NSO Group must pay more than $167 million in damages to WhatsApp for spyware campaign

Spyware maker NSO Group will have to pay more than $167 million in damages to WhatsApp for a 2019 hacking campaign against more than 1,400 users.
On Tuesday, after a five-year legal battle, a jury ruled that NSO Group must pay $167,256,000 in punitive damages and around $444,719 in compensatory damages.
This is a huge legal win for WhatsApp, which had asked for more than $400,000 in compensatory damages, based on the time its employees had to dedicate to remediate the attacks, investigate them, and push fixes to patch the vulnerability abused by NSO Group, as well as unspecified punitive damages.
WhatsApp did not immediately respond to a request for comment.
NSO Group’s spokesperson Gil Lainer left the door open for an appeal
“We will carefully examine the verdict’s details and pursue appropriate legal remedies, including further proceedings and an appeal,” Lainer said in a statement.
The trial, as well as the whole lawsuit, prompted a series of revelations, such as the location of the victims of the 2019 spyware campaign, as well as the names of some of NSO Group’s customers.
Techcrunch event
Berkeley, CA
|
June 5
The ruling marks the end — pending a potential appeal — of a legal battle that started in more than five years ago, when WhatsApp filed a lawsuit against the spyware maker. The Meta-owned company accused NSO Group of accessing WhatsApp servers and exploiting an audio-calling vulnerability in the chat app to target around 1,400 people, including dissidents, human rights activists, and journalists.
Will Cathcart, the head of WhatsApp, explained the lawsuit’s reasoning in a Washington Post op-ed at the time, where he said that “this should serve as a wake-up call for technology companies, governments and all Internet users. Tools that enable surveillance into our private lives are being abused, and the proliferation of this technology into the hands of irresponsible companies and governments puts us all at risk.”
Last December, WhatsApp won. Judge Phyllis Hamilton, who presided over the case, ruled that NSO Group was liable for breaching federal and California hacking laws in its 2019 spyware campaign against the 1,400 WhatsApp users. The judge ruled that NSO Group was also liable for breaching WhatsApp’s terms of service, which prohibit the use of the app for malicious purposes.
Cathcart celebrated the December ruling saying in an X post that it was “a huge win for privacy,” and that “surveillance companies should be on notice that illegal spying will not be tolerated.”
At that point, the case moved on to a jury trial to determine what damages the spyware company owed WhatsApp, which has now concluded.