> ## Content Index
> Fetch the complete content index at: https://www.theamericanquorum.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# Apple Sues NSO Group, Seeks Permanent Ban on Its Use of Apple Products After FORCEDENTRY Spyware Campaign
- URL: https://www.theamericanquorum.com/taq-historical-2021-11-27-tech/
- Published: 2021-11-28T04:59:00.000Z
- Updated: 2021-11-28T04:59:00.000Z
- Description: Apple sued NSO Group and its parent company, seeking damages and a permanent injunction barring the spyware maker from using Apple software, services or devices after FORCEDENTRY attacks.
- Author: Kenneth R. Deans Jr.
- Tags: Tech, #Import 2026-08-31 06:04

CUPERTINO, Calif. — Apple has sued Israeli spyware maker NSO Group and its parent company, seeking damages and a permanent injunction that would bar the firms from using Apple software, services or devices after a campaign in which Pegasus spyware was delivered through a sophisticated zero-click exploit against a small number of iPhone users.

The November 23 [lawsuit announcement](https://www.apple.com/newsroom/2021/11/apple-sues-nso-group-to-curb-the-abuse-of-state-sponsored-spyware/?ref=theamericanquorum.com) marks Apple’s most direct legal move yet against the commercial surveillance industry. Apple says NSO and its clients created Apple IDs and used company infrastructure to deliver malicious data associated with FORCEDENTRY, an exploit capable of installing Pegasus without requiring the target to click a link or take another action.

## Apple moves beyond patches to attack the vendor

Apple has spent years responding technically to highly targeted spyware by fixing vulnerabilities and adding security protections. The new case attempts something broader: changing the economics and legal exposure of the company that sells the surveillance capability.

The federal [docket](https://dockets.justia.com/docket/california/candce/3%3A2021cv09078/388382?ref=theamericanquorum.com) shows Apple filed the case on November 23 in the U.S. District Court for the Northern District of California against NSO Group Technologies and Q Cyber Technologies. Apple alleges violations of federal and state law and seeks to prevent the defendants from continuing to use its products and services in connection with attacks.

The company also said it will contribute $10 million, plus any damages recovered in the lawsuit, to organizations conducting cybersurveillance research and advocacy. Apple is notifying users it believes may have been targeted by state-sponsored attackers and says similar notifications will continue when such activity is detected.

## FORCEDENTRY demonstrated how little a victim had to do

The legal action follows the discovery of FORCEDENTRY, one of the most technically significant mobile exploits publicly documented this year. Citizen Lab researchers at the University of Toronto identified the exploit while examining the phone of a Saudi activist. Their September [analysis](https://citizenlab.ca/2021/09/forcedentry-nso-group-imessage-zero-click-exploit-captured-in-the-wild/?ref=theamericanquorum.com) showed that a maliciously crafted file delivered through iMessage could exploit Apple’s image-processing software and install Pegasus on a fully updated device.

The exploit was especially concerning because it required no interaction from the target. Conventional phishing defenses depend partly on users recognizing suspicious links, attachments or login requests. A zero-click exploit removes that layer of protection and allows a highly resourced attacker to focus on software vulnerabilities rather than human mistakes.

Apple released emergency updates in September after Citizen Lab disclosed the flaw. Once Pegasus gains sufficient access to a smartphone, it can potentially expose messages, location, photos, contacts, microphones and cameras — turning a personal device into a powerful surveillance platform.

## The commercial spyware market is facing government pressure too

Apple’s case arrives only weeks after the U.S. Commerce Department added NSO Group and Candiru to the Entity List. Commerce said in its November 3 [announcement](https://www.commerce.gov/news/press-releases/2021/11/commerce-adds-nso-group-and-other-foreign-companies-entity-list?ref=theamericanquorum.com) that investigative information showed the companies developed and supplied spyware to foreign governments that used it to maliciously target officials, journalists, activists, academics, businesspeople and embassy workers.

Entity List status creates significant licensing restrictions on exports and transfers of U.S.-controlled technology to NSO. The measure does not itself shut down the company, but it can make access to American products, components and services more difficult and signals an unusually strong policy judgment about the risks posed by commercial surveillance vendors.

NSO has consistently argued that Pegasus is licensed to government intelligence and law-enforcement agencies for legitimate investigations of terrorism and serious crime. The company says it investigates allegations of misuse and can terminate customers. The central dispute is whether those safeguards are adequate given repeated evidence that spyware has reached people outside conventional criminal and national-security targets.

## Researchers have documented a pattern beyond one exploit

Amnesty International’s July [forensic methodology](https://www.amnesty.org/en/latest/research/2021/07/forensic-methodology-report-how-to-catch-nso-groups-pegasus/?ref=theamericanquorum.com) described technical indicators researchers used to identify Pegasus activity on mobile devices and released tools to assist independent analysis. That work formed part of a broader investigation into alleged targeting of journalists, activists and public figures in multiple countries.

NSO is also already defending a lawsuit brought by WhatsApp and Facebook. Their 2019 [announcement](https://about.fb.com/news/2019/10/whatsapp-nso-group/?ref=theamericanquorum.com) said an attack using WhatsApp infrastructure targeted about 1,400 users, including journalists, human-rights defenders, political dissidents and diplomats. NSO has argued that it should receive protections associated with the sovereign governments that use its technology, an issue that remains contested in court.

The accumulation of cases has made commercial spyware a challenge not only for individual technology companies but for the broader security model of smartphones. Firms such as Apple can harden operating systems, isolate risky processes and deploy rapid patches, but well-funded surveillance vendors have strong incentives to keep finding new vulnerabilities.

## Apple is trying to make attacks legally and financially harder

Apple’s legal strategy reflects the limits of purely defensive security. A software patch can close one vulnerability while leaving the attacker free to search for another. A successful injunction or damages award, by contrast, could raise the cost of operating against Apple users and potentially deter suppliers, investors or customers that interact with spyware vendors.

Washington Post [reporting](https://www.washingtonpost.com/technology/2021/11/23/apple-pegasus-lawsuit-spyware-nso/?ref=theamericanquorum.com) on the suit noted that Apple alleges NSO created more than 100 Apple IDs and agreed to Apple’s iCloud terms, facts the company is using to support jurisdiction and its claims that NSO misused Apple services while conducting attacks.

The case may also test novel legal theories. Commercial spyware firms do not generally hack devices for their own purposes; they sell capabilities to government clients. Apple is trying to hold the vendor itself responsible for the technical infrastructure and conduct that enable those clients to reach Apple users.

The Guardian’s November 23 [coverage](https://www.theguardian.com/technology/2021/nov/23/apple-sues-israeli-cyber-firm-nso-group?ref=theamericanquorum.com) described the case as part of mounting pressure on NSO after the U.S. government blacklist and months of revelations about Pegasus deployments.

## A security battle becomes a policy battle

Apple’s lawsuit will not eliminate sophisticated surveillance. Governments have long invested in lawful interception, intelligence collection and offensive cyber capabilities, and legitimate investigations will continue to create demand for tools that can penetrate encrypted devices.

The emerging question is whether private companies that industrialize those capabilities can be held to standards that meaningfully constrain abuse. Apple is now asking a federal court to impose one of the strongest possible private-sector sanctions: barring NSO from using the very ecosystem it has targeted.

For iPhone users, the immediate defense remains software updates and Apple’s continuing security work. For the technology industry, however, this week’s action signals a larger shift. Smartphone makers are beginning to treat commercial spyware vendors not merely as attackers to patch around, but as companies to confront through courts, export policy and public accountability.