In this article
Today we look at the tool that has done the most to turn state espionage into something you can buy like any other software license. It's called Pegasus, it's developed by the Israeli company NSO Group, and it has been in use for more than a decade by governments around the world —Spain's included—. The thesis is harsh. Pegasus on its own was a high-quality surveillance instrument but with a bottleneck: someone had to read what it captured. Combining Pegasus —or its technical equivalents— with generative language models removes that bottleneck. Why does it matter to the European user? Because the technical and legal infrastructure for automated mass spying exists, is buyable, and democratic governments are already using it. My take is biased by having read every Citizen Lab report since 2018. Form yours.
I've had Citizen Lab's reports in a fixed tab for seven years. Each new report extends the list of confirmed victims and of buying governments. The trajectory is predictable and worth looking at in detail, because it illuminates something the press covers as a geopolitical anecdote and which is, in reality, permanent structure.
What Pegasus is, technically
NSO Group Technologies is an Israeli company founded in 2010 by Niv Carmi, Shalev Hulio and Omri Lavie. Its flagship product is Pegasus, spyware installed remotely on iOS and Android phones. The company sells exclusively to governments —by its own account— and under licenses controlled by Israel's Ministry of Defense, which authorizes each export.
The technical operation is what sets Pegasus apart from other spyware. Installation is done, in its most sophisticated versions, through zero-click exploits: the victim doesn't need to click any link or download anything. In 2019 a missed WhatsApp call was enough to infect the device. In 2021, an image received in iMessage produced the infection without the user opening the message. The exploits take advantage of vulnerabilities in the operating system or in messaging apps before the manufacturer has discovered and patched them.
Once installed, Pegasus accesses practically everything the device contains: text and encrypted-app messages (WhatsApp, Signal, Telegram), emails, call history, contacts, real-time GPS location, microphone and camera —which it can activate remotely—, photos, saved passwords, browsing history. The extraction is done encrypted toward servers controlled by the government client.
The approximate price of a Pegasus deployment, according to NSO Group's own sources cited in lawsuits, runs around 500,000 dollars per individual target, with multi-year licenses for governments that infect a larger number of phones. That is: industrial-scale spying costs between five and ten million dollars a year per buying country. A tiny fraction of any intelligence budget.
The victims confirmed by Citizen Lab
The work of identifying targets is done mainly by Citizen Lab, an academic laboratory at the Munk School of Global Affairs of the University of Toronto, specializing in digital security and human rights since 2001. Citizen Lab has developed forensic tools to detect the presence of Pegasus on devices and has published technical reports on dozens of cases across a dozen countries.
The list of confirmed victims has extended year after year. Journalists: Jamal Khashoggi, a Washington Post columnist murdered in the Saudi consulate in Istanbul on October 2, 2018, had been a Pegasus target, as had his fiancée Hatice Cengiz, several of his colleagues and family members. Journalists in Mexico, Hungary, India, Morocco, Azerbaijan have been infected with the tool. The Pegasus Project, an international media consortium coordinated by Forbidden Stories with technical support from Amnesty International and Citizen Lab, published in July 2021 a months-long investigation documenting more than 50,000 phone numbers that had been selected as possible targets by NSO Group clients.
Activists and human-rights lawyers: numerous in Mexico, India, Bahrain, Morocco. Politicians: the most resounding case in Spain, officially confirmed by the National Cryptologic Center (CCN-CERT) in May 2022, documented that the phone of Prime Minister Pedro Sánchez had been infected with Pegasus in May and June 2021, with two documented data extractions. Defense Minister Margarita Robles was also a victim. The Interior Ministry, then headed by Fernando Grande-Marlaska, opened an investigation. The authorship hasn't been officially attributed to any state to this day, but the circulating hypotheses point to actors with an interest in Spanish politics over Catalonia or the Sahara.
The important thing about the list isn't each individual name. It's the pattern. Pegasus is sold with the argument of fighting terrorism and organized crime. The evidence accumulated by Citizen Lab and by journalistic consortia over a decade shows it's also used, and systematically, against journalists, activists, lawyers, political opponents and, in some cases, against democratic officials of the buying country itself. The abuse isn't an exception; it's habitual use.
The Spanish government as a buyer
Spain isn't only a Pegasus victim in the Sánchez-Robles case. It's also a buyer. The existence of the contract with NSO Group was confirmed by Paz Esteban, then director of the National Intelligence Center, in an appearance before the Congress's Official Secrets Committee in May 2022. The CNI had used Pegasus against targets linked to Catalan independence, as confirmed in that same appearance. The number of infected targets was around 18, but the total scope —including judicially authorized investigations or not— remained partly classified.
Citizen Lab had previously documented, in its CatalanGate report of April 2022, the Pegasus infection of at least 65 people linked to the Catalan independence movement: presidents of the Generalitat (Pere Aragonès, Quim Torra, Roger Torrent), MEPs, lawyers, activists. The authorship of some infections was later attributed to the CNI; others remained without firm attribution.
The balance, without entering into political judgments each reader will make for themselves, is operational: Spain is at once a buyer and a victim of the same tool. The asymmetry holds as long as Pegasus is bought and used without sufficient public parliamentary debate, and as long as the public doesn't demand stricter procedural guarantees for the use of spyware against the body politic itself.
The bottleneck AI removes
Here comes the part the Pegasus case alone doesn't quite show. Until roughly 2022, spying via Pegasus had a human bottleneck. Once the software was installed and the data extracted, someone had to read it. A target's WhatsApp conversations over a month can be thousands of messages. The audio recordings the microphone captures can be hundreds of hours. The emails can be tens of thousands. The work of analysis was enormous and expensive.
That meant, in practice, that an intelligence service could spy simultaneously on dozens or hundreds of selected targets, not on tens of thousands. The operational limit was human, not technical.
The arrival of high-capacity generative language models —GPT-4, Claude, Gemini, Llama 3.3 and later, as well as specialized models developed internally by intelligence agencies— has largely removed that bottleneck. A language model can read in minutes the thousands of messages of a target, identify thematic patterns, extract named entities, detect relationships, summarize the relevant content, flag what merits human attention. Multimodal models can, moreover, transcribe and analyze audio at scale. The estimated processing-cost figure per target falls from hours of qualified labor to minutes of inference.
The consequence is structural. An intelligence service that before could spy industrially on two hundred targets can now, with the same staff, spy on twenty thousand. The operational constraints relax. The legal constraints —if any— become proportionally laxer because they're the only binding ones left.
This isn't speculative theory. The public-procurement documents of several U.S., British and European agencies during 2023 and 2024 specifically include systems for the mass processing of intercepted communications with language-model support. The integration is already underway. The total figures of surveilled targets remain under operational secrecy, but the budgets are public and show growing investment.
The political normalization
The most disturbing part isn't that an authoritarian regime uses Pegasus —that's to be expected—. It's that democratic governments buy and use it, too, against internal political opponents. The list of democratic states confirmed as buyers includes the United States (via the FBI and DEA, with added restrictions after 2021), Germany (BKA), the Netherlands (AIVD), Belgium, Poland (CBA until 2023, with documented use against opponents), Hungary, Mexico, Israel, India, Thailand and Spain.
The legal argument sustaining the use is always the same: fighting terrorism, drug trafficking, organized crime. The operational argument is similar: "we can't speak about specific targets for reasons of national security." The demonstrable balance is invariable: in addition to the uses described in the argument, there are uses against journalists and political opponents in most buying countries.
The normalization rests on three pillars. First, legislative opacity: the rules governing the use of spyware are general, they don't enumerate concrete products, and they leave wide margin to the executive. Second, weak parliamentary control: the official-secrets committees receive limited information, vote behind closed doors and rarely leak serious friction. Third, an uninformed public: most citizens don't know their government uses Pegasus, don't know the documented cases of abuse, and don't demand reforms because they have no frame.
The political question
This is personal opinion, but the accumulated public documentation supports it. The combination of commercially available military-grade spyware, democratic buying governments without robust parliamentary control, and generative-AI models that automate the analysis at industrial scale constitutes a technical and legal architecture for permanent mass spying. Not a future scenario: an operational present.
What isn't clear is what's done with the tool once it's routine. The history of surveillance technologies suggests that tools tend to be used to the limit of what's legal and, at times, beyond. The easier it is to spy on a hundred thousand people, the higher the probability that a hundred thousand people will be spied on. The presumption that only legitimate targets will be spied on rests, ultimately, on the political and professional will of the services operating the tool. That will varies with the political cycle, with social pressure, with shifting incentives.
What I'd ask for —and here with some hope, because there are regulatory precedents— is a specific European framework on spyware. Three minimum requirements. First, a ban on its use against journalists, lawyers, parliamentarians and members of the body politic itself except with specific judicial authorization with detailed justification. Second, an auditable public register —with reasonable declassification deadlines— of all infected targets, their legal authorization and the results obtained. Third, an independent mechanism of forensic technical review available to any citizen who suspects infection, similar to the one available for wiretap remedies. None of the three guarantees the elimination of abuse. All three make it operationally harder.
The concrete figure to close on. In May 2025, a federal jury in California ruled against NSO Group in the case WhatsApp Inc. v. NSO Group Technologies Limited, filed in 2019, ordering the company to pay roughly 167 million dollars in punitive damages and 444,000 dollars in compensatory damages for the infection of some 1,400 WhatsApp devices in 2019. That figure is the first significant court victory against NSO in a Western jurisdiction and, although small relative to the diffuse harm caused by a decade of use, it sets a legal precedent usable by future lawsuits. The commercial spyware industry will exist as long as governments keep buying it. That jurisprudence and rules exist to limit its use is the only structural defense available. Spain, as a buyer and as a victim, should lead that demand. It isn't.
Definitions
Spyware: a computer program designed to access a device without the user's authorization and extract information, monitor activity, control device functions. Pegasus is the best-known example.
Zero-click exploit: a technical vulnerability that allows a device to be infected without the user taking any conscious action, not even opening a message. These are the most expensive to develop and the most sought after by agencies.
Citizen Lab: an interdisciplinary academic laboratory at the University of Toronto, specializing in forensic research on spyware and state surveillance. Its work has been decisive in documenting the use of Pegasus.
Pegasus Project: an international journalistic consortium coordinated by Forbidden Stories in 2021 with the participation of 17 media outlets and the technical support of Amnesty International and Citizen Lab. It published an investigation documenting more than 50,000 possible targets.
References
Citizen Lab, CatalanGate: Extensive Mercenary Spyware Operation against Catalans Using Pegasus and Candiru (University of Toronto, April 2022). A technical report on the documented infections in the Catalan independence movement.
Forbidden Stories & Amnesty International, The Pegasus Project (July 2021). A joint journalistic investigation into the global reach of the software.
The Washington Post, coverage of the murder of Jamal Khashoggi and its connection to Pegasus (2018-2022).
National Cryptologic Center (CCN-CERT), official statement on the detection of Pegasus on the devices of Pedro Sánchez and Margarita Robles (May 2022). Institutional document.
WhatsApp Inc. v. NSO Group Technologies Limited, U.S. District Court for the Northern District of California, complaint filed in October 2019. Jury verdict in May 2025 with a penalty of roughly 167 million dollars.
Ronen Bergman, Rise and Kill First: The Secret History of Israel's Targeted Assassinations (Random House, 2018). A historical framework on the Israeli doctrine of intelligence and special operations, context for understanding the NSO ecosystem.
Amnesty International, Forensic Methodology Report: How to Catch NSO Group's Pegasus (Amnesty, July 2021). Technical documentation of the forensic method for detecting infections.
Further reading
Shoshana Zuboff, The Age of Surveillance Capitalism (PublicAffairs, 2019). A general framework on the economy and politics of contemporary digital surveillance.
Kate Crawford, Atlas of AI (Yale University Press, 2021). Chapters on the material and political infrastructures of AI surveillance systems.
Edward Snowden, Permanent Record (Metropolitan Books, 2019). Testimony on the architecture of U.S. mass surveillance pre-AI, a basis for understanding the leap generative AI now enables.
John Scott-Railton et al., academic publications at citizenlab.ca/publications. A continuous archive of Citizen Lab's research.
You might also like
- On the Taylor Swift deepfake
- The 25-million deepfake video-call fraud in Hong Kong
- Let's talk about the Kenyan annotators behind ChatGPT

Comments0
No comments yet.
Leave a comment