US court dismisses El Faro Pegasus suit against NSO Group
A California federal court dismissed the El Faro journalists' Pegasus-spyware suit against NSO Group for lack of jurisdiction; the Knight Institute says it will appeal.
A US federal court in the Northern District of California dismissed Dada v. NSO Group on September 30, ruling it lacks jurisdiction over the Israeli spyware maker for conduct that took place in El Salvador. The suit was brought by journalists and staff of the independent Salvadoran outlet El Faro, whose phones were infected with NSO's Pegasus zero-click spyware. The plaintiffs' counsel, the Knight First Amendment Institute, says it will appeal.
What the court ruled
The dismissal was on jurisdictional grounds: the court found the plaintiffs had not established that a California court could hear a case against a foreign company over targeting that occurred abroad. The plaintiffs had argued jurisdiction attached because the operation routed through US-based infrastructure, including Apple's iMessage delivery path. The court was not persuaded. The ruling was first reported by The Record.
The case
Per the Knight Institute, Pegasus was deployed against lead plaintiff Carlos Dada and El Faro colleagues at least 226 times between June 2020 and November 2021 — the period El Faro was reporting on the Salvadoran government's dealings with gang leadership. The suit was filed in November 2022. It is the first case brought against NSO Group in a US court by journalists.
This is the second time the case has been dismissed. An initial dismissal was vacated and remanded by the Ninth Circuit, which revived the suit before this latest ruling sent it out again on jurisdiction. Knight attorney Carrie DeCell said spyware manufacturers "that participate in the persecution of journalists shouldn't be able to operate with impunity, and U.S. courts must ensure they are held accountable for violations of U.S. law."
Why it matters
Jurisdiction, not the merits, is where NSO keeps winning against individual targets. The company has not had to defend the targeting itself in open court in this matter — the fight stops at whether a US court can hear the claim at all. That contrasts with WhatsApp v. NSO Group, the one US case that reached a merits verdict: a Northern District of California jury in May 2025 ordered NSO to pay roughly $168 million (about $167.25M punitive plus $447,719 compensatory) after the court found on summary judgment that NSO breached the CFAA and California hacking law in attacks on 1,400 WhatsApp users (CyberScoop). The distinction that keeps surfacing: suits anchored to a US platform's own infrastructure clear the jurisdictional bar; suits brought by foreign targets over foreign conduct do not, even when the delivery path touched US servers.
For high-risk users
Nothing here changes the mobile-threat picture for journalists, activists, and their IT support. Pegasus and its peers still rely on zero-click chains against messaging and media stacks. Concrete steps that remain worth taking:
- Enable Lockdown Mode on iOS/macOS for anyone in a plausible targeting set — it disables the attachment and link-preview paths these chains have historically abused.
- Patch on the day, not the week. Zero-click vendors burn exploits the moment a fix ships; the gap between patch and update is the exposure window.
- Keep a mobile forensic baseline. For at-risk devices, retain the ability to pull a sysdiagnose / backup for later analysis — Amnesty's MVT and the iOS
Shutdown.logartifacts have carried past Pegasus findings.
A court closing the courthouse door on jurisdiction does not shrink the attack surface. It just removes one of the few accountability levers targets had.