Meta Accuses NSO Group of WhatsApp Spear Phishing, Seeks Contempt After Court Injunction
Image: Ynetnews

Meta Accuses NSO Group of WhatsApp Spear Phishing, Seeks Contempt After Court Injunction

08 June, 2026.Technology and Science.13 sources

The story in 15 seconds

  • Meta alleges NSO violated a permanent injunction by targeting WhatsApp users with spear-phishing.
  • WhatsApp disrupted new NSO-linked spear-phishing campaigns; seeks contempt action.
  • NSO Group is an Israeli Pegasus spyware vendor previously blacklisted by the U.S. government.

The divide

How many WhatsApp users were targeted

Disagreement affects perceived scale and urgency of the alleged violation.

Who skipped what

How each outlet frames it

Every outlet we compared, the headline it ran, and a link to the original article.

Source Diversity
13 sources
Other
5
Western Mainstream
4
Local Western
2
Western Alternative
1
Israeli
1

Western Mainstream

Ars Technica
Ars Technica

Meta alleges NSO violated spyware injunction with new WhatsApp attacks

08 June, 2026

Read the original →
Numerama
Numerama

Convicted, blacklisted, and still active: WhatsApp re-enters the war against the Pegasus maker.

08 June, 2026

Read the original →
TechCrunch
TechCrunch

WhatsApp says it caught new spyware attacks linked to NSO Group in violation of court order

08 June, 2026

Read the original →
The Hacker News
The Hacker News

Meta Blocks NSO Group's New WhatsApp Phishing Attack, Files Contempt Order

08 June, 2026

Read the original →

Other

BleepingComputer
BleepingComputer

WhatsApp says it disrupted new NSO spyware phishing attacks

08 June, 2026

Read the original →
CyberScoop
CyberScoop

Meta accuses NSO Group of defying spyware injunction, files contempt of court complaint

08 June, 2026

Read the original →
Facebook
Facebook

Fighting Spyware: An Update From WhatsApp

08 June, 2026

Read the original →
iTnews
iTnews

Meta accuses NSO Group of violating court order by WhatsApp spear phishing

08 June, 2026

Read the original →
The Record from Recorded Future News
The Record from Recorded Future News

WhatsApp says NSO targeted users with spearfishing attacks in violation of court order

08 June, 2026

Read the original →

Local Western

Engadget
Engadget

WhatsApp Says Spyware Maker NSO Group Is Still Targeting Its Users

08 June, 2026

Read the original →
Silicon.fr
Silicon.fr

WhatsApp sues NSO for injunction violation.

09 June, 2026

Read the original →

Western Alternative

The Tech Buzz
The Tech Buzz

WhatsApp Asks Court to Hold NSO Group in Contempt After New Attacks

08 June, 2026

Read the original →

Israeli

Ynetnews
Ynetnews

WhatsApp accuses Israel's NSO of renewed spyware campaign against users worldwide

08 June, 2026

Read the original →

Full story

Meta seeks contempt

Meta accused NSO Group of violating a permanent injunction by continuing to target WhatsApp communications with spear phishing and social engineering attempts, and said it had applied to court for NSO to be held in contempt.

Meta today accused spyware maker NSO Group of violating a court order that barred it from targeting users of WhatsApp

Ars TechnicaArs Technica

WhatsApp said it caught and disrupted the latest NSO-linked campaign after investigating user reports, and Meta said the incidents involved attempts to trick people into clicking on malicious links that drove them to external websites outside of WhatsApp.

Image from Ars Technica
Ars TechnicaArs Technica

Meta also said it caught NSO creating test accounts and groups on WhatsApp, which it took down, and it published malicious domains as indicators of compromise including ikhwancast[.]com, ghazacast[.]com, and fr24cast[.]com.

Meta’s filing comes after a jury decision in early May forced NSO Group to pay damages for attacking users of WhatsApp and other platforms with Pegasus, with damages originally set to US$167 million ($237 million) and later reduced to US$4 million ($5.7 million).

Jordan-linked tactics

Meta said the campaign it disrupted resembled spyware infections that hit journalists and activists in Jordan from 2019 to 2023, and it described the tactic as trying to “trick people into clicking on malicious links to drive them to external websites outside of WhatsApp.”

In a separate account of the same dispute, The Record from Recorded Future News said WhatsApp accused NSO of deploying spearfishing attacks in violation of an October court order barring the firm from using the messaging app as an attack vector.

Image from BleepingComputer
BleepingComputerBleepingComputer

The Record also reported that WhatsApp said the latest attacks used social engineering techniques to “trick people into clicking on malicious links to drive them to external websites outside of WhatsApp,” and that NSO created test accounts and groups that WhatsApp removed.

Meta’s contempt push was framed by a researcher at the University of Toronto’s Citizen Lab, John Scott-Railton, who wrote that “NSO’s own actions make the strongest argument for why they should stay on the Entity list.”

What’s at stake

Meta argued that keeping NSO under U.S. restrictions is necessary because “When a malicious company on the US government’s Entity List continues to defy US courts, existing restrictions must remain firmly in place.”

Meta said Monday that it caught a spearphishing campaign linked to spyware maker NSO Group despite a court injunction, prompting the tech giant to file a contempt-of-court complaint

CyberScoopCyberScoop

CyberScoop reported that Meta said easing restrictions would undermine U.S. national security and put “American companies and billions of people worldwide who depend on secure communications at risk,” while also noting lawmakers sought information about the federal government’s prospective use of NSO Group tech.

WhatsApp’s public-facing response included technical guidance that end-to-end encryption protects users’ messages and calls from Pegasus and other spyware, along with calls to update apps and operating systems for optimal protection.

In addition, WhatsApp urged users to enable features such as Android’s ‘Advanced Protection’ and iOS’s ‘Lockdown Mode,’ and it said the threat indicators it shared included the domains ikhwancast[.]com, ghazacast[.]com, and fr24cast[.]com for people to check whether they were targeted.

The deep audit

How victims, perpetrators and terms are handled across outlets.

More on Technology and Science