Share This Page
Litigation Details for WhatsApp Inc. v. NSO Group Technologies Limited (N.D. Cal. 2019)
✉ Email this page to a colleague
WhatsApp Inc. v. NSO Group Technologies Limited (N.D. Cal. 2019)
| Docket | ⤷ Start Trial | Date Filed | 2019-10-29 |
| Court | District Court, N.D. California | Date Terminated | |
| Cause | 28:1331 Fed. Question | Assigned To | Phyllis Jean Hamilton |
| Jury Demand | Plaintiff | Referred To | Sallie Kim |
| Patents | 6,147,103; 6,166,213; 6,191,148; 6,369,085; 6,428,810; 6,875,872; 7,411,070 | ||
| Link to Docket | External link to docket | ||
Small Molecule Drugs cited in WhatsApp Inc. v. NSO Group Technologies Limited
Details for WhatsApp Inc. v. NSO Group Technologies Limited (N.D. Cal. 2019)
| Date Filed | Document No. | Description | Snippet | Link To Document |
|---|---|---|---|---|
| 2019-10-29 | External link to document | |||
| 2019-10-29 | 29 | Exhibit 3 to Declaration of Joseph D. Mornin | quot;the `070 atent") U.S. Patent No. 6,147,103 October• 9, 2018 (&…960 patent, the `424 patent, the `103 patent, the `213 patent, the `148 patent, or the `810 patent -- …230 patent, Che `960 patent, the `424 patent, the `103 patent, the `213 patent, the `1~8 patent, the `810…872 patent; the `810 patent; the `085 patent; and U.S. Patent No. 5,948,789("the `789 patent"…the `960 patent, the `424 patent, the `103 patent, the `213 patent, and the `148 patent. Thus, these | External link to document |
| >Date Filed | >Document No. | >Description | >Snippet | >Link To Document |
WhatsApp Inc. v. NSO Group Technologies Ltd.: Litigation Summary, Claims, Rulings, and Commercial Impact
WhatsApp’s lawsuit against NSO Group Technologies is a landmark U.S. spyware case involving Pegasus, a surveillance platform allegedly used to compromise WhatsApp accounts and mobile devices. WhatsApp filed the action in the Northern District of California in October 2019, alleging unauthorized access to WhatsApp servers, violations of the Computer Fraud and Abuse Act, breach of contract, and related claims.
The court rejected NSO’s sovereign-immunity defense and allowed the core case to proceed. On December 20, 2024, the court granted WhatsApp summary judgment on key liability issues, finding that NSO accessed WhatsApp’s computer systems without authorization and violated WhatsApp’s contractual terms. The case number is 4:19-cv-07123, and the matter was assigned to Judge Phyllis J. Hamilton.
What is WhatsApp Inc. v. NSO Group about?
WhatsApp alleges that NSO used WhatsApp’s servers to deliver Pegasus spyware to approximately 1,400 mobile devices between April and May 2019. The alleged targets included journalists, human-rights advocates, diplomats, political dissidents, and government officials.
According to the complaint, NSO exploited WhatsApp’s calling functionality to install Pegasus without requiring the targeted user to answer the call. WhatsApp alleged that NSO created or controlled accounts on WhatsApp’s platform, sent malicious call traffic, and used WhatsApp’s servers to facilitate spyware delivery.
The case is significant because WhatsApp sued the spyware vendor itself rather than only the government customers that allegedly purchased or operated Pegasus.
Case identification
| Item | Detail |
|---|---|
| Case | WhatsApp Inc. v. NSO Group Technologies Ltd. |
| Court | U.S. District Court for the Northern District of California |
| Case number | 4:19-cv-07123 |
| Judge | Phyllis J. Hamilton |
| Filing date | October 29, 2019 |
| Plaintiff | WhatsApp Inc., a Meta Platforms company |
| Defendant | NSO Group Technologies Ltd. |
| Product at issue | Pegasus spyware and related infrastructure |
| Principal technology | WhatsApp messaging and calling systems |
| Core legal theories | CFAA, breach of contract, California computer-access law, DMCA, trespass, and related claims |
What claims did WhatsApp assert against NSO Group?
WhatsApp’s claims centered on unauthorized access to computer systems and violation of the platform’s contractual restrictions.
Computer Fraud and Abuse Act
The Computer Fraud and Abuse Act, 18 U.S.C. § 1030, prohibits unauthorized access to protected computers and certain forms of computer intrusion. WhatsApp alleged that NSO accessed WhatsApp systems without authorization and caused the transmission of malicious code to targeted devices.
The CFAA claim was commercially important because a finding of liability could support compensatory damages, injunctive relief, and recovery of litigation-related costs.
Breach of contract
WhatsApp alleged that NSO accepted and violated WhatsApp’s Terms of Service. The terms prohibited unauthorized use, abuse of WhatsApp’s systems, automated access, and conduct that interfered with the platform or its users.
The contract claim allowed WhatsApp to frame NSO’s conduct as a direct violation of platform rules, independent of whether NSO’s conduct also violated federal computer-access law.
California computer-access claims
WhatsApp also asserted claims under California’s Comprehensive Computer Data Access and Fraud Act. The statute addresses unauthorized access, damage, copying, and interference involving computer systems and data.
Digital Millennium Copyright Act
WhatsApp asserted a claim under Section 1201 of the Digital Millennium Copyright Act. The theory was that NSO circumvented technological protections designed to control access to WhatsApp’s software and services.
Other claims
The complaint included claims based on trespass to chattels, intentional interference with contractual relations, intentional interference with prospective economic advantage, unjust enrichment, and civil conspiracy.
What did NSO Group argue in response?
NSO challenged the court’s jurisdiction and the sufficiency of WhatsApp’s claims. Its principal defenses included the following:
- NSO argued that it was protected by foreign sovereign immunity because it developed Pegasus for government customers.
- NSO disputed whether its conduct constituted access to WhatsApp’s protected computers.
- NSO challenged WhatsApp’s interpretation of its Terms of Service.
- NSO contested the causal relationship between its conduct and the alleged device compromises.
- NSO disputed the damages theory and the scope of any requested injunction.
- NSO challenged aspects of the DMCA and California statutory claims.
The sovereign-immunity defense was central. NSO attempted to characterize itself as performing governmental functions for foreign states. The court rejected that position, holding that NSO had not established an entitlement to sovereign immunity under the Foreign Sovereign Immunities Act.
What were the major court rulings?
2020 ruling on NSO’s motion to dismiss
In 2020, Judge Hamilton denied NSO’s principal effort to dismiss the case. The court concluded that WhatsApp had adequately pleaded its federal and state-law claims and that the action could proceed against NSO in the United States.
The ruling allowed WhatsApp to pursue discovery into NSO’s infrastructure, customer relationships, Pegasus deployment methods, and alleged use of WhatsApp’s systems.
Discovery disputes and sanctions
The case included extensive discovery disputes. WhatsApp sought information concerning NSO’s source code, servers, deployment mechanisms, customer use, and communications relating to the alleged attacks.
NSO resisted disclosure of certain materials on confidentiality, foreign-government, trade-secret, and security grounds. Those disputes affected the scope and pace of discovery and increased the importance of court-ordered production and evidentiary sanctions.
The discovery record also created litigation risk for NSO because the court could limit defenses or draw adverse inferences if the company failed to preserve or produce relevant evidence.
December 20, 2024 summary-judgment ruling
The court granted WhatsApp summary judgment on significant liability issues. The ruling found that NSO accessed WhatsApp’s computer systems without authorization and violated WhatsApp’s contractual terms.
The ruling materially narrowed the remaining dispute. Liability on the principal CFAA and contract theories no longer depended entirely on a jury’s determination of whether NSO had engaged in unauthorized access. Remaining issues included damages, the scope of relief, and claims that were not resolved in WhatsApp’s favor at summary judgment.
What damages and remedies did WhatsApp seek?
WhatsApp sought monetary damages, litigation costs, and injunctive relief. The requested relief was directed at preventing NSO from accessing WhatsApp’s systems, using WhatsApp accounts or infrastructure, and deploying conduct that circumvents WhatsApp’s security controls.
The damages case has several potential components:
| Damages category | Potential basis |
|---|---|
| Direct technical costs | Investigation, remediation, security hardening, and incident response |
| Statutory damages | Available under certain federal and California claims |
| Contract damages | Losses caused by violation of WhatsApp’s Terms of Service |
| Lost business or platform harm | Alleged injury to platform integrity and user trust |
| Exemplary or punitive damages | Potentially available under certain state-law theories |
| Equitable relief | Injunction against unauthorized access and circumvention |
The economic value of the case is difficult to measure from the public pleadings alone. The larger commercial objective is platform protection and deterrence. An injunction could restrict NSO’s ability to use WhatsApp infrastructure even where Pegasus is sold to foreign-government customers.
What is the litigation status of WhatsApp v. NSO Group?
As of the December 20, 2024 summary-judgment ruling, WhatsApp had secured major liability findings against NSO. The case remained relevant to damages and final remedies.
The procedural posture can be summarized as follows:
| Date | Event |
|---|---|
| October 29, 2019 | WhatsApp filed the complaint |
| 2020 | Court denied NSO’s principal motion to dismiss |
| 2020-2024 | Discovery disputes concerning Pegasus, customer activity, servers, and source code |
| 2024 | Court resolved significant discovery and summary-judgment issues |
| December 20, 2024 | Court granted WhatsApp summary judgment on key CFAA and contract liability issues |
| After December 20, 2024 | Damages and remaining remedial issues continued |
The key legal result is that NSO’s role as a private surveillance-technology supplier did not shield it from liability for direct access to WhatsApp systems.
How strong is WhatsApp’s legal position?
WhatsApp’s position strengthened substantially after summary judgment.
Strengths
WhatsApp had several advantages:
- The alleged conduct involved identifiable technical activity directed through WhatsApp infrastructure.
- WhatsApp controlled the relevant platform terms and security systems.
- The CFAA and contract claims provided separate liability pathways.
- The court rejected NSO’s sovereign-immunity defense.
- The alleged attack affected a defined group of approximately 1,400 targets.
- WhatsApp could rely on technical logs, server records, account data, and internal security investigations.
Remaining legal risks
The remaining risks related primarily to damages and the scope of relief:
- WhatsApp had to connect NSO’s conduct to quantifiable economic injury.
- NSO could contest the amount of damages even after liability findings.
- Some claims involved more demanding proof of intent, causation, or statutory elements.
- The enforceability of broad injunctive relief could become a contested issue.
- Enforcement against a foreign defendant could create practical complications.
What does the case mean for spyware vendors and platform operators?
The decision increases litigation exposure for commercial spyware companies that interact directly with a U.S. technology platform. A vendor may face liability even if the ultimate customer is a foreign government and the surveillance activity occurs outside the United States.
For platform operators, the case supports several litigation strategies:
- Enforceable terms of service can provide a direct contractual claim against unauthorized commercial users.
- Server logs and security telemetry can establish unauthorized access.
- Technical countermeasures can support DMCA and computer-access theories.
- Early injunctions can prevent continued use of platform infrastructure.
- Claims against vendors can complement regulatory restrictions on government customers.
For surveillance vendors, the decision increases the importance of segregating customer operations from third-party platforms and avoiding direct interaction with protected systems without express authorization.
How does this case compare with patent litigation?
This is not a drug patent, medical-device patent, or patent-infringement case. It does not involve Orange Book listings, Paragraph IV certifications, FDA exclusivity, formulation patents, method-of-use patents, biosimilars, or generic entry.
The relevant intellectual-property issue is circumvention of technological protections under the DMCA, not infringement of a patent claim. The commercial dispute concerns unauthorized access to software infrastructure and deployment of spyware, rather than rights in a chemical compound, biologic, manufacturing process, or dosage form.
Does the case affect FDA status, Orange Book status, or drug exclusivity?
No. WhatsApp v. NSO Group has no FDA regulatory pathway, Orange Book listing, New Drug Application, biologic license application, Hatch-Waxman exclusivity period, or pharmaceutical patent-expiration date.
The relevant regulatory and commercial risks are cybersecurity, export controls, sanctions, government procurement restrictions, privacy enforcement, and platform-access restrictions.
What companies and organizations are affected?
The immediate parties are Meta-owned WhatsApp and NSO Group. The case also affects:
- Government customers that procure commercial spyware
- Mobile-device manufacturers
- Messaging platforms
- Cloud and telecommunications providers
- Human-rights organizations
- Cybersecurity vendors
- Investors evaluating surveillance-technology companies
- Insurers underwriting cyber and technology risk
The case may increase vendor due diligence requirements for companies that sell intrusion tools to government agencies. It also creates a litigation precedent for technology platforms seeking to block commercial exploitation of their infrastructure.
Key Takeaways
- WhatsApp sued NSO Group in 2019 over alleged Pegasus spyware attacks delivered through WhatsApp infrastructure.
- The case is pending in the Northern District of California as No. 4:19-cv-07123.
- The court rejected NSO’s sovereign-immunity defense.
- WhatsApp asserted CFAA, contract, California computer-access, DMCA, trespass, interference, and unjust-enrichment theories.
- On December 20, 2024, the court granted WhatsApp summary judgment on major CFAA and breach-of-contract liability issues.
- The case is a cybersecurity and platform-access dispute, not a pharmaceutical patent matter.
- The principal remaining commercial issues concern damages, injunctive relief, enforcement, and the broader exposure of commercial spyware vendors.
FAQs About WhatsApp v. NSO Group
Can a private spyware company be sued for conduct performed for a foreign government?
Yes. The court rejected NSO’s attempt to obtain sovereign-immunity protection based on its government customers. A private contractor does not automatically acquire sovereign immunity merely because it sells technology to a government.
Did WhatsApp sue the governments that allegedly used Pegasus?
The case targeted NSO Group, the commercial spyware developer and supplier. The central allegations concerned NSO’s direct use of WhatsApp systems to facilitate Pegasus deployment.
Was Pegasus itself found to infringe WhatsApp intellectual property?
The case did not primarily concern patent or copyright infringement. WhatsApp’s principal theories involved unauthorized computer access, breach of contract, circumvention, and interference with its platform.
What is the significance of the 1,400 targeted accounts?
The alleged 1,400 compromises provided a defined factual basis for WhatsApp’s technical investigation, liability claims, and damages analysis. The number also helped distinguish the case from a generalized security incident.
Could the ruling affect other commercial spyware companies?
Yes. The ruling may encourage messaging platforms, cloud providers, and device companies to pursue vendors that use their systems without authorization, even when those vendors operate for government customers.
References
-
WhatsApp Inc. v. NSO Group Technologies Ltd., No. 4:19-cv-07123, Complaint (N.D. Cal. Oct. 29, 2019).
-
WhatsApp Inc. v. NSO Group Technologies Ltd., No. 4:19-cv-07123, Order on Motion to Dismiss (N.D. Cal. 2020).
-
WhatsApp Inc. v. NSO Group Technologies Ltd., No. 4:19-cv-07123, Order on Motions for Summary Judgment (N.D. Cal. Dec. 20, 2024).
-
Computer Fraud and Abuse Act, 18 U.S.C. § 1030.
-
Digital Millennium Copyright Act, 17 U.S.C. § 1201.
-
Foreign Sovereign Immunities Act, 28 U.S.C. §§ 1602-1611.
More… ↓
