybercriminals, including members of the Hive...