Press to release document — or hit Enter
Episode II — Pegasus, Case III
5W+1H — Case Summary
WHO: More than 50,000 phone numbers selected by customers of NSO Group's Pegasus system. The records included journalists, human rights defenders, lawyers, diplomats, politicians, businesspeople, and several heads of state.FS
WHAT: A leaked database of selection records tied to Pegasus customers, paired with forensic work showing that some phones linked to the data had in fact been infected or faced attempted infection.FSASL
WHEN: The records covered selections dating back to 2016. The Pegasus Project findings were published on July 18-19, 2021.FSAI
WHERE: More than 50 countries appeared in the records. Amnesty and media partners identified potential NSO clients in 11 countries.FSAI
WHY: Pegasus had been marketed as a narrowly used tool for crime and terrorism investigations. The leaked selections suggested a far broader surveillance appetite aimed at civil society, media, and politics.FS
HOW: Forbidden Stories and partner newsrooms analyzed the leak. Amnesty Security Lab conducted forensic examinations, published a methodology report, released an open-source tool, and disclosed more than 700 Pegasus-related domains.ASL
The Pegasus Project did not begin with a court filing or a company disclosure. It began with leaked records: more than 50,000 phone numbers selected for surveillance by NSO clients, spanning more than 50 countries and dating back to 2016.FS
That distinction matters. The leak was not a list of 50,000 confirmed infections. It was a record of numbers selected inside a surveillance workflow. That made it evidence of intent, scale, and targeting patterns before a forensic lab ever touched a device.GDN
What made the records explosive was not only their size, but their consistency with later forensic findings. The leak showed a selection layer that looked industrial rather than exceptional: a queue, not a one-off target package.FS
Presence on the list did not prove a successful Pegasus compromise. Some selected numbers may never have been infected. Some may have been unreachable. Some may have been associated with failed attempts. That caution is essential if the story is going to remain factual.GDN
But the leak did not stand alone. Amnesty Security Lab's forensic analyses confirmed Pegasus infection or attempted infection on 37 smartphones tied to the wider project, and published the technical methodology behind those findings along with an open-source verification tool.FSASL
The methodology release mattered almost as much as the findings. Amnesty published indicators and more than 700 Pegasus-related domains, making the investigation reproducible instead of rhetorical.AIASL
Amnesty said the records included at least 180 journalists in 20 countries. Its reporting cited specific examples: the Mexican journalist Cecilio Pineda Birto, more than 40 Azerbaijani journalists, at least 40 Indian journalists, and staff linked to the Associated Press, CNN, The New York Times, Reuters, and the Financial Times.AI
Forbidden Stories described the target pool even more broadly: human rights defenders, academics, businesspeople, lawyers, doctors, diplomats, union leaders, politicians, and several heads of state. The leak did not point to one abusive customer. It pointed to a category of abuse spanning multiple regimes and institutions.FS
This is where the marketing line around Pegasus began to collapse. A tool sold as precise and exceptional kept reappearing around reporters, dissidents, lawyers, and political actors whose relevance was democratic, not criminal.AI
One number in the reporting became impossible to ignore: more than 10,000 phone numbers were selected over two years by one Pegasus client in Morocco alone. Even if selection and infection are kept separate, that is not the profile of rare, surgical use.FS
Amnesty and its partners said they identified potential NSO clients in 11 countries. That did not establish that every listed number was hacked. It did establish that the targeting ecosystem around Pegasus was multinational, routinized, and much larger than any single scandal.AI
The 50K list was damaging precisely because it shifted the argument. The question was no longer only what Pegasus could do once installed. The question became how many people were being queued for possible surveillance before the public ever heard their names.FSGDN
Exploit chains make headlines because they are technical, cinematic, and easy to dramatize. The 50K list exposed something more administrative and therefore more unsettling: surveillance as process. Numbers were gathered, sorted, selected, and queued long before a forensic report could confirm what happened next.FS
The list did not prove 50,000 infections. It proved something else: that a commercial spyware market had matured into a repeatable system for choosing people first and compromising some of them later. That is why the leak mattered beyond Pegasus itself.GDNAI
That pattern is the real warning. By the time a device is forensically verified, the political decision has already been made. First comes the list. Then, if the system works, the rest becomes technical detail.ASL
Leak anatomy
Public, open-access claims only. Selection and infection are kept separate on purpose.
Sources: Forbidden Stories · Amnesty International · Amnesty Security Lab · The Guardian.
"More than 50,000 phone numbers were selected. More than 50 countries appeared in the records. At least 180 journalists were among the potential targets. The leak did not prove every infection. It proved something else: long before a forensic lab confirmed Pegasus on a phone, somebody had already decided that phone belonged on a surveillance queue."
The exploit is only the second half of the story. First comes the list.