Home › Intelligence › Brief
BREACH BRIEF🟠 High Breach

Judge Dismisses Pegasus Spyware Lawsuit Targeting Salvadoran Journalists

A California federal judge dismissed a lawsuit alleging that NSO Group's Pegasus spyware infected 226 times the phones of El Faro journalists. The case underscores the need for robust third‑party risk monitoring and audit‑ready evidence of vendor controls.

LiveThreat™ Intelligence · 📅 October 03, 2026· 📰 therecord.media
🟠
Severity
High
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
1 sector(s)
✅
Actions
2 recommended
📰
Source
therecord.media

Judge Dismisses Pegasus Spyware Lawsuit Targeting Salvadoran Journalists

What Happened — A U.S. federal judge in California dismissed a lawsuit filed on behalf of El Faro journalists whose phones were infected with the zero‑click Pegasus spyware. The plaintiffs alleged 226 infections between June 2020 and November 2021, but the court ruled the case lacked jurisdiction.

Why It Matters for Trust & Control Assurance

  • Demonstrates the risk of undisclosed third‑party surveillance tools infiltrating devices that handle sensitive information.
  • Highlights the need for continuous monitoring of vendor‑supplied software and evidence‑backed due‑diligence to prove that no hidden malicious components exist.
  • Aligns with a control objective around third‑party risk management—collecting, reviewing, and retaining assurance artifacts that satisfy multiple frameworks (e.g., NIST CSF 2.0, ISO 27001).

Who Is Affected — Media and journalism organizations, especially those operating in high‑risk political environments; broader implications for any entity relying on third‑party mobile applications.

Recommended Actions

  • Inventory all mobile applications and SDKs used by staff; verify provenance and conduct threat‑model reviews.
  • Implement continuous vendor‑risk monitoring, capturing contracts, security attestations, and real‑time threat intelligence feeds as audit evidence.
  • Prepare a defensible incident‑response playbook that includes evidence‑preservation steps for potential spyware detection.

Source: The Record

Technical Notes

  • Pegasus is a zero‑click exploit that leverages iOS/Android vulnerabilities to gain full device control without user interaction.
  • The attacks were timed to precede major investigative publications, indicating a strategic surveillance campaign.

Source: Knight First Amendment Institute

📰 Original Source
https://therecord.media/judge-dismisses-spyware-case-brought-by-salvadoran-journalists ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Vendor Risk Hub

Point-in-time vendor reviews miss incidents like this.

Verisq AI Trust Operations replaces the annual questionnaire with continuous third-party monitoring — so vendor exposure becomes audit evidence, not a once-a-year guess.

See how Verisq AI Trust Operations works →