WASHINGTON — The Commerce Department this week placed Israeli spyware vendors NSO Group and Candiru on the U.S. Entity List, imposing export restrictions that sharply raise the cost and complexity of doing business with American technology suppliers and marking the strongest action yet by Washington against the commercial surveillance industry.
The department said on Wednesday that the firms were added because investigative information showed they developed and supplied spyware to foreign governments that used the tools to maliciously target officials, journalists, businesspeople, activists, academics and embassy workers. The Commerce action also covered Positive Technologies of Russia and Computer Security Initiative Consultancy of Singapore, reflecting a broader concern that sophisticated intrusion tools are being sold into markets where their use can conflict with U.S. national-security and human-rights interests.
Entity List status changes the business environment
Placement on the Entity List does not amount to a blanket ban on NSO Group, but it creates a presumption against licenses for exports, reexports or transfers of items subject to U.S. export controls. The restrictions can affect software, hardware, services and technical components that firms need to develop or operate their products. The formal rule makes the policy more than a symbolic rebuke.
NSO Group has repeatedly said that it licenses Pegasus only to government intelligence and law-enforcement customers for fighting terrorism and serious crime, and that it has mechanisms to investigate misuse. But the company has faced growing evidence that customers used Pegasus against people who were not accused of serious crimes.
Amnesty International, which helped provide technical support for the Pegasus Project investigation, said the U.S. move recognized the scale of documented abuses and called it a warning to the spyware market. Its contemporaneous statement described the decision as a significant accountability measure after months of disclosures.
Zero-click exploitation changed the security debate
The policy decision follows a series of technical findings showing how advanced commercial spyware can compromise modern smartphones without requiring a victim to click a malicious link. In September, researchers at the University of Toronto’s Citizen Lab published a detailed analysis of an iMessage exploit they called FORCEDENTRY. The exploit targeted Apple’s image-rendering system and was used to install Pegasus on fully updated devices.
Apple responded by releasing emergency security updates for iPhones, iPads, Macs and Apple Watches. Its security advisory for iOS and iPadOS 14.8 described a vulnerability in which processing a maliciously crafted PDF could lead to arbitrary code execution and acknowledged that Apple was aware of a report that the issue may have been actively exploited.
The significance is broader than one software flaw. A zero-click exploit can reach a target without a phishing mistake, limiting the value of conventional security training. Once installed with sufficient privileges, a tool such as Pegasus can potentially access communications, photos, location data and microphones that users reasonably believe are protected by device security and encrypted applications.
A legal and commercial campaign is taking shape
Technology companies have been fighting NSO through courts as well as software patches. WhatsApp and Facebook sued the company in 2019, alleging that Pegasus infrastructure was used to target about 1,400 WhatsApp users. Facebook’s original announcement said the victims included journalists, human-rights defenders, political dissidents and diplomats.
NSO has argued in that litigation that it should receive immunity because its products are used by sovereign governments. The dispute has become a test of whether private surveillance contractors can claim protections associated with the governments that buy their services. Meanwhile, investigative groups have developed increasingly detailed forensic methods for detecting traces of Pegasus. Amnesty’s July methodology documented technical indicators found on targeted phones and released tools intended to help researchers validate infections.
The accumulation of evidence has shifted the debate from whether commercial spyware can be abused to what governments and technology platforms should do about the market that supplies it. The Commerce action is particularly consequential because many surveillance vendors depend directly or indirectly on U.S.-origin technologies.
Export controls may become a new cybersecurity instrument
The Entity List has traditionally been associated with sanctions-like restrictions on companies implicated in national-security concerns, proliferation or efforts to obtain sensitive American technology. Applying it to spyware vendors signals that the government increasingly views commercial cyber capabilities through the same strategic lens.
That does not resolve difficult questions about legitimate law-enforcement access. Governments have real investigative needs, particularly as encryption has made conventional wiretapping less useful. But the U.S. action draws a distinction between lawful tools and companies whose products, in the government’s judgment, have enabled malicious targeting beyond those purposes.
For NSO Group, the immediate consequence is restricted access to American products and a new reputational barrier with investors, suppliers and customers. For the wider technology sector, the message is more expansive: commercial surveillance software is no longer being treated simply as a niche security product. It is becoming a subject of export policy, diplomacy, human-rights scrutiny and corporate security strategy at the same time.