Observed Signal · Jun 8, 2026 · Legal Action · Source: techcrunch · Impact: 4/5 · Sentiment: Negative
WhatsApp Disrupts NSO-Linked Spyware Phishing Campaign
WhatsApp announced it disrupted a spear-phishing campaign it says was linked to NSO Group and that the activity violated a prior court injunction barring NSO from targeting WhatsApp and its users. The Meta-owned messaging app said attackers used malicious links that directed targets to external sites and created test accounts and groups on WhatsApp; those accounts and groups were removed. WhatsApp has filed a contempt motion seeking to hold NSO in contempt of court. The report references prior litigation stemming from a 2019 mass-hacking campaign (leading to a jury award later reduced) and notes NSO’s continued controversy, past U.S. trade restrictions, and a 2025 acquisition by a group of U.S. investors.
Major platform (WhatsApp/Meta) reports a new spyware-linked campaign and alleges violation of a court injunction — this affects platform security, legal precedent around spyware targeting, user protections, and ongoing regulatory scrutiny of surveillance vendors.
Track Meta Signals & Market Shifts in Real-Time
Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.
Key Takeaways & Evidence Grounding
- WhatsApp said it caught and disrupted spear-phishing attempts linked to NSO Group.
- WhatsApp alleges the campaign violated a 2025 court injunction that bars NSO from targeting WhatsApp users and filed a contempt order against NSO.
- The attacks used malicious links directing users to external websites and included creation of test accounts and groups on WhatsApp which WhatsApp removed.
- The injunction traces to a 2019 mass-hacking campaign; a jury previously ordered NSO to pay $167 million in damages, later lowered to $4 million.
- NSO Group was purchased by a group of U.S. investors in 2025 but remains subject to U.S. trade restrictions and blocklisting.
Connected Companies & Entities
1 Entity mappedOntology Mapping & Concepts
Related Market Signals & Shifts
Recent verified developments and strategic activity across this market segment.
Russian Hackers Target Signal and WhatsApp Users, Warns Dutch Intel
Dutch intelligence agencies MIVD and AIVD warned of a large-scale global hacking campaign by alleged Russian state actors targeting Signal and WhatsApp users — especially government and military officials and journalists. The attackers are reported to use phishing and social‑engineering techniques rather than malware, including impersonating Signal support to request SMS verification codes and PINs, tricking users into scanning malicious QR codes or clicking links, and abusing WhatsApp’s Linked Devices feature to link attacker devices and, in some cases, read past messages. Signal and Meta alerted users not to share verification codes; Meta pointed to Help Center guidance. Dutch spokespeople declined to provide additional operational details. Some techniques match methods previously observed in Russian operations related to the war in Ukraine.
Fake WhatsApp iOS App Installed Spyware on ~200 iPhones
WhatsApp warned roughly 200 iOS users they had likely installed a fake WhatsApp client that contained spyware capable of reading sensitive data. WhatsApp attributes the fake app to the Italian surveillance-software company SIO, which develops the malware through its subsidiary ASIGINT; earlier reporting says SIO previously distributed Android spyware called "Spyrtacus." WhatsApp's security team logged affected accounts out, notified users about privacy risks, and instructed them to remove the unofficial app and reinstall the official client. Initial coverage came from La Repubblica and ANSA and was reported by TechCrunch. WhatsApp said it will pursue legal action against SIO; neither SIO nor Apple had publicly responded at the time of reporting.
WhatsApp Blocks Logins on Outdated Smartphones
Meta's WhatsApp is implementing a server-side update that blocks logins on mobile devices running severely outdated operating systems. The block, first reported by WABetaInfo, presents a full-screen lock screen to affected users, requiring them to update their OS before using the app. This measure is part of WhatsApp's broader security strategy to protect user data from vulnerabilities in unpatched systems. The update is rolling out gradually and does not require an app store update. WhatsApp had previously set minimum OS requirements (Android 6, iOS 12), and the new server-side enforcement aims to enforce these standards technically. The company is testing the mechanism across both Apple and Google platforms, but has not officially documented the exact version thresholds.
Track Real-Time Market Signals & Shifts
Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.
