
The UK prime ministerās office was targeted multiple times by spyware sold legally to states around the world, claim security experts. The Pegasus software, created by the Israeli firm NSO Group, allows security services to listen in to the microphone on a compromised smartphone, read messages and access sensitive data.
The Citizen Lab, a research group at the University of Toronto in Canada that has worked for years to examine the use of spyware such as Pegasus, claims that it warned the UK government of attacks in 2020 and 2021.
The group says it has found evidence for multiple suspected Pegasus infections of devices used by the prime ministerās office andĀ what was then the Foreign andĀ Commonwealth Office (FCO), now the Foreign, Commonwealth and Development Office (FCDO). ItĀ claims that the spyware was being deployed against the FCO from the United Arab Emirates, India, Cyprus and Jordan, while the attacks against 10 Downing Street originated in the UAE.
Advertisement
Ron Deibert at the Citizen LabĀ said in a that the groupās main goal is to watch forĀ spyware use against non-governmental organisations, such as charities and aid groups, but that it sometimes finds evidence of state-on-state espionage andĀ would occasionally inform theĀ targeted nation if it believed itĀ could reduce harm to do so.
A by The New Yorker claims that the UK National CyberĀ Security Centre scanned numerous devices used by Downing Street staff, including aĀ smartphone used by Prime Minister Boris Johnson, once it had been informed of the attacks, but was unable to locate evidence of an intrusion. The report quotesĀ a Citizen Lab member whoĀ believes data was probably stolen, and says that the UK has been āspectacularly burnedā.
NSO, which was founded by former Israeli state surveillance operators, says it licenses customers to use its software āonly for their lawful and necessary purposes of preventing and investigating terrorism and serious crimeā. However, previous reports from the Citizen Lab revealed that Pegasus is being misused to watch journalists, academics and politicians.
Researchers have claimed that Pegasus has been used to hack the phones of journalists at as well as people at human rights organisation . In 2017, itĀ emerged that Mexico had beenĀ using the software to target journalists and their families. It was also suspected in attacks targeting Amazon founder Jeff Bezos and , who was murdered inĀ a Saudi Arabian consulate.
at internet security company ESET says that Pegasus and similar tools are often used byĀ governments to carry out espionage against other states. ItĀ can infect users remotely, without their knowledge.
āOnce the software is placed onĀ a device, it can copy messages, view photos, record phone calls and even secretly view the user viaĀ the phoneās camera, and both Android and Apple phones are vulnerable,ā he says. āPegasus canĀ be installed onĀ phones via a simple text message or through exploiting vulnerabilities on devices that can even deploy without requiring the user to click anything. High-profile people must be aware of the ease at which this can occur and must take precautions such as using a second device for official business and hold private meetings away from any device where possible.ā
The FCDO and the prime ministerās press office told ±·±š·ÉĢż³§³¦¾±±š²Ō³Ł¾±²õ³Ł that they wouldnāt comment on matters relating to security. NSO Group didnāt respond to a request for comment.