Pegasus Spyware Enables Global AI-Driven Surveillance and Rights Violations

Thumbnail Image

The information displayed in the AIM should not be reported as representing the official views of the OECD or of its member countries.

The Israeli company NSO's AI-enabled spyware Pegasus exploited smartphone vulnerabilities to conduct covert surveillance on activists, journalists, and political opponents worldwide. The system extracted private data undetected, leading to significant privacy breaches and human rights violations through unauthorized, automated data exfiltration.[AI generated]

Why's our monitor labelling this an incident or hazard?

Pegasus is an AI-related system that uses advanced automated hacking techniques to infiltrate smartphones and extract data covertly. Its use has directly led to violations of human rights and privacy through unauthorized surveillance, which is a clear harm. The article describes realized harm from the use of this AI system, not just potential harm. Therefore, this event qualifies as an AI Incident under the OECD framework because the AI system's use has directly led to significant harm to individuals and communities.[AI generated]
AI principles
AccountabilityPrivacy & data governanceRespect of human rightsTransparency & explainabilityDemocracy & human autonomy

Industries
Digital securityGovernment, security, and defence

Affected stakeholders
Civil society

Harm types
Human or fundamental rights

Severity
AI incident

Business function:
Other

AI system task:
Other


Articles about this incident or hazard

Thumbnail Image

¿Cómo se produce el espionaje (y se puede evitar) a través de Pegasus?

2021-07-19
infobae
Why's our monitor labelling this an incident or hazard?
Pegasus is an AI-related system that uses advanced automated hacking techniques to infiltrate smartphones and extract data covertly. Its use has directly led to violations of human rights and privacy through unauthorized surveillance, which is a clear harm. The article describes realized harm from the use of this AI system, not just potential harm. Therefore, this event qualifies as an AI Incident under the OECD framework because the AI system's use has directly led to significant harm to individuals and communities.
Thumbnail Image

Cómo se produce espionaje a través del programa Pegasus

2021-07-20
Listin diario
Why's our monitor labelling this an incident or hazard?
Pegasus is an AI-enabled spyware system that exploits smartphone vulnerabilities to spy on individuals, leading to violations of privacy and human rights. The article details how the spyware operates, the methods used to hack phones, and the resulting unauthorized data extraction. This clearly fits the definition of an AI Incident because the development and use of this AI system have directly led to harm in the form of human rights violations and breaches of privacy. Therefore, the event is classified as an AI Incident.
Thumbnail Image

Así funciona Pegasus, el software espía israelí que roba la información de tu celular

2021-07-19
EL UNIVERSO
Why's our monitor labelling this an incident or hazard?
Pegasus is an AI-enabled spyware system that autonomously exploits vulnerabilities in smartphones to extract sensitive data and control device functions covertly. The article details how it has been used to spy on vulnerable groups, causing direct harm through violations of privacy and human rights. The involvement of AI in the spyware's operation and the realized harm to individuals' rights meet the criteria for an AI Incident under the OECD framework.
Thumbnail Image

¿Cómo se produce el espionaje (y se puede evitar) a través de Pegasus?

2021-07-19
www.diariolibre.com
Why's our monitor labelling this an incident or hazard?
Pegasus is an AI system used for espionage that exploits smartphone vulnerabilities to extract sensitive user data covertly. Its deployment has directly caused violations of human rights, specifically privacy rights, by spying on individuals without consent. The article details realized harm from the use of this AI system, meeting the criteria for an AI Incident under violations of human rights and breach of legal protections. Therefore, this event is classified as an AI Incident.
Thumbnail Image

¿Cómo funciona el programa de espionaje Pegasus?

2021-07-19
El Universal
Why's our monitor labelling this an incident or hazard?
Pegasus is an AI-enabled spyware system that exploits smartphone vulnerabilities to spy on individuals, leading to direct violations of human rights and privacy. The article details how the spyware operates, the harms caused, and the sophisticated methods used, including zero-day exploits and automated data extraction. These factors demonstrate the development and use of an AI system that has directly led to significant harm, fitting the definition of an AI Incident.
Thumbnail Image

¿Cómo se produce el espionaje a través de Pegasus y cómo se puede evitar?

2021-07-19
Telemetro.com
Why's our monitor labelling this an incident or hazard?
Pegasus is an AI-enabled spyware system that uses sophisticated AI techniques to exploit vulnerabilities and extract data from smartphones without user knowledge. The article details how its use leads to direct harm by violating privacy and potentially other human rights. The involvement of AI in the spyware's operation and the resulting harm to individuals' rights and privacy meet the criteria for an AI Incident. The article also discusses mitigation but does not focus primarily on responses or governance, so it is not Complementary Information. The harm is realized, not just potential, so it is not an AI Hazard. Hence, the classification is AI Incident.
Thumbnail Image

¿Cómo es que Pegasus se infla en los teléfonos de sus víctimas?

2021-07-20
El Economista
Why's our monitor labelling this an incident or hazard?
Pegasus is an AI-enabled spyware system that exploits smartphone vulnerabilities to spy on individuals, leading to violations of privacy and human rights. The article details how Pegasus infiltrates devices, extracts data, and evades detection, causing direct harm to targeted users. This fits the definition of an AI Incident because the AI system's use has directly led to harm in the form of rights violations and unauthorized surveillance. The involvement of AI is explicit in the sophisticated exploitation and data exfiltration methods described.
Thumbnail Image

¿Cómo se produce el espionaje (y se puede evitar) a través de Pegasus?

2021-07-20
Gestión
Why's our monitor labelling this an incident or hazard?
Pegasus is an AI-enabled spyware system that exploits smartphone vulnerabilities to conduct unauthorized surveillance, leading to violations of human rights and privacy. The article details how the system is used to spy on individuals, causing direct harm through data theft and privacy breaches. This fits the definition of an AI Incident because the development and use of this AI system have directly led to harm (violation of rights). The discussion of mitigation measures and their limitations further supports the classification as an incident rather than a hazard or complementary information.
Thumbnail Image

Qué es Pegasus, el sistema de espionaje israelí que está en el centro de la polémica

2021-07-21
Diario La Prensa
Why's our monitor labelling this an incident or hazard?
Pegasus is an AI-enabled spyware system that directly causes harm by violating human rights and privacy through unauthorized surveillance and data extraction. The article details how the system operates, its use against vulnerable groups, and the resulting harm, fitting the definition of an AI Incident due to direct harm to rights and privacy caused by the AI system's use.
Thumbnail Image

Así actúa Pegasus, el software espía que infectó 50 mil celulares en

2021-07-20
Los Tiempos
Why's our monitor labelling this an incident or hazard?
Pegasus is an AI-enabled spyware system that has been used to conduct mass surveillance and espionage on thousands of individuals, including vulnerable groups such as journalists and human rights activists. The spyware's deployment has directly led to violations of fundamental rights and privacy, fulfilling the criteria for an AI Incident. The article details realized harm caused by the AI system's use, including unauthorized data extraction and surveillance, which constitute breaches of human rights and privacy protections.
Thumbnail Image

¿Cómo se produce el espionaje (y se puede evitar) a través de Pegasus? - Ensegundos.do

2021-07-19
José Peguero
Why's our monitor labelling this an incident or hazard?
Pegasus is an AI-enabled spyware system that exploits vulnerabilities in smartphones to spy on individuals, leading to violations of fundamental rights such as privacy and freedom of expression. The article details how Pegasus has been used to spy on activists and journalists, causing real harm. The involvement of AI in the spyware's operation and the resulting direct harm to individuals' rights meet the criteria for an AI Incident. The article also discusses mitigation measures but emphasizes that no protection is fully effective, reinforcing the seriousness of the harm caused.