US Judges Question NSO Group’s Dismissal Bid in Pegasus Spyware Lawsuit by Salvadoran Journalists

Listen to this Post

In a closely watched legal battle over the use of Pegasus spyware, U.S. federal judges are casting doubt on NSO Group’s attempt to dismiss a lawsuit brought by Salvadoran journalists. The case, rooted in allegations that their iPhones were infected by the Israeli firm’s infamous spyware, has reignited debates over jurisdiction, cybersecurity, and the reach of international tech surveillance.

Introduction

Spyware is no longer just a tool of espionage—it’s a growing threat to journalists, activists, and even governments. NSO Group’s Pegasus spyware, known for its ability to covertly extract data from smartphones, has been under intense scrutiny for years. In this latest development, a group of Salvadoran journalists are taking legal action in U.S. courts, arguing that their devices were compromised using Apple infrastructure based in California. While a lower court previously dismissed the case on jurisdictional grounds, a panel of U.S. appellate judges seems less convinced that NSO Group should be let off the hook so easily.

This lawsuit—Dada et al v. NSO Group—sits at the intersection of technology, human rights, and international law. With backing from major U.S. tech giants and growing public concern over spyware abuse, the outcome of this case could set a powerful precedent for how foreign entities can be held accountable in American courts.

Case Overview in

  • The lawsuit was filed by Salvadoran journalists who claim NSO Group used Pegasus spyware to infect their iPhones.
  • Pegasus is a sophisticated surveillance tool developed by Israel-based NSO Group, often sold to government clients.
  • The journalists argue that their devices were hacked through Apple’s servers located in California.
  • A lower U.S. District Court judge had dismissed the case, citing that it should be tried elsewhere due to the plaintiffs and the company being outside the U.S.
  • Now, a panel of appellate judges appears more open to the idea that California has proper jurisdiction.
  • Judge Michael Simon referenced Apple’s own legal battle against NSO in the same district, emphasizing a precedent.
  • He highlighted that misconduct, including the hacking, allegedly occurred through systems in California.
  • NSO Group’s lawyer, Paul Watford, countered that the journalists were located in El Salvador—so that’s where the damage occurred.
  • He framed the issue as an international matter involving foreign actors harming foreign nationals.
  • Judge Jennifer Sung wasn’t convinced, noting the involvement of Apple’s infrastructure in the attack.
  • Plaintiffs’ lawyer Carrie DeCell emphasized the link between NSO’s spyware and Apple’s platforms.
  • She claimed the defendants exploited vulnerabilities in Apple’s iOS system via Apple IDs.
  • The argument centers on whether using Apple’s California-based servers constitutes misconduct in the U.S.
  • The plaintiffs insist that NSO’s actions targeted Apple as well, not just the journalists.
  • Several tech giants, including Microsoft and Google, filed a legal brief supporting the plaintiffs.
  • They argue that NSO’s tools pose serious risks to national security and U.S.-based tech infrastructure.
  • Their brief mentions California’s and the U.S. government’s shared interest in regulating such spyware.
  • This support boosts the credibility of the plaintiffs’ case and highlights broader industry concerns.
  • The court must now determine whether NSO can be tried in the U.S. for actions that had global reach.
  • The case is part of a broader legal trend where jurisdiction and cybersecurity law are evolving rapidly.
  • NSO Group continues to face legal challenges around the world for its spyware technology.
  • The outcome could redefine how foreign tech companies are treated when their tools affect U.S. interests.
  • Legal experts suggest that if the court accepts U.S. jurisdiction, it would mark a turning point.
  • It could pave the way for similar lawsuits from spyware victims across the globe.
  • The decision may also influence future cyber laws and international cooperation on digital rights.
  • The plaintiffs are backed by the Knight First Amendment Institute, signaling strong advocacy for press freedom.
  • Their position highlights the broader issue of journalist safety in the digital age.
  • At stake is not just compensation, but also accountability and the limits of surveillance capitalism.
  • The final ruling could be a benchmark for transnational legal responsibility in the cyber age.

What Undercode Say:

This legal face-off between Salvadoran journalists and NSO Group isn’t just another court drama—it’s a critical flashpoint in the global conversation about cybersecurity, sovereignty, and human rights.

What makes this case so compelling is how it tests the limits of jurisdiction in the digital age. In traditional legal frameworks, cases are heard in places where the alleged harm occurred. But the internet has muddied those lines. The plaintiffs’ core argument—that Apple’s servers in California were used to compromise their devices—pushes the legal boundaries of where “harm” actually takes place.

If courts agree that targeting U.S.-based infrastructure is enough to grant jurisdiction, the implications are massive. It would open the door for foreign victims of spyware and cyberattacks to seek justice in U.S. courts when American tech platforms are involved. This could significantly expand legal protections for journalists and activists worldwide, many of whom are targeted precisely because their home countries offer little recourse.

Another crucial element here is the involvement of major tech firms. Microsoft, Google, and Apple joining the fray through amicus briefs is a big deal. It’s not just about solidarity—it’s about protecting their ecosystems from spyware that exploits vulnerabilities in their software. These companies have every reason to back tighter scrutiny of surveillance vendors like NSO. If Pegasus can target phones undetected, it undermines the very trust consumers place in these brands.

NSO Group’s counter-argument—that the victims were in El Salvador and the hackers were foreign actors—leans on classic notions of legal distance. But it risks sounding outdated. In a world where digital borders are blurry, can companies really wash their hands of responsibility just because the physical harm occurred elsewhere?

From a tech policy standpoint, this case could push governments and courts to reconsider how they regulate surveillance tech. The U.S. government has already blacklisted NSO Group, and this lawsuit further aligns with Washington’s increasing unease about unregulated cyber tools.

If the court sides with the journalists, it may catalyze stricter export controls on spyware, more robust protections for cloud-based infrastructure, and broader legal pathways for cross-border accountability. It also sends a strong signal that press freedom in the digital era must be defended not just in principle, but through enforceable legal mechanisms.

What’s at stake here is not just about NSO Group—it’s about creating a blueprint for holding tech abusers accountable, no matter where they operate from. As spyware becomes more sophisticated, the legal system must evolve to meet the challenge. This case may just be a glimpse of the legal battles to come.

Fact Checker Results:

  • NSO Group has faced multiple lawsuits and global scrutiny for Pegasus spyware use.
  • The U.S. District Court originally dismissed the case, but the appeal is now gaining traction.
  • Apple, Google, Microsoft, and others have publicly supported litigation targeting Pegasus-related abuse.

References:

Reported By: cyberscoop.com
Extra Source Hub:
https://www.pinterest.com
Wikipedia
Undercode AI

Image Source:

Pexels
Undercode AI DI v2

Join Our Cyber World:

💬 Whatsapp | 💬 TelegramFeatured Image