IT Pro is supported by its audience. When you purchase through links on our site, we may earn an affiliate commission. Learn more

Amnesty International blames ‘hostile government’ after Israeli-made spyware targets staff

The organisation was targeted by a ‘sophisticated campaign’ that has seen 175 attacks around the world since 2016

Amnesty International has disclosed how its staff were targeted in a spyware attack launched by what it believes to be "a government hostile to its work".

Alarms sounded in June after an Amnesty researcher received a suspicious WhatsApp message with details of an alleged protest outside the Saudi embassy in Washington DC, along with a link to a website.

An investigation by the charity's technology team revealed clicking this would have installed a surveillance tool called "Pegasus", developed by Israeli-based company NSO Group. The software enables an "extraordinarily invasive form of surveillance" and allows a malicious actor to intercept phone calls, and messages received on the handset, the charity claims.

"NSO Group is known to only sell its spyware to governments. We therefore believe that this was a deliberate attempt to infiltrate Amnesty International by a government hostile to our human rights work," said Amnesty International's head of technology and human rights Joshua Franco.

"This chilling attack on Amnesty International highlights the grave risk posed to activists around the world by this kind of surveillance technology."

Researchers from the University of Toronto's Citizen Lab, which investigates digital espionage among other subjects, corroborated Amnesty's assessment, suggesting the SMS messages Amnesty received contain domain names pointing to websites that appear to be part of NSO Group's Pegasus infrastructure.

Citizen Lab's researchers found the domains social-life.info and akhbar-arabia.com, which appeared on the WhatsApp messages, were consistent with the Pegasus infrastructure they had been tracking since 2016.

The organisation suggest the contents of the WhatsApp message were connected with the organisation's campaigning that week for the release of six women's rights activists being detained in Saudi Arabia. The organisation learned a Saudi Arabian rights activist received a similar message shortly afterwards.

"Can you please cover [the protest] for your brothers detained in Saudi Arabia in front of the Saudi embassy in Washington," the message read. "My brother was detained in Ramadan and I am on a scholarship here so please do not link me to this. [LINK]. Cover the protest now it will start in less than an hour. We need your support please."

Citizen Lab has identified 175 reported such instances of surveillance with ties to NSO in its experience, with up to 150 incidents in Panama alone, as well as reports from the United Arab Emirates, Mexico and Saudi Arabia.

The institution's researchers identified the links as matching websites appearing as part of NSO's new infrastructure that retains a Saudi-focus. They concluded the messages appear to represent attempts to infect the Amnesty researcher and the Saudi activist based abroad with NSO Group's Pegasus spyware.

"NSO Group develops cyber technology to allow government agencies to identify and disrupt terrorist and criminal plots," the Israeli-based company said.

"Our product is intended to be used exclusively for the investigation and prevention of crime and terrorism. Any use of our technology that is counter to that purpose is a violation of our policies, legal contracts, and the values that we stand for as a company.

"If an allegation arises concerning a violation of our contract or inappropriate use of our technology, as Amnesty has offered, we investigate the issue and take appropriate action based on those findings. We welcome any specific information that can assist us in further investigating of the matter."

Featured Resources

Accelerating AI modernisation with data infrastructure

Generate business value from your AI initiatives

Free Download

Recommendations for managing AI risks

Integrate your external AI tool findings into your broader security programs

Free Download

Modernise your legacy databases in the cloud

An introduction to cloud databases

Free Download

Powering through to innovation

IT agility drive digital transformation

Free Download

Recommended

What is cyber warfare?
Security

What is cyber warfare?

20 May 2022
Bahrain targets activists with NSO's Pegasus spyware
spyware

Bahrain targets activists with NSO's Pegasus spyware

24 Aug 2021

Most Popular

Former Uber security chief to face fraud charges over hack coverup
data breaches

Former Uber security chief to face fraud charges over hack coverup

29 Jun 2022
Macmillan Publishers hit by apparent cyber attack as systems are forced offline
Security

Macmillan Publishers hit by apparent cyber attack as systems are forced offline

30 Jun 2022
FCC commissioner urges Apple and Google to remove TikTok from app stores
data protection

FCC commissioner urges Apple and Google to remove TikTok from app stores

29 Jun 2022