Back to all lessons
Awareness Lessons
4 months ago

Spyware Vendor Defies Court Injunction Despite Legal Sanctions

NSO Group allegedly continued conducting spearphishing attacks against WhatsApp users despite a court injunction and $168 million civil judgment against them. This case highlights how malicious actors in the supply chain ecosystem may disregard legal restrictions and continue operating even under sanctions. Organizations must recognize that legal remedies alone cannot stop determined threat actors, and technical defenses remain essential even when legal protections exist. The incident demonstrates the ongoing risks posed by commercial spyware vendors who may operate outside normal business compliance frameworks.

Tactical Insight

Immediate actions

  • Implement advanced anti-phishing controls and user training to detect spearphishing attempts
  • Deploy endpoint detection and response tools to identify potential spyware infections
  • Enable multi-factor authentication on all communication platforms and critical accounts

Supply chain security

  • Conduct thorough due diligence on all technology vendors and security partners
  • Maintain an approved vendor list and regularly review vendor risk assessments
  • Implement contractual security requirements and compliance monitoring for all suppliers

Legal and compliance measures

  • Establish incident response procedures that include legal notification requirements
  • Document all security incidents for potential legal proceedings
  • Regularly review and update contracts to include stronger security and compliance clauses