The Pegasus Project: spyware read journalists' phones after decryption
A 2021 global investigation confirmed NSO's Pegasus on the phones of journalists and activists, where it could read messages from any app once they were decrypted on the device.
01What actually happened
In July 2021, Forbidden Stories, Amnesty International's Security Lab, and 17 media organizations published the Pegasus Project, built around a leaked list of 50,000 phone numbers of interest. Forensic analysis confirmed Pegasus infections or attempts on dozens of the phones examined, including devices linked to people close to murdered journalist Jamal Khashoggi. Once installed, Pegasus reads any app's content on the device itself, so end-to-end encryption offers no protection.
02Why it matters
Endpoint compromise defeats every encrypted app at once, because the attacker sees the plaintext on the device. Cipher cannot defend an infected phone — the honest takeaway is that secure messaging must be paired with device security, not treated as a substitute for it.
Sources
- Washington Post · Jul 2021Takeaways from the Pegasus Project
- Amnesty International · Jul 2021Massive data leak reveals NSO Group's spyware used to target activists and journalists globally
We describe only what these sources report. If you think we've framed something inaccurately, tell us — accuracy is the whole point.
Cipher is built for exactly this gap: zero-access encryption, no phone number, on-device AI, and minimal metadata — so the failure in this story can't happen the same way.
See how the architecture works