World

Mossad's invisible phone invasion: How Israelis see everything without you knowing

Mossad's invisible phone invasion: How Israelis see everything without you knowing
The Israeli spyware Pegasus broke through the barriers...
An invisible battle rages in the digital landscape, where the devices we rely on are transformed into silent observers. Civil rights organizations have repeatedly pointed out that a series of Israeli technology companies, many of which were founded by veterans of elite intelligence units, such as Unit 8200, Unit 81, and Mossad, constitute key players in a rapidly growing global market for commercial surveillance software (spyware), as Jose Nino writes. These companies possess powerful tools that have been used against journalists, activists, political dissidents, and, in several confirmed cases, individuals living in the United States and Europe. Organizations, such as War on Want, point out that Israel hosts more spyware development companies than any other country. Among these are NSO Group, Candiru, Cellebrite, Verint, NICE, Black Cube, Cytrox, and Intellexa.

Of all these companies, one stands out more than any other: NSO Group. Headquartered in Herzliya, north of Tel Aviv, it constitutes the most characteristic example of the Israeli surveillance software industry. It was founded in 2010 by Shalev Hulio, Omri Lavie, and Niv Karmi (the brand name came from the initials of their names for its brand name, although Karmi departed just one month later). According to information, Hulio and Lavie originated from Unit 8200, the military intelligence agency of Israel, while Karmi had served in Mossad and military intelligence services. NSO acquired international fame thanks to Pegasus, a sophisticated espionage software that allows the discreet breach of smartphones, providing access to the user's camera, microphone, messages, and location data.

In 2021, the Pegasus Project, a joint investigation by Amnesty International, Forbidden Stories, and more than a dozen international news organizations, revealed that Pegasus had been used to monitor journalists, human rights defenders, and political figures. The investigation also showed that individuals belonging to the close circle of murdered Saudi journalist Jamal Khashoggi had been targeted by NSO clients both before and after his murder. However, investigators failed to ascertain which specific clients were involved, while Hulio denied any involvement of the company in the murder.

The confrontation of NSO with American technology companies ended up in courtrooms and did not evolve in its favor. In 2019, Meta, owner of WhatsApp, filed a lawsuit against it, accusing it of exploiting a security loophole in the application to install Pegasus on approximately 1,400 mobile phones within a few weeks. Among the targets were lawyers, journalists, activists, political dissidents, and high-ranking government officials from various countries. The attack could take place without any action from the victim (zero-click exploit): a call via WhatsApp was enough, even if the user never answered.

In December 2024, a federal judge ruled NSO responsible, while in May 2025 a court obligated it to pay approximately 167 million dollars in compensation and another 444,000 dollars as compensatory damages. In October of the same year, the court reduced the compensation amount to approximately 4 million dollars, but imposed a permanent injunction on NSO from attacking WhatsApp again, a development considered a far more serious blow for a company whose business relies on access to information.

In November 2021, another significant development occurred. On November 3, the US Department of Commerce included NSO on the Entity List, effectively excluding it from access to American technology. The department justified the decision, arguing that the company's activity was contrary to «the national security or foreign policy of the United States».

Three weeks later, Apple filed a lawsuit against NSO, accusing it of creating fraudulent Apple IDs and utilizing the zero-click exploit named FORCEDENTRY to breach user devices, including American citizens whose mobile phones «were monitored by NSO spyware, even when crossing international borders».

In September 2024, Apple withdrew its lawsuit, and the reasons were indicative of the difficulties of the case. As it reported to the court, continuing the procedure would obligate it to disclose critical information regarding the techniques it uses to counter such attacks. At the same time, there was a serious possibility that it would never obtain the necessary evidence, since, according to reports, Israeli officials had seized NSO documents as early as 2020 to prevent them from ending up in an American court.

The Guardian revealed this case in July 2024, maintaining that the seizure aimed to prevent NSO's cooperation with American authorities and the surrender of evidence in the parallel trial for WhatsApp. In other words, Apple partially abandoned the case because important evidentiary material was no longer accessible due to actions by the state of Israel.

The pressure on NSO is not limited to courtrooms. Amnesty International has appealed to the Justice of Israel requesting the revocation of the company's export license, while Citizen Lab of the University of Toronto has documented the use of Pegasus against Catalan politicians, members of the European Parliament, dissidents from Saudi Arabia and the United Arab Emirates, as well as figures of civil society organizations in the West. At the same time, Microsoft, Google, Cisco, and other major technology companies supported Apple's initial appeal, characterizing NSO's tools as a threat not only to users, but also to the security of the internet itself.

NSO dominates the headlines, but it does not constitute the sole case. Candiru, an extremely secretive company based in Tel Aviv, was included on the same US Department of Commerce Entity List on the same day as NSO, in 2021, due to the sale of espionage software used against journalists, political dissidents, and human rights defenders. A joint investigation by Citizen Lab and Microsoft mapped more than 750 internet domains connected to Candiru's infrastructure.

They mimic organizations

Many of these domains were created to mimic organizations that their victims considered trustworthy, such as Amnesty International, the Black Lives Matter movement, the World Health Organization, as well as various news media. Microsoft recorded at least one hundred victims, including politicians, human rights activists, academics, and members of diplomatic missions in Spain, the United Kingdom, and the Middle East.

However, the surveillance technology market is not limited to remote spyware. Cellebrite, an Israeli company specializing in digital forensic tools, develops technology for unlocking mobile phones and extracting data. Its tools are used by thousands of police services worldwide, among them in the United States, where its client is Immigration and Customs Enforcement (ICE). Critics of the company maintain that its equipment can be used just as easily against political dissidents as against criminals.

Amnesty International documented that Serbian authorities used Cellebrite tools to unlock the phones of a journalist and an activist during their detention and subsequently installed spyware on their devices. Later, Citizen Lab traced marks of Cellebrite technology use on seized mobile phones of activists in Russia, Jordan, and Kenya, which had been unlocked while their owners were in detention due to their opposition activity. Similar incidents were recorded in Botswana and Myanmar, where devices of journalists were breached after they published reports critical of their governments.

Cellebrite has stated that it terminates cooperation with clients who misuse its tools. However, researchers maintained that Russian authorities continued to use its technology even after the company's departure from the Russian market. Before Cellebrite's listing on the Nasdaq stock exchange in 2021, human rights and press freedom advocacy organizations called on competent regulatory authorities to postpone the public offering until the company proved that it had terminated sales to governments that abuse their power.

Since then, Cellebrite announced that it stopped cooperating with clients in Russia, Belarus, Serbia, Hong Kong, Bangladesh, and Myanmar, following revelations of abuse. Nevertheless, its critics maintain that the implementation of its own rules occurs only when violations receive public attention.

The presence of Israeli companies in the telecommunications sector extends far beyond spyware companies and has established itself to a significant degree in American telecommunications infrastructure. The companies Verint, formerly Comverse Infosys, and NICE Systems originated from the ecosystem of Israeli intelligence services and have at times been at the center of American public debate due to their role in lawful interception communications systems.

In his book The Shadow Factory (2008), investigative journalist James Bamford maintained that Israeli companies supplied a significant portion of the interception equipment and software used in the American telephone network, highlighting at the same time the close ties of Verint with the FBI Central Interception Office. His best-known formulation states that «nearly the entire telecommunications system of the United States is monitored through two Israeli companies with potential ties to Israeli intelligence services, without substantive oversight from Congress». Bamford names the companies Verint and Narus.

This specific position constitutes a personal claim by the author, was formulated in 2008, and has not been independently confirmed. Nevertheless, it captures enduring concerns regarding the possibility of foreign influence or surveillance through critical telecommunications infrastructure of the United States.

Verint also faced serious corporate problems. Its parent company, Comverse, collapsed following a accounting fraud and stock options backdating scandal. The CEO at the time, Kobe Alexander, fled to Namibia before eventually being extradited and pleading guilty. At the same time, reports indicated that Verint and other companies in the same field supplied surveillance systems to authoritarian regimes in Central Asia, among them Kazakhstan and Uzbekistan.

The international presence of the Israeli surveillance technology sector is not limited to its commercial activities, but constitutes a subject of broader geopolitical debate regarding the export of surveillance technologies and their integration into critical digital infrastructure. Critics maintain that the extensive presence of such companies creates risks for privacy, national security, and democratic accountability, especially when these technologies are used without sufficient transparency or effective oversight mechanisms.

www.bankingnews.gr

Latest Stories

Readers’ Comments

Also Read