iPhones of At Least 9 US State Officials Said to Be Hacked by NSO Group Spyware

It is the widest known hack of US officials through NSO Group technology.

Advertisement
By Reuters | Updated: 4 December 2021 10:44 IST
Highlights
  • iPhones were hacked by an unknown assailant using sophisticated spyware
  • This spyware developed by the Israel-based NSO Group
  • US officials in Uganda or focused on East African country were targetted

Apple said it would notify victims, and it has sued NSO Group as well

Apple iPhones of at least nine US State Department employees were hacked by an unknown assailant using sophisticated spyware developed by the Israel-based NSO Group, according to four people familiar with the matter.

The hacks, which took place in the last several months, hit US officials either based in Uganda or focused on matters concerning the East African country, two of the sources said.

The intrusions, first reported here, represent the widest known hacks of US officials through NSO technology. Previously, a list of numbers with potential targets including some American officials surfaced in reporting on NSO, but it was not clear whether intrusions were always tried or succeeded.

Advertisement

Reuters could not determine who launched the latest cyberattacks.

Advertisement

NSO Group said in a statement on Thursday that it did not have any indication their tools were used but canceled access for the relevant customers and would investigate based on the Reuters inquiry.

"If our investigation shall show these actions indeed happened with NSO's tools, such customer will be terminated permanently and legal actions will take place," said an NSO spokesperson, who added that NSO will also "cooperate with any relevant government authority and present the full information we will have."

Advertisement

NSO has long said it only sells its products to government law enforcement and intelligence clients, helping them to monitor security threats, and is not directly involved in surveillance operations.

Officials at the Uganda embassy in Washington did not comment. A spokesperson for Apple declined to comment.

Advertisement

A State Department spokesperson declined to comment on the intrusions, instead pointing to the Commerce Department's recent decision to place the Israeli company on an entity list, making it harder for U.S. companies to do business with them.

NSO Group and another spyware firm were "added to the Entity List based on a determination that they developed and supplied spyware to foreign governments that used this tool to maliciously target government officials, journalists, business people, activists, academics, and embassy workers," the Commerce Department said in an announcement last month.

Easily identifiable

NSO software is capable of not only capturing encrypted messages, photos and other sensitive information from infected phones, but also turning them into recording devices to monitor surroundings, based on product manuals reviewed by Reuters.

Apple's alert to affected users did not name the creator of the spyware used in this hack.

The victims notified by Apple included American citizens and were easily identifiable as U.S. government employees because they associated email addresses ending in state.gov with their Apple IDs, two of the people said.

They and other targets notified by Apple in multiple countries were infected through the same graphics processing vulnerability that Apple did not learn about and fix until September, the sources said.

Since at least February, this software flaw allowed some NSO customers to take control of iPhones simply by sending invisible yet tainted iMessage requests to the device, researchers who investigated the espionage campaign said.

The victims would not see or need to interact with a prompt for the hack to be successful. Versions of NSO surveillance software, commonly known as Pegasus, could then be installed.

Apple's announcement that it would notify victims came on the same day it sued NSO Group last week, accusing it of helping numerous customers break into Apple's mobile software, iOS.

In a public response, NSO has said its technology helps stop terrorism and that they've installed controls to curb spying against innocent targets.

For example, NSO says its intrusion system cannot work on phones with U.S. numbers beginning with the country code +1.

But in the Uganda case, the targeted State Department employees were using iPhones registered with foreign telephone numbers, said two of the sources, without the U.S. country code.

Uganda has been roiled this year by an election with reported irregularities, protests and a government crackdown. U.S. officials have tried to meet with opposition leaders, drawing ire from the Ugandan government. Reuters has no evidence the hacks were related to current events in Uganda.

A senior Biden administration official, speaking on condition he not be identified, said the threat to U.S. personnel abroad was one of the reasons the administration was cracking down on companies such as NSO and pursuing new global discussion about spying limits.

The official added that the government has seen "systemic abuse" in multiple countries involving NSO's Pegasus spyware.

Sen. Ron Wyden, who is on the Senate Intelligence Committee, said: "Companies that enable their customers to hack U.S. government employees are a threat to America's national security and should be treated as such."

Historically, some of NSO Group's best-known past clients included Saudi Arabia, the United Arab Emirates and Mexico.

The Israeli Ministry of Defense must approve export licenses for NSO, which has close ties to Israel's defense and intelligence communities, to sell its technology internationally.

In a statement, the Israeli embassy in Washington said that targeting American officials would be a serious breach of its rules.

"Cyber products like the one mentioned are supervised and licensed to be exported to governments only for purposes related to counter-terrorism and severe crimes," an embassy spokesperson said. "The licensing provisions are very clear and if these claims are true, it is a severe violation of these provisions."

© Thomson Reuters 2021


This week on Orbital, the Gadgets 360 podcast, we discuss iPhone 13, new iPad and iPad mini, and Apple Watch Series 7 — and what they mean to the Indian market. Orbital is available on Apple Podcasts, Google Podcasts, Spotify, Amazon Music and wherever you get your podcasts.
Affiliate links may be automatically generated - see our ethics statement for details.
 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: iPhones, iPhone Hack, Apple
Advertisement

Related Stories

Popular Mobile Brands
  1. OnePlus 15R Storage Options Leaked: Here's How Much It Might Cost in India
  2. Pixel 10 Series Gets Price Cuts During Google's End of Year Sale: See Offers
  3. MacBook Air (2025) With M4 Chip Available at This Discounted Price
  4. Motorola Edge 70 With 5,000mAh Battery Launched in India at This Price
  5. Logitech MX Master 4 Launches in India With These Features
  6. Oppo Reno 15c With Snapdragon 7 Gen 4 SoC Launched at This Price
  7. Vivo S50, S50 Pro Mini With Snapdragon Chips Launched at These Prices
  8. Jio Launches Happy New Year 2026 Prepaid Plans: Check Price, Benefits
  9. RAM Crisis 2026: 16GB Phones Out, 4GB Models Making a Comeback
  10. Mrs Deshpande OTT Release Date: Madhuri Dixit's Starrere to Premiere on This Date
  1. The End of 16GB RAM Phones? AI Boom Forces Smartphone Makers to Bring Back 4GB Models
  2. Xiaomi 17 Ultra Tipped to Launch Alongside Redmi Turbo 5 Series, New Wearables
  3. Mrs Deshpande OTT Release Date: Madhuri Dixit’s Psychological Thriller Premieres on This Date
  4. Knives Out Now Streaming on Lionsgate Play: What You Need to Know
  5. The Copenhagen Test OTT Release Date: When and Where to Watch it Online?
  6. Tell Me Softly Out on OTT: Everything You Need to Know About This Spanish Teen Romance Film
  7. Vivo S50 Pro Mini Launched With Snapdragon 8 Gen 5 SoC, Vivo S50 Tags Along: Price, Specifications
  8. Clair Obscur: Expedition 33 Gets New 'Thank You' Update After Winning at The Game Awards
  9. Apple Fitness+ Now Available in India With Custom Workout Programmes: Price and Other Details
  10. Samsung Could Reportedly Strike a Deal With AMD to Build Future 2nm Process Chipsets
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.