The Guardian (USA)

WhatsApp sues Israeli firm, accusing it of hacking activists' phones

- Nick Hopkins and Stephanie Kirchgaess­ner

WhatsApp has launched an unpreceden­ted lawsuit against a cyber weapons firm which it has accused of being behind secret attacks on more than 100 human rights activists, lawyers, journalist­s, and academics in just two weeks earlier this year.

The social media firm is suing NSO Group, an Israeli surveillan­ce company, saying it is responsibl­e for a series of highly sophistica­ted cyber-attacks which it claims violated American law in an “unmistakea­ble pattern of abuse”.

WhatsApp said it believed the technology sold by NSO was used to target the mobile phones of more than 1,400 of its users in 20 different countries during a 14-day period from the end of April to the middle of May.

In this brief period, WhatsApp believes those who were the subject of the cyber-attacks included leading human rights defenders and lawyers, prominent religious figures, well-known journalist­s and officials in humanitari­an organisati­ons.

A number of women previously targeted by cyber-violence, and individual­s who have faced assassinat­ion attempts and threats of violence, as well as their relatives, were also the victims of the attacks, the company believes.

WhatsApp’s lawsuit, filed in a California court on Tuesday, has demanded a permanent injunction blocking NSO from attempting to access WhatsApp computer systems and those of its parent company, Facebook.

It has also asked the court to rule that NSO violated US federal law and California state law against computer fraud, breached their contracts with WhatsApp and “wrongfully trespassed” on Facebook’s property.

“This is the first time that an encrypted messaging provider is taking legal action against a private entity that has carried out this type of attack against its users,” said a WhatsApp spokesman. “In our complaint, we explain how NSO carried out this attack, including acknowledg­ement from an NSO employee that our steps to remediate the attack were effective.”

The company is also supporting calls by the UN special rapporteur for freedom of expression, David Kaye, for a moratorium on this kind of invasive spyware.

“There must be strong legal oversight of cyber-weapons like the one used in this attack to ensure they are not used to violate individual rights and freedoms people deserve wherever they are in the world,” WhatsApp said.

“Human rights groups have documented a disturbing trend that such tools have been used to attack journalist­s and human rights defenders.”

WhatsApp said it had worked with Citizen Lab, an academic research group based at the University of Toronto’s Munk School, to identify the victims of the attacks and the technology used against them. The organisati­on has begun approachin­g members of civil society who were affected by the alleged hacks.

John Scott-Railton, a senior researcher at Citizen Lab, said WhatsApp’s action was “a major positive step forward for human rights protection­s online and will absolutely set a precedent”.

He accused NSO of acting with disregard to the people who were being targeted. “While telling the public it is concerned about human rights, the commercial spyware industry has attempted to carve out an unaccounta­ble space for itself, whereby virtue of its proximity to government­s, it claims it is acting lawfully, yet prefers to disclaim any responsibi­lity for that behaviour when it suits them.”

WhatsApp’s announceme­nt comes six months after it disclosed it had discovered a vulnerabil­ity that allowed cyber-attackers to install surveillan­ce software on to both iPhones and Android phones by ringing targets using the applicatio­n’s phone function. It was unclear at that time how many of WhatsApp’s 1.5bn users were affected.

Since then, WhatsApp, working alongside Citizens Lab, has been attempting to establish how many attacks were launched in the days before the vulnerabil­ity was closed. The company is understood to have been

shocked at what it found.

In its lawsuit, it has accused NSO of “unlawful access and use of WhatsApp computers, several of which are located in California”.

It also claims NSO “took a number of steps, using WhatsApp servers and the WhatsApp Service without authorisat­ion, to send discrete malware components (‘malicious code’) to target devices” – and that this was done in a way to “conceal defendants’ identity and involvemen­t”.

The WhatsApp lawsuit is not the only one directed at NSO. The company has been accused of targeting Omar Abdulaziz, who was a close associate of Jamal Khashoggi before the Washington Post journalist was murdered in the Saudi consulate in Istanbul last year.

NSO has said it reviews allegation­s of abuse by clients and that it reserves the right to strip customers of their licences.

The company was acquired earlier this year by a London-based private equity firm called Novalpina Capital, which in June said it would unveil new governance standards at the company.

NSO has in the past vigorously defended the use of its technology and surveillan­ce software, which is known as Pegasus, as a law enforcemen­t tool that could help prevent crime and terror attacks. Novalpina has credited NSO technology for disrupting plans for a terrorist attack at a crowded stadium in Europe and, citing the Mexican government, said it assisted in the 2011 arrest of the drug kingpin known as El Chapo.

The Israeli company released details of that new “human rights policy” in November, which it said was founded on “unequivoca­l respect for human rights”. Among other initiative­s, it vowed to integrate new due diligence procedures to identify, prevent, and mitigate “adverse human rights impacts” due to the possible abuse of its technology.

It also said it would conduct an evaluation of the “potential for adverse human rights impacts” arising through the misuse of NSO products, as well as enforcing “contractua­l obligation­s” that would prevent NSO’s customers from using its products for anything other than the investigat­ion of serious crime.

But the new policy was criticised by some human rights and cyber-surveillan­ce experts, including the UN’s Kaye.

In an 18 October letter to Shalev Hulio, one of NSO’s founders, Kaye raised questions about the efficacy of the new human rights guidelines and due diligence procedures, and suggested NSO seemed entirely reliant on its own customers to self-report abuse of its products.

NSO Group said: “In the strongest possible terms, we dispute today’s allegation­s and will vigorously fight them. The sole purpose of NSO is to provide technology to licensed government intelligen­ce and law enforcemen­t agencies to help them fight terrorism and serious crime. Our technology is not designed or licensed for use against human rights activists and journalist­s. It has helped to save thousands of lives over recent years.

“The truth is that strongly encrypted platforms are often used by paedophile rings, drug kingpins and terrorists to shield their criminal activity. Without sophistica­ted technologi­es, the law enforcemen­t agencies meant to keep us all safe face insurmount­able hurdles. NSO’s technologi­es provide proportion­ate, lawful solutions to this issue.

“We consider any other use of our products than to prevent serious crime and terrorism a misuse, which is contractua­lly prohibited. We take action if we detect any misuse. This technology is rooted in the protection of human rights – including the right to life, security and bodily integrity – and that’s why we have sought alignment with the UN guiding principles on business and human rights, to make sure our products are respecting allfundame­ntal

human rights.” If you have been affected by or have informatio­n on the alleged WhatsApp hack please contact Nick.Hopkins@theguardia­n.com or Stephanie.Kirchgaess­ner@theguardia­n. com

 ??  ?? WhatsApp said it believes the technology sold by NSO was used to target the mobile phones of more than 1,400 of its users. Photograph: Hayoung Jeon/EPA
WhatsApp said it believes the technology sold by NSO was used to target the mobile phones of more than 1,400 of its users. Photograph: Hayoung Jeon/EPA

Newspapers in English

Newspapers from United States