The RecordEndpoint / Device

The Pegasus Project: spyware read journalists' phones after decryption

A 2021 global investigation confirmed NSO's Pegasus on the phones of journalists and activists, where it could read messages from any app once they were decrypted on the device.

01What actually happened

In July 2021, Forbidden Stories, Amnesty International's Security Lab, and 17 media organizations published the Pegasus Project, built around a leaked list of 50,000 phone numbers of interest. Forensic analysis confirmed Pegasus infections or attempts on dozens of the phones examined, including devices linked to people close to murdered journalist Jamal Khashoggi. Once installed, Pegasus reads any app's content on the device itself, so end-to-end encryption offers no protection.

02Why it matters

Endpoint compromise defeats every encrypted app at once, because the attacker sees the plaintext on the device. Cipher cannot defend an infected phone — the honest takeaway is that secure messaging must be paired with device security, not treated as a substitute for it.

Sources

We describe only what these sources report. If you think we've framed something inaccurately, tell us — accuracy is the whole point.

Cipher is built for exactly this gap: zero-access encryption, no phone number, on-device AI, and minimal metadata — so the failure in this story can't happen the same way.

See how the architecture works

Get on the list. Be early.

Join the waitlist and be among the first invited when Cipher opens.