Judge Dismissed Lawsuit Against NSO Group
A federal court ruled that it lacks jurisdiction over allegations involving Pegasus spyware on iPhones in El Salvador.
Updated on Sept. 30, 2026 in Cybersecurity

Live Poll
Should technology companies be held liable in domestic courts for spyware misuse occurring in other countries?
A federal judge has dismissed a lawsuit filed by journalists who alleged that NSO Group Technologies targeted their iPhones with Pegasus spyware. The court ruled that it lacks the legal jurisdiction to hear the case.
Why it matters
The ruling underscores the jurisdictional barriers often faced in cross-border litigation involving digital surveillance tools. It clarifies that interacting with U.S.-based servers alone may not be sufficient for plaintiffs to establish legal standing in California courts.
The case involved allegations of Pegasus spyware compromising iPhone devices. The court determined that the defendants' interaction with Apple servers in California was insufficient to establish jurisdiction.
The players
NSO Group Technologies
An Israel-based firm known for developing Pegasus, a software platform that provides remote surveillance capabilities for mobile devices.
James Donato
A United States District Judge presiding over federal cases in California.
The details
District Judge James Donato presided over the case, concluding that the connection between the alleged spyware deployment and California-based infrastructure did not provide grounds for legal standing. Pegasus is a sophisticated mobile surveillance platform capable of exfiltrating data and enabling remote control over host devices, but the judge found the plaintiffs' specific claims failed to meet the threshold for jurisdiction in this state.
Timeline
September 30, 2026: A federal judge dismissed the journalists' spyware lawsuit.
The Tech Race
The ruling follows legal precedents established in the Apple Inc. v. NSO Group Technologies litigation regarding the reach of U.S. courts in international digital privacy disputes. This decision delineates the boundaries for how third-party surveillance software providers may be held accountable under U.S. law.
This development clarifies the legal hurdles journalists and activists face when seeking redress for alleged spyware intrusions. It serves as a benchmark for future digital privacy litigation involving cross-border software deployment.
The takeaway
The dismissal demonstrates the difficulty of asserting jurisdiction in globalized digital surveillance cases. Interested parties should watch for future filings in alternative international venues where plaintiffs may seek to bypass these U.S. jurisdictional limits.
Further reading
For broader insights into how digital vulnerabilities are addressed in court, see our coverage of Cybersecurity.
Live Poll
Should technology companies be held liable in domestic courts for spyware misuse occurring in other countries?









