NSO GROUP
- Status
- ACTIVE — Commercial spyware vendor (Pegasus), founded 2010; US Entity List since Nov 2021; controlling stake acquired by US investors Oct 2025
- Hazard — Reach
- 86
- RCH / FND / ENT
- 9 / 6 / 7
- Conduct
- ADJUDICATED — US COURT FOUND WHATSAPP HACKING; PERMANENT INJUNCTION
OLYMPUS opened an institutional file, and filed it in the wing that operates the systems the rest of the drawer only watches. A firm has no Big Five and no Dark Triad, and the unit does not invent them; what a firm has is a product, a customer list, an export license, and a docket. NSO Group is catalogued here as the locksmith — the company that sells the master key and insists it only ever hands it to the government. The finding is the position: a private Israeli firm whose zero-click product silently opens any phone, whose customers are states, and whose license to sell is granted by a defense ministry. Not a hand on any single target. A key, and the question of who is standing at the door once it opens. The “breach reach” of a spyware vendor is real, but the numbers in the front matter are reach, offensive capability, and durability under fire — not malice. Unlike most files in this drawer, part of this record is ADJUDICATED: a US federal court found the hacking as fact.
Institutional Archetype
THE LOCKSMITH — The archetype is the maker of the master key who sells only to the authorities and disclaims what the authorities do with it. NSO does not run its own operations against its own targets; it licenses Pegasus to government clients, who select the numbers. The structural power is that the instrument is the same regardless of the hand: the zero-click exploit that reaches a cartel lieutenant’s phone reaches a journalist’s phone by the identical mechanism, and the vendor’s business model requires it to work on any phone before it can be sold as working on the phone the customer names. That is the hazard — not authorship of any single infection, but authorship of the capability inside which every infection is possible. The instrument is the exploit chain. The leverage is that a democracy and an autocracy buy the same key from the same shop.
Mandate & Origin
NSO Group Technologies was founded in 2010 in Herzliya, Israel, by Niv Carmi, Shalev Hulio, and Omri Lavie — the company name is an acronym of the three founders’ first names. Carmi is a former Mossad operative; Hulio and Lavie were childhood friends whose earlier venture, Communitake, built remote-smartphone-management technology that (by the founders’ account) drew intelligence-agency interest in a bypass for encrypted messaging. Its flagship product, Pegasus, is zero-click spyware that silently compromises a target phone and delivers the operator everything on it — messages, calls, email, microphone, camera. Under a 2007 Israeli law, cyber-intrusion products require an export license from the Defense Ministry’s Defense Export Controls Agency (DECA); NSO’s stated mandate, repeated in its public statements, is that it sells “only to legitimate law enforcement agencies” for counterterrorism and serious crime, under those licenses and with safeguards against misuse.
Funding & Backers
NSO’s ownership is itself a map of the private-surveillance market. Francisco Partners, a US private-equity firm, acquired majority control in 2014 for a reported $120 million; founders Hulio and Lavie bought the company back in 2019 via the London-based Novalpina Capital fund. In October 2025, NSO confirmed that a group of US investors led by Hollywood producer Robert Simonds acquired a controlling stake — the transaction that, on its face, moves ownership of the Pegasus maker to American hands even as the firm remains on the US government’s own trade-restriction list and states its operations stay under Israeli Ministry of Defense supervision. Who owns the locksmith is part of what the key is: a firm sanctioned by the US Commerce Department in 2021 passed into majority US ownership four years later, with the export controls and the litigation still live.
Institutional Voice & Intent
The voice is the lawful-intercept register — the responsible-vendor’s, not the operator’s. NSO speaks in the grammar of “legitimate law enforcement,” “warrants,” “terrorists and criminals,” and “safeguards”: a compliance vocabulary that frames the firm as a regulated defense exporter serving sovereign clients, with abuse the client’s fault and the client’s alone. The persuasion is in the licensing — a product cleared by a defense ministry reads as governed, even when the governance is a permit to sell.
Stated intent: Provide governments and their law-enforcement agencies with lawful-intercept capability to prevent and investigate terrorism and serious crime, under export license and with safeguards against misuse.
Observed intent: Be the market-leading vendor of turnkey phone compromise to state clients, with the license as the shield and the client named as the operator whenever a target turns out to be a journalist, a dissident, or a head of state.
Gap: The stated and observed intents diverge at the point the forensic record documents. NSO’s clients selected targets including — per the Pegasus Project, Citizen Lab, and Amnesty International — journalists, human-rights lawyers, and people in murdered Saudi journalist Jamal Khashoggi’s circle. Whether NSO knew or intended any specific abuse is not establishable from the outside and is precisely what NSO’s licensed-vendor posture is built to keep unanswerable. What the record does settle is narrower and harder: a US federal court found that NSO hacked roughly 1,400 WhatsApp users. The gap is structural — a business whose product only sells if it works on any phone, sold to states whose target lists the vendor says it does not control — and the court reached the one part of it a court can reach.
Position in the Apparatus
NSO is a node in the operations wing — the commercial-intrusion layer that sits alongside the data-fusion vendors (Palantir Technologies) and the state collection substrate (the NSA surveillance stack) this file also catalogues. Its lineage is the Israeli signals-intelligence-to-commercial pipeline documented across the corpus: alumni of military intelligence units carrying offensive capability into the private sector, and from there to any government with hard currency and an enemies list. Its customer cohort — documented buyers and deployers of Pegasus — spans states across the Gulf and beyond, each disclosed or exposed separately; only reading the forensic reports together shows the same key opening doors on four continents. The pipeline is lawful and the adjacency is recurrence, not a roster anyone curated. The locksmith’s product became the instrument of record for state phone compromise, and its market is every state that can pay.
Actions & Leadership Choices
Founding purpose, judged on evidence. NSO was founded in 2010 as a commercial offensive-cyber vendor, and the commercial status is the founding fact. Judged on its deeds, its purpose is to sell working phone-compromise to the states that will pay for it, with the export license as the governing fiction. That is not a benign-by-default purpose; a private firm whose product must function against any phone, sold to sovereign clients whose target selection the vendor disclaims, has a conflict built into the model. The deeds below are weighed against that conflict.
Consequential actions, especially where it cost something. The record is a sequence of documented exposures and one adjudication. The Pegasus Project (2021, Forbidden Stories consortium with Amnesty and Citizen Lab) documented a list of 50,000-plus phone numbers selected for potential targeting by NSO clients, including some 14 heads of state and hundreds of officials and journalists. Phones in Khashoggi’s circle were infected before his 2018 murder. Citizen Lab documented the FORCEDENTRY zero-click iMessage exploit and the WhatsApp vector (CVE-2019-3568) used to reach roughly 1,400 phones in a two-week window in 2019. In November 2021 the US Commerce Department added NSO to the Entity List, finding it supplied spyware used to target journalists, activists, and officials. In Meta Platforms Inc. v. NSO Group (N.D. Cal.), NSO was found liable in December 2024; a jury awarded $167.3 million in punitive plus $444,719 in compensatory damages in May 2025; and on October 17, 2025, Judge Phyllis Hamilton cut the punitive award to roughly $4 million (a 9-to-1 ratio) and issued a permanent injunction barring NSO from ever targeting WhatsApp again. NSO is appealing.
The self-inflicted exposure is its own exhibit: in 2018 a rogue NSO employee stole the Pegasus source code and tried to sell it on the dark web for $50 million before being arrested. The firm that sells the tool to surveil everyone could not surveil its own programmer.
Leadership choices. NSO’s leadership ledger is the ownership chain and the litigation posture: founders who sold to private equity and bought back in, a firm that fought the WhatsApp case through a jury verdict and an appeal rather than settle, and a 2025 transfer of control to US investors while the Entity List designation and the injunction stayed in force. The choice under cost — to litigate rather than concede, and to keep selling under the license rather than exit the market the way its Israeli-forensics neighbor Cellebrite periodically does — is the choice that defines it.
CONDUCT verdict: ADJUDICATED — a commercial spyware vendor whose product’s documented use against journalists, dissidents, and officials was catalogued by Citizen Lab and Amnesty, sanctioned by the US Commerce Department, and, on the one claim a court reached, found liable: a US federal jury and judge held that NSO hacked roughly 1,400 WhatsApp users and barred it from doing so again. The rest — client target selection, motive — the record does not settle, and the licensed-vendor posture is built so it never has to.
Reach Assessment
Institutional: Pegasus became the instrument of record for state phone compromise — reach measured in the client governments that bought it and the forensic reports that traced it, not in any single infection. Memetic: “Pegasus” became the generic name for commercial zero-click spyware, and the Pegasus Project made the phrase a shorthand for the private-surveillance-industry problem entire; owning the byword is upstream of every policy argument conducted in it. Civilizational: NSO does not build the AI systems this file otherwise tracks. It built the commercial capability that decides whether any given phone — a journalist’s, a diplomat’s, a head of state’s — is an open book, and it sold that capability to states as a product. The breach reach of a spyware vendor is wide because the key travels: a working exploit chain, once sold, opens doors long after anyone checks who was standing behind them.
Sources: NSO Group — Wikipedia; The rise and fall of NSO Group — Forbidden Stories; About the Pegasus Project — Forbidden Stories; FORCEDENTRY: NSO Group iMessage Zero-Click Exploit Captured in the Wild — Citizen Lab; HIDE AND SEEK: Tracking NSO Group’s Pegasus Spyware to Operations in 45 Countries — Citizen Lab; Commerce Adds NSO Group and Other Foreign Companies to the Entity List — US Commerce Department, Nov 2021; NSO Ordered to Stop Hacking WhatsApp, but Damages Cut to $4 Million — SecurityWeek; NSO Group Shrinks $167 Million Punitive Award in WhatsApp Case — Bloomberg Law; Spyware maker NSO Group confirms acquisition by US investors — TechCrunch, Oct 10 2025; Fired NSO employee stole and tried to sell Pegasus — Axios.
Get updates on the Evil Robots series
Newsletter essays on AI escape, deception, and the humans who built them.