Āé¶¹“«Ć½

UK prime minister’s office smartphones targeted by Pegasus spyware

Researchers claim to have uncovered cyberattacks using Pegasus software against 10 Downing Street and the Foreign and Commonwealth Office
LONDON, ENGLAND - APRIL 12: A police officer walks past 10 Downing Street on April 12, 2022 in London, England. (Photo by Rob Pinney/Getty Images)
The prime minister’s residence and office at 10 Downing Street, London
Rob Pinney/Getty Images

The UK prime minister’s office was targeted multiple times by spyware sold legally to states around the world, claim security experts. The Pegasus software, created by the Israeli firm NSO Group, allows security services to listen in to the microphone on a compromised smartphone, read messages and access sensitive data.

The Citizen Lab, a research group at the University of Toronto in Canada that has worked for years to examine the use of spyware such as Pegasus, claims that it warned the UK government of attacks in 2020 and 2021.

The group says it has found evidence for multiple suspected Pegasus infections of devices used by the prime minister’s office andĀ what was then the Foreign andĀ Commonwealth Office (FCO), now the Foreign, Commonwealth and Development Office (FCDO). ItĀ claims that the spyware was being deployed against the FCO from the United Arab Emirates, India, Cyprus and Jordan, while the attacks against 10 Downing Street originated in the UAE.

Ron Deibert at the Citizen LabĀ said in a that the group’s main goal is to watch forĀ spyware use against non-governmental organisations, such as charities and aid groups, but that it sometimes finds evidence of state-on-state espionage andĀ would occasionally inform theĀ targeted nation if it believed itĀ could reduce harm to do so.

A by The New Yorker claims that the UK National CyberĀ Security Centre scanned numerous devices used by Downing Street staff, including aĀ smartphone used by Prime Minister Boris Johnson, once it had been informed of the attacks, but was unable to locate evidence of an intrusion. The report quotesĀ a Citizen Lab member whoĀ believes data was probably stolen, and says that the UK has been ā€œspectacularly burnedā€.

NSO, which was founded by former Israeli state surveillance operators, says it licenses customers to use its software ā€œonly for their lawful and necessary purposes of preventing and investigating terrorism and serious crimeā€. However, previous reports from the Citizen Lab revealed that Pegasus is being misused to watch journalists, academics and politicians.

Researchers have claimed that Pegasus has been used to hack the phones of journalists at as well as people at human rights organisation . In 2017, itĀ emerged that Mexico had beenĀ using the software to target journalists and their families. It was also suspected in attacks targeting Amazon founder Jeff Bezos and , who was murdered inĀ a Saudi Arabian consulate.

at internet security company ESET says that Pegasus and similar tools are often used byĀ governments to carry out espionage against other states. ItĀ can infect users remotely, without their knowledge.

ā€œOnce the software is placed onĀ a device, it can copy messages, view photos, record phone calls and even secretly view the user viaĀ the phone’s camera, and both Android and Apple phones are vulnerable,ā€ he says. ā€œPegasus canĀ be installed onĀ phones via a simple text message or through exploiting vulnerabilities on devices that can even deploy without requiring the user to click anything. High-profile people must be aware of the ease at which this can occur and must take precautions such as using a second device for official business and hold private meetings away from any device where possible.ā€

The FCDO and the prime minister’s press office told ±·±š·ÉĢż³§³¦¾±±š²Ō³Ł¾±²õ³Ł that they wouldn’t comment on matters relating to security. NSO Group didn’t respond to a request for comment.

Topics: Hacking / security