The iPhones of at least nine US State Department employees were hacked by an unknown assailant using sophisticated spyware developed by the Israel-based NSO Group, according to four people familiar with the matter.
Follow Israel Hayom on Facebook and Twitter
The hacks, which took place in the last several months, hit US officials either based in Uganda or focused on matters concerning the East African country, two of the sources said.
The intrusions represent the widest known hacks of US officials through NSO technology. Previously, a list of numbers with potential targets including some American officials surfaced in reporting on NSO, but it was not clear whether intrusions were always tried or succeeded.
NSO Group said in a statement on Thursday that it did not have any indication their tools or the Pegasus software were used but canceled access for the relevant customers and would investigate based on the Reuters inquiry.
"If our investigation shall show these actions indeed happened with NSO's tools, such customer will be terminated permanently and legal actions will take place," said an NSO spokesperson, who added that NSO will also "cooperate with any relevant government authority and present the full information we will have."
NSO has long said it only sells its products to government law enforcement and intelligence clients, helping them to monitor security threats, and is not directly involved in surveillance operations.
Officials at the Uganda Embassy in Washington did not comment. A spokesperson for Apple declined to comment.
A State Department spokesperson declined to comment on the alleged hack, pointing instead to the Commerce Department's recent decision to place the Israeli company on an entity list, making it harder for US companies to do business with them.
NSO Group and another spyware firm were "added to the Entity List based on a determination that they developed and supplied spyware to foreign governments that used this tool to maliciously target government officials, journalists, businesspeople, activists, academics, and embassy workers," the Commerce Department said in an announcement last month.
NSO software is capable of not only capturing encrypted messages, photos and other sensitive information from infected phones, but also turning them into recording devices to monitor surroundings.
Apple's alert to affected users did not name the creator of the spyware used in this hack.
In a public response, NSO has said its technology helps stop terrorism and that they've installed controls to curb spying against innocent targets.
For example, NSO says its intrusion system cannot work on phones with US numbers beginning with the country code +1.
But in the Uganda case, the targeted State Department employees were using iPhones registered with foreign telephone numbers, said two of the sources, without the US country code.
Uganda has been roiled this year by an election with reported irregularities, protests and a government crackdown. US officials have tried to meet with opposition leaders, drawing ire from the Ugandan government. read more Reuters has no evidence the hacks were related to current events in Uganda.
A senior Biden administration official, speaking on condition he not be identified, said the threat to US personnel abroad was one of the reasons the administration was cracking down on companies such as NSO and pursuing new global discussion about spying limits.
The official added that the government has seen "systemic abuse" in multiple countries involving NSO's Pegasus spyware.
Sen. Ron Wyden, who is on the Senate Intelligence Committee, said: "Companies that enable their customers to hack US government employees are a threat to America's national security and should be treated as such."
Historically, some of NSO Group's best-known past clients included Saudi Arabia, the United Arab Emirates and Mexico.
The Israeli Ministry of Defense must approve export licenses for NSO, which has close ties to Israel's defense and intelligence communities, to sell its technology internationally.
In a statement, the Israeli Embassy in Washington said that targeting American officials would be a serious breach of its rules.
"Cyber products like the one mentioned are supervised and licensed to be exported to governments only for purposes related to counter-terrorism and severe crimes," an embassy spokesperson said. "The licensing provisions are very clear and if these claims are true, it is a severe violation of these provisions."
Subscribe to Israel Hayom's daily newsletter and never miss our top stories!