Pegasus Spyware Used for Unauthorized Surveillance of Spanish Politicians and Activists

Thumbnail Image

The information displayed in the AIM should not be reported as representing the official views of the OECD or of its member countries.

The AI-powered spyware Pegasus, developed by NSO Group, was used to hack the phones of Spanish politicians and activists, including Catalan leaders. Citizen Lab revealed this marked the first known use of Pegasus against European officials, resulting in serious privacy violations and unauthorized surveillance.[AI generated]

Why's our monitor labelling this an incident or hazard?

The article details the use of Pegasus spyware, which employs AI techniques to infiltrate encrypted communications and access mobile phone content without user interaction. This has resulted in unauthorized surveillance of politicians, a clear violation of rights and privacy, fulfilling the criteria for harm under human rights violations. The AI system's use directly caused this harm. Therefore, this event qualifies as an AI Incident.[AI generated]
AI principles
Privacy & data governanceRespect of human rightsTransparency & explainabilityAccountabilityDemocracy & human autonomy

Industries
Digital securityGovernment, security, and defence

Affected stakeholders
GovernmentCivil society

Harm types
Human or fundamental rights

Severity
AI incident

Business function:
ICT management and information security

AI system task:
Other


Articles about this incident or hazard

Thumbnail Image

Citizen Lab considera 'preocupante' hackeo de teléfonos a políticos españoles

2020-07-16
www.diariolibre.com
Why's our monitor labelling this an incident or hazard?
The article details the use of Pegasus spyware, which employs AI techniques to infiltrate encrypted communications and access mobile phone content without user interaction. This has resulted in unauthorized surveillance of politicians, a clear violation of rights and privacy, fulfilling the criteria for harm under human rights violations. The AI system's use directly caused this harm. Therefore, this event qualifies as an AI Incident.
Thumbnail Image

Pegasus, el programa que ha hackeado a políticos catalanes y espió a periodistas y activistas por todo el mundo

2020-07-15
eldiario.es
Why's our monitor labelling this an incident or hazard?
Pegasus is an AI-enabled spyware system that uses sophisticated techniques to infiltrate mobile devices and extract sensitive information. Its deployment against civil society members, including politicians and activists, has directly caused violations of human rights and privacy. The article details confirmed infections and espionage activities, linking the AI system's use to realized harm. Therefore, this event qualifies as an AI Incident due to the direct harm caused by the AI system's use in unauthorized surveillance and rights violations.
Thumbnail Image

Citizen Lab considera "preocupante" hackeo de teléfonos a políticos españoles

2020-07-16
Agencia EFE
Why's our monitor labelling this an incident or hazard?
Pegasus is an AI-enabled spyware tool used for unauthorized surveillance, which constitutes a violation of human rights and privacy. The hacking of politicians' phones using this AI system has directly led to harm in terms of privacy violations and breaches of fundamental rights. Therefore, this event qualifies as an AI Incident due to the realized harm caused by the use of an AI system.
Thumbnail Image

Pegasus fue presuntamente usado para espiar a políticos e...

2020-07-15
Economía Digital
Why's our monitor labelling this an incident or hazard?
Pegasus is an AI system (spyware with sophisticated capabilities such as zero-click installation and data extraction) used to spy on individuals, including politicians and activists. The article details actual harm caused by its use, such as privacy violations and political espionage, which are breaches of fundamental rights. The involvement of the AI system in causing these harms is direct and material. Hence, this event meets the criteria for an AI Incident rather than a hazard or complementary information.
Thumbnail Image

Jefe investigador de Citizen Lab considera preocupante el jaqueo de teléfonos

2020-07-16
El Expresso
Why's our monitor labelling this an incident or hazard?
The article explicitly discusses the use of Pegasus, an AI-powered spyware system, to hack into mobile phones of politicians and activists, resulting in unauthorized surveillance and privacy violations. This constitutes a violation of human rights and harm to individuals and communities. The AI system's use directly led to these harms. Therefore, this event meets the criteria for an AI Incident rather than a hazard or complementary information.
Thumbnail Image

Torrent y Maragall pedirán al juez que el Gobierno desclasifique secretos para aclarar si el CNI espió sus móviles

2020-07-29
EL PAÍS
Why's our monitor labelling this an incident or hazard?
Pegasus is an AI system designed for surveillance and espionage, involving complex AI capabilities to exploit vulnerabilities and monitor targets. The article describes a concrete case where this AI system was allegedly used to spy on individuals, leading to violations of privacy and human rights. The harm is realized, not just potential, as the spying occurred and affected multiple individuals. The involvement of the AI system is direct and central to the incident. Hence, this event meets the criteria for an AI Incident under the OECD framework.
Thumbnail Image

NSO, la firma israelí con un poderoso spyware que invade móviles

2020-07-29
Infobae
Why's our monitor labelling this an incident or hazard?
Pegasus is an AI-powered spyware system that infiltrates mobile devices and extracts data covertly, enabling surveillance of individuals without consent. The article details its use against political leaders and activists, constituting violations of human rights and privacy. The harms described are realized and ongoing, including unauthorized access to communications and location data. The AI system's use directly leads to these harms, fulfilling the criteria for an AI Incident under violations of human rights and breach of legal protections. The article also mentions legal actions and governance issues but the primary focus is on the realized harm caused by the AI system's use.
Thumbnail Image

NSO, la firma israelí con un poderoso spyware que invade móviles

2020-07-29
Agencia EFE
Why's our monitor labelling this an incident or hazard?
Pegasus is a sophisticated spyware software that uses AI techniques for surveillance and intrusion into mobile devices. Its use against political dissidents constitutes a violation of human rights, specifically privacy rights. The article reports actual use of this AI system leading to harm (surveillance and violation of rights), thus qualifying as an AI Incident.
Thumbnail Image

NSO, la firma israelí con un poderoso spyware que invade móviles - Diario La Tribuna

2020-07-29
Diario La Tribuna
Why's our monitor labelling this an incident or hazard?
Pegasus is an AI-powered spyware system that infiltrates mobile devices to monitor and extract data without user consent. Its use against political figures, activists, and journalists constitutes a violation of human rights and privacy, fulfilling the criteria for harm under the AI Incident definition. The article details actual cases of such surveillance and legal actions, confirming realized harm rather than potential risk. Hence, the event is classified as an AI Incident.
Thumbnail Image

NSO, la firma israelí con un poderoso spyware que invade móviles

2020-07-29
Proceso Hn
Why's our monitor labelling this an incident or hazard?
Pegasus is an AI system designed for sophisticated surveillance and intrusion into mobile devices, involving AI techniques for exploiting vulnerabilities and extracting data covertly. Its use has directly caused violations of human rights and privacy, fitting the definition of an AI Incident under category (c) violations of human rights or breach of legal protections. The harms are realized and ongoing, with documented cases of spying on dissidents and activists. The article details these harms and the system's role, thus qualifying as an AI Incident rather than a hazard or complementary information.
Thumbnail Image

Pegasus, el programa israelí que nos espía sin dejar rastro

2020-07-30
Atlántico
Why's our monitor labelling this an incident or hazard?
Pegasus is an AI system designed for sophisticated surveillance and data extraction from mobile devices. Its deployment has directly caused harm by violating privacy and human rights of targeted individuals, including political figures and activists. The article details actual instances of misuse and harm, such as spying on Catalan leaders and activists, which fits the definition of an AI Incident. The involvement of AI in the spyware's operation and the resulting breaches of rights and privacy confirm this classification.
Thumbnail Image

NSO, la firma israelí con un poderoso spyware que invade móviles

2020-07-29
El Expresso
Why's our monitor labelling this an incident or hazard?
Pegasus is an AI system designed for sophisticated surveillance and intrusion into mobile devices. Its deployment has directly caused harm by violating privacy rights and enabling unauthorized surveillance of individuals, including political dissidents and human rights activists. These actions constitute violations of human rights and harm to communities. The article provides concrete examples and allegations of such harms occurring in multiple countries, including Spain and Saudi Arabia. Therefore, this event qualifies as an AI Incident due to the direct and significant harm caused by the AI system's use.
Thumbnail Image

Torrent i Maragall es querellen contra l'exdirector del CNI per l'espionatge dels mòbils

2020-07-30
CCMA
Why's our monitor labelling this an incident or hazard?
The spyware Pegasus is an AI system designed for surveillance and intrusion, and its use here led to direct harm by illegally accessing private communications of political figures, violating their human rights. The event describes realized harm (illegal espionage and communication interception) caused by the AI system's use. Hence, it meets the criteria for an AI Incident involving violations of human rights and breaches of legal protections.
Thumbnail Image

Torrent i Maragall es querellen contra l'exdirector del CNI per espionatge - ElNacional.cat

2020-07-30
ElNacional.cat
Why's our monitor labelling this an incident or hazard?
The Pegasus spyware is an AI system designed for covert surveillance and data extraction from mobile devices. Its deployment against political figures without judicial authorization directly violates rights to privacy, data protection, and communication secrecy, which are fundamental human rights. The spyware's use caused actual harm through illegal intrusion and monitoring, fulfilling the criteria for an AI Incident. The involvement of the AI system (Pegasus) in causing these harms is explicit and central to the event. Hence, this is classified as an AI Incident.
Thumbnail Image

Torrent i Maragall es querellen contra l'ex-director del CNI i NSO Group

2020-07-30
VilaWeb
Why's our monitor labelling this an incident or hazard?
The event involves the use of Pegasus, a software tool with AI capabilities for cyber espionage, to hack and monitor phones without authorization, violating privacy and communication rights. The spyware's use led to direct harm to individuals' rights and privacy, fulfilling the criteria for an AI Incident. The harm is realized, not just potential, and the AI system's role is pivotal in causing the harm. Hence, it is classified as an AI Incident.
Thumbnail Image

Torrent i Maragall es querellen contra l'exdirector del CNI i la propietària de Pegasus per espionatge i intrusió

2020-07-30
Regió 7
Why's our monitor labelling this an incident or hazard?
The event explicitly involves the use of Pegasus, a software tool with AI capabilities for surveillance and intrusion, which was used to spy on individuals without authorization. This led to direct harm in the form of illegal interception of communications and violation of privacy rights, fulfilling the criteria for an AI Incident under the OECD framework. The spyware's role is pivotal in causing these harms, and the event describes realized harm rather than potential harm. Therefore, it qualifies as an AI Incident.
Thumbnail Image

Torrent i Maragall es querellen contra l'exdirector del CNI per "espionatge"

2020-07-30
El Periódico de Catalunya
Why's our monitor labelling this an incident or hazard?
The Pegasus system is an AI-powered spyware tool used by state intelligence agencies to intercept communications. Its use in spying on political figures directly violates their rights and constitutes an AI Incident under the framework, as it involves harm to human rights through the use of an AI system. The event describes realized harm (espionage and interception of communications), not just potential harm, and thus qualifies as an AI Incident.