Spyware Vendors Still Operate Despite Sanctions and Court Orders
Meta's contempt filing against NSO Group highlights a commercial spyware industry that keeps thriving despite sanctions and court orders, as vendors keep selling, governments keep buying, and victims find out only after their phones are compromised.
On June 8, 2026, Meta filed a federal court contempt order against NSO Group, the Israeli surveillance vendor behind the Pegasus spyware tool, alleging that the company violated a permanent injunction barring it from targeting users of WhatsApp. Ars Technica reported that WhatsApp disrupted spear-phishing attempts linked to NSO, the same firm a U.S. district judge had already ruled against in a landmark 2024 decision. That decision, which found NSO liable for hacking WhatsApp users, was supposed to function as a hard boundary. The contempt filing six months into 2026 suggests the boundary functioned as a suggestion.
The Meta contempt filing is not an isolated episode. It lands in the middle of a larger, more disorienting shift in how the United States and its allies treat the commercial spyware industry. After years in which civil-society groups, Dark Reading reported in March, had built momentum through sanctions, lawsuits, and a Biden-era executive order restricting government use of spyware, that momentum now appears to be reversing. The vendors, their resellers, and their government customers are adapting faster than the constraints designed to rein them in.
The architecture of the commercial spyware industry has not fundamentally changed in the years since the Pegasus Project revelations of 2021 first mapped its reach. A small cluster of companies, primarily based in Israel, the European Union, and a handful of other jurisdictions, develop zero-click exploit chains that can remotely compromise a target's phone without any user interaction. These tools are sold exclusively to government agencies, on the premise that they will be used for serious criminal and national security investigations. The premise, by now, is documented fiction. Researchers at the University of Toronto's Citizen Lab have catalogued Pegasus infections on the phones of journalists, human rights lawyers, opposition politicians, and dissidents in dozens of countries. The same pattern has repeated with tools from Intellexa, whose Predator spyware TechCrunch reported was used against journalists and activists in Italy, and with Paragon Solutions, an Israeli firm whose Graphite tool has been linked to targeting civil society in multiple countries.
The United States spent much of the early 2020s positioning itself as the enforcer against these abuses. In November 2021, the Commerce Department added NSO Group and another Israeli firm, Candiru, to its Entity List, effectively banning American companies from exporting technology to them. In March 2023, the Biden administration issued an executive order prohibiting the operational use of commercial spyware by U.S. government agencies when that use posed counterintelligence, security, or human rights risks. The order was not a blanket ban, but it required agencies to inventory their spyware holdings and created an interagency review process. In February 2024, a federal judge in California ruled in favor of Meta in its lawsuit against NSO Group, finding that NSO had violated the Computer Fraud and Abuse Act and a California state law by deploying Pegasus against 1,400 WhatsApp users over a two-week period in 2019. The ruling included a permanent injunction barring NSO from using WhatsApp or its servers for any purpose.
The contempt filing alleges that NSO violated that very injunction. According to Reuters, Meta stated that it caught and disrupted spear-phishing attempts linked to NSO that were designed to install spyware on targets' devices through WhatsApp. The filing marks a new chapter in a legal battle that had already become the defining test case for whether a U.S. technology company can use the courts to discipline a foreign surveillance vendor. It also raises a starker question: if a permanent federal injunction backed by one of the largest corporations in the world cannot stop NSO from targeting WhatsApp users, what mechanism can?
The policy landscape on the U.S. government side has been shifting under the Trump administration in ways that suggest the enforcement posture is loosening. NPR reported in May 2026 that Immigration and Customs Enforcement acknowledged for the first time that its growing arsenal of surveillance technology includes spyware, tools that can remotely hack into phones. The disclosure came after months of pressure from civil liberties organizations and members of Congress who had been attempting to map the federal government's own procurement of commercial-grade intrusion tools. The NPR investigation, by reporter Jude Joffe-Block, found that ICE acting director Todd Lyons told lawmakers the agency had purchased Paragon Solutions' Graphite spyware for use in drug trafficking investigations.
The ICE acknowledgment exposed a contradiction at the center of U.S. spyware policy. The same government that had sanctioned NSO Group and placed it on an export blacklist was actively purchasing comparable technology from another Israeli vendor. Paragon Solutions, founded by former Israeli intelligence officers, markets Graphite as a lawful intercept tool designed for government use. But researchers and journalists have documented Graphite deployments against journalists and activists in multiple countries, raising the same abuse concerns that prompted sanctions against NSO. In May 2026, the Department of Homeland Security stated that ICE had "no current contract or relationship" with Paragon, a formulation that did not address whether the agency retained access to software it had already purchased or whether the relationship might resume.
The ICE-Paragon disclosure sits inside a broader reversal that Dark Reading catalogued in its March 2026 report. The article, by Jai Vijayan, noted that "despite a recent historic legal victory, the fight against commercial spyware may be trending in the wrong direction." The historic victory referred to was the Meta-NSO ruling. The wrong direction included signals from the Trump administration that it might ease restrictions on spyware vendors, particularly those with ties to allied intelligence agencies. Civil-liberties advocates quoted in the Dark Reading piece expressed alarm that the administration was considering lifting sanctions on NSO Group, a move that would effectively nullify one of the most significant enforcement actions the U.S. had taken against the industry.
The European theater has been no less turbulent. In April 2026, TechCrunch reported that Paragon Solutions was not cooperating with Italian authorities investigating spyware attacks against journalists and activists. WhatsApp and Apple had notified several people in Italy that they had been targeted with government spyware, and WhatsApp specifically identified Paragon as the vendor. The Italian probe was one of several European investigations into commercial spyware abuse that had been launched following the European Parliament's Pegasus inquiry and subsequent regulatory pressure. The lack of vendor cooperation complicated efforts to trace who had commissioned the attacks, a question that sits at the center of every spyware investigation.
Intellexa, the consortium behind the Predator spyware, has been another flashpoint. The U.S. Treasury Department sanctioned Intellexa and its founder, Tal Dilian, in March 2024, citing the tool's use to target Americans, including government officials, journalists, and policy experts. The European Union added Intellexa to its own sanctions list shortly afterward. Despite those sanctions, Metro reported in June 2026 that British officials had held talks with Intellexa representatives. The discrepancy between the public sanctions regime and the private diplomacy was not lost on researchers. It suggested that governments were maintaining a two-track approach to commercial spyware: public condemnation paired with quiet engagement, procurement, or evaluation.
The two-track dynamic is the defining feature of the commercial spyware market in 2026. Governments issue sanctions, and other government agencies buy the products. Courts issue injunctions, and the vendors allegedly violate them. Civil-society organizations run awareness campaigns, while spyware firms rebrand and open new sales offices. The underlying market incentive has not changed. A single spyware license can sell for millions of dollars. The zero-day exploits that power these tools are valuable precisely because they are unknown to the platform vendors who could patch them. The entire business model depends on a supply chain of vulnerabilities that is, by design, opaque and unregulated.
This opacity extends to what happens after a government agency purchases spyware. The typical data flow begins with a vendor building or acquiring an exploit chain, a sequence of software vulnerabilities that, when chained together, allows remote code execution on a target device. The vendor packages the exploit chain with a command-and-control infrastructure that lets the purchasing agency select targets, deploy the exploit, exfiltrate data, and manage the operation. In many cases, the vendor also provides operational support, sometimes including the actual deployment of the exploit. Once the target's phone is compromised, the spyware can extract messages, call logs, location data, passwords, and files. It can activate the microphone and camera. The data flows from the target's device to the purchasing agency's servers, often routed through the vendor's infrastructure. At no point in this chain does the target consent, know they are being surveilled, or have any mechanism to contest the intrusion.
The question of whose body produces the data and whose business buys it is not abstract. In May 2026, The Conversation published an analysis by researchers examining how democracies have become "the new digital authoritarians," exporting spyware and using it to surveil activists. The analysis noted that the problem is no longer confined to Moscow or Beijing. Democracies, the researchers argued, are not just customers of the surveillance industry; they are increasingly its architects, funding the development of intrusion tools through intelligence-agency budgets and then deploying them domestically against political opponents, journalists, and civil society.
The ICE disclosure illustrates this dynamic with unusual clarity. The agency told lawmakers it purchased Paragon's spyware for drug trafficking cases. But once a tool capable of full device compromise is inside a government agency, there is no technical mechanism that limits its use to the stated purpose. The same exploit that can extract a drug trafficker's messages can extract a journalist's sources, an immigration lawyer's client list, or a political activist's organizing network. The only constraint is the agency's internal policy, oversight mechanisms that are typically classified and opaque to the public, and the willingness of congressional committees to conduct meaningful oversight. On each of those fronts, the record in 2026 is thin.
The legal architecture that was supposed to contain the industry also shows deepening cracks. The Meta-NSO ruling, however historic, was a civil case brought by a private corporation. It established that NSO could be held liable under U.S. law for hacking WhatsApp users, but it did not establish criminal liability for the company's executives, nor did it create a mechanism for victims to seek redress outside of the U.S. court system. The sanctions regimes, while symbolically powerful, have proven porous. Intellexa continued to operate after U.S. and EU sanctions by restructuring its corporate entities and shifting operations to jurisdictions with weaker enforcement. The Biden executive order on government spyware use was an important norm-setting document, but it was not a statute. An executive order can be amended or rescinded by the next administration without congressional input.
Privacy and civil-liberties organizations have been tracking these developments with growing alarm. The Electronic Frontier Foundation, Access Now, and the European Digital Rights network have all published analyses documenting the gap between stated government policy on spyware and actual government practice. Their shared concern, articulated across multiple reports and public statements in the first half of 2026, is that the window for meaningful regulation is closing. The vendors are too profitable, too embedded in intelligence-agency workflows, and too adept at corporate restructuring for sanctions alone to be effective. Without binding legislation that criminalizes the sale and use of spyware for human rights abuses, the organizations argue, the cycle of exposure, sanction, and adaptation will continue indefinitely.
The contempt filing against NSO will test one theory of accountability: that private litigation can achieve what public regulation has not. If the federal court finds NSO in contempt, the remedies could include escalating fines, restrictions on NSO's ability to do business with U.S. entities, and potentially a referral for criminal prosecution. But the filing also highlights the limits of that theory. The alleged violation occurred despite a court order that was supposed to be definitive. NSO has consistently argued that it is not subject to U.S. jurisdiction because it acts as an agent of its sovereign government clients, a defense that invokes the same sovereign-immunity logic that has long shielded intelligence agencies from foreign court rulings. The contempt proceeding will force a U.S. court to decide whether that logic extends to the violation of its own injunctions.
For the people whose phones are the objects of this industry, the legal abstractions are beside the point. A journalist in Rome who learns from Apple that her device was targeted with Paragon's spyware does not get to cross-examine the Italian official who commissioned the attack. An immigration lawyer in Texas whose phone is compromised by a tool ICE purchased does not get a notification, because spyware is designed to leave no trace. The asymmetry is not a bug. It is the product.
What to watch for in the second half of 2026: the contempt ruling in Meta v. NSO Group, expected before the end of the year; whether the Trump administration formally rescinds or modifies the Biden executive order on spyware; whether any U.S. agency beyond ICE discloses spyware procurement, particularly the FBI and the Drug Enforcement Administration, both of which have been linked in previous reporting to spyware acquisition efforts; and whether the European Union moves beyond sanctions to direct regulation of the vulnerability supply chain that makes commercial spyware possible. The vendors have proven they can survive sanctions. The test now is whether they can survive a coordinated legal and legislative response. On the evidence of the first half of 2026, that response has not yet arrived at the scale or speed required.