What you'll learn
Key ideas from Pegasus
These ideas compress the book's argument without treating the author's view as settled fact. Use them as an orientation before reading the full work or listening in Wiseley.
Pegasus was described as capable of silently opening broad access to an infected phone, including its private communications and sensors.
Antonio’s refusal and NSO’s stated safeguards sit alongside accounts of sales pressure and uncertain customer vetting.
A number in leaked data is a lead; verified identity and device evidence are separate steps.
Export licensing imposed formal limits, while executive discretion and secrecy made controversial sales hard to scrutinize.
A compromised journalist’s phone can expose risks to sources, family, colleagues, and private medical information, even when encrypted apps are used.
A five-day release across seventeen newsrooms paired right of reply with careful editing and evidence-bounded claims.
Replacement operators and continuing state demand allow the spyware market to persist after exposure.
Inside Pegasus
Read the first chapter in full here. The other 8 continue in the Wiseley app.
Chapter 1 of 9 · 7 min · Audio & text
The List and the Promise
Pegasus, by Laurent Richard and Sandrine Rigaud.
Pegasus mattered because of what a phone could reveal after a successful infection. The account describes software capable of defeating phone protections, including encryption, and opening access without the owner noticing. An operator could reach messages, calls, files, photographs, notes, browsing history, and location, and could remotely activate the microphone or camera. These are described capabilities of an infected phone. They do not tell us what happened to any particular number on a list.
NSO presented Pegasus as a tool licensed only to sovereign states for law enforcement and intelligence. The company said it helped prevent terrorism, crime, and child abuse, and had saved tens of thousands of lives. The account says the numbers for lives saved are impossible to verify. These remain company assertions; the stated purpose, by itself, cannot show that a particular use was lawful or that a particular person was infected.
A court case involving Princess Haya offered a specific account of alleged misuse. During child-custody proceedings in London, the case became public. The High Court later found that the phones of Haya, her lawyer Baroness Fiona Shackleton, and four people in their circle had been attacked with Pegasus. It found it more than probable that the surveillance had been carried out by servants or agents of Sheikh Mohammed bin Rashid Al Maktoum, the Emirate of Dubai, or the UAE. That qualified finding gave the investigators a documented case to consider, while leaving its attribution short of absolute certainty.
NSO sought to alert Haya through Cherie Blair and said it had prevented further access. The court accepted the company’s account that the United Arab Emirates’ access had been terminated, at a cost described in tens of millions of dollars. But the authors question whether that termination really happened. The episode shows why a company’s response, a court’s finding, and what investigators can independently establish must remain distinct.
The Haya case drew attention partly because the alleged targets included members of royal circles and a prominent lawyer, and partly because an outside cybersecurity researcher had found the attacks. It raised a larger question: did this case stand alone, or was it one visible example of wider surveillance? A source then gave two Paris journalists and two Berlin cybersecurity researchers access to data containing fifty thousand phone numbers and timestamps. The numbers were understood as phones selected for possible targeting by NSO clients. The disclosure turned a case-specific concern into a much broader lead.
But the list was initially a cipher. Most numbers had not yet been matched to names, and the timestamps stretched across nearly five years, reaching into the recent past. That timing led investigators to suspect that some activity might still be underway; it did not prove that surveillance was ongoing. Nor did inclusion establish that a phone had been infected, that Pegasus had been used, or who had chosen the number. Some entries might have related to genuine investigations of serious crime. Others might have pointed to abuse. The list alone could not decide between them.
This uncertainty mattered because previous investigations and warnings had exposed abuses in the surveillance industry without generating much public attention or meaningful limits on NSO. The new data seemed to offer a way to examine whether scattered cases formed a larger pattern. It also offered a way to test accusations and company claims against evidence. Yet the size of the leak could magnify an error as easily as a discovery. Treating all fifty thousand numbers as confirmed victims would have made the story less credible, not more.
The organization taking on that responsibility, Forbidden Stories, had a promise at its heart. The idea grew from journalist Khadija Ismayilova’s insistence that her colleagues finish and publish her investigations if she could no longer do so. Her request became a principle: threatening or silencing a journalist should not automatically end the reporting. Forbidden Stories carried that principle forward through collaboration, asking other journalists to help continue work that its original reporter could not safely complete.
The Pegasus assignment brought that promise into direct contact with source protection. The source who opened the way to the list was taking serious risks, and revealing the project could expose the source before the data had been understood. The team therefore kept the investigation secret, even from trusted people outside it. Secrecy was a condition for protecting the source and preserving the chance to investigate, not proof that the list was true. Trust in a source could begin the work, but it could not substitute for verification.
The scale of the material also exceeded what one small newsroom could examine alone. Forbidden Stories worked with Amnesty International’s Security Lab and a wider group of journalists. More than eighty reporters from seventeen media organizations joined the project across four continents. Their different reporting contexts and technical expertise made it possible to investigate a global set of leads while maintaining the source’s anonymity. That cooperation reflected the organization’s founding commitment, but it also made careful judgment essential: each new story still had to be supported by what the evidence could show.
The investigation began, then, with two connected obligations. The first was to carry threatened journalists’ work forward and protect the person who had trusted the team. The second was to resist turning a list of possible targets into a claim of confirmed infection. The promise explained why the team took on the work; the uncertainty in the data defined what it had to prove.
Chapter 2 of 9 · 13 min · Audio & textIn the app
How Pegasus Became a Market
Pegasus did not begin as a response to Mexico’s cartel war. Its commercial ancestor was software for ordinary phone support.
Chapter 3 of 9 · 10 min · Audio & textIn the app
Turning Leads Into Evidence
A leaked list gives investigators a place to begin, but each number raises questions. Who used it?
Chapter 4 of 9 · 9 min · Audio & textIn the app
The People Under Surveillance
Evidence that spyware reached a phone matters for more than proving a technical claim. A journalist’s phone also holds conversations, contacts, and source material.
Chapter 5 of 9 · 9 min · Audio & textIn the app
Power Behind the Product
To understand how Pegasus was built and sold, the account widens its focus beyond NSO. It describes a cyber sector shaped by Israel’s security priorities, military training, commercial opportunity, and a government preference for limiting regulation.
Chapter 6 of 9 · 7 min · Audio & textIn the app
When Evidence Sets the Standard
Some findings matter most where the evidence is hardest to complete. In the Pegasus investigation, a suspicious trace, an attempted attack, and a confirmed infection were different conclusions.
Chapter 7 of 9 · 10 min · Audio & textIn the app
Khadija and the Cost of Complicity
When Khadija Ismayilova reached Ankara in 2021, it was her first trip outside Azerbaijan since 2014. After imprisonment and years under a travel ban, she was finally reunited with friends and colleagues who had helped keep her reporting alive while she was unable to work freely.
Chapter 8 of 9 · 14 min · Audio & textIn the app
Verification Before Publication
As publication approached, the Pegasus Project faced a final test: decide exactly what each piece of evidence could support. The leaked numbers, the identities attached to them, signs of an attempted attack, and traces of a successful infection were different things.
Chapter 9 of 9 · 8 min · Audio & textIn the app
After the Revelations
The revelations did not end with publication. They set off new checks, corporate responses, government inquiries, and legal action.
Chapter 1 of 9 · 7 min · Audio & text: The List and the Promise
Wiseley supports reading and listening to summaries in the app.
Continue in Wiseley
