Meta Catches NSO Spear-Phishing on WhatsApp, Asks Court to Hold Vendor in Contempt
The injunction was supposed to keep Pegasus operators away from WhatsApp users. Meta says NSO came back anyway — and is now asking a judge to do something about it.

Meta says it caught NSO Group running spear-phishing attempts against WhatsApp users, and it is going back to federal court to argue the spyware vendor violated a permanent injunction that was supposed to end exactly this behavior.
The campaign was a fairly standard social-engineering play. Operators tried to coax targets into tapping malicious links that pulled them off WhatsApp and onto attacker-controlled sites. No zero-click exploit chain this time, at least not one Meta is describing publicly. Just a lure, a click, and an external page doing whatever it was built to do.
This is the part of the playbook where I'd normally note whether MFA would have helped. Honestly? Against a credential-harvest page on a domain a user already trusted enough to visit, phishing-resistant auth — WebAuthn, passkeys, FIDO2 — is what actually moves the needle. SMS or TOTP wouldn't have saved most of these targets if the operator was proxying the session.
The legal piece is the more interesting story.
Meta won its civil suit against NSO in May, with a jury awarding roughly $168 million in damages tied to the 2019 Pegasus campaign that abused a WhatsApp voice-call vulnerability to deliver spyware to journalists, activists, and diplomats. The permanent injunction handed down alongside that verdict was explicit: NSO is barred from accessing or targeting WhatsApp infrastructure and users, full stop.
Meta's contempt filing argues NSO did it anyway.
That matters beyond one vendor. Contempt is one of the few enforcement levers that actually bites a foreign company whose customers are sovereign governments. Damages can be appealed, restructured, or absorbed. A contempt finding puts officers personally on the hook and gives a U.S. court a reason to escalate. NSO has spent years arguing it sells to vetted government clients and isn't responsible for downstream targeting. A judge looking at fresh evidence of spear-phishing against the exact platform it was enjoined from touching may find that argument thinner than it used to be.
For defenders, the operational read is unchanged. Treat WhatsApp messages from unknown contacts with the same suspicion as an unsolicited email. Push high-risk users — reporters, dissidents, executives, anyone NSO's customers care about — onto Lockdown Mode on iOS or the equivalent hardened profiles on Android, and pair that with hardware-backed passkeys for any account that matters.
The spear-phishing pivot is also worth sitting with. When zero-click chains get burned or patched, even well-funded offensive vendors fall back to clicking links on phones. That's a downgrade in capability, and it's a downgrade defenders can actually do something about.
The court filing has not yet been ruled on. NSO has not publicly responded to the contempt allegation as of writing.



