Facebook exposes mercenary spy firms that targeted 50,000 people

WASHINGTON 鈥 Facebook owner Meta Platforms Inc. is calling out half a dozen private surveillance companies for hacking or other abuses, accusing them in a听听published Thursday of collectively targeting about 50,000 people across its platforms.听听
The company鈥檚 fight with the spy firms comes amid a wider move by American tech companies, US lawmakers,听and President Joseph R. Biden, Jr.鈥檚 administration against purveyors of digital espionage services, notably the Israeli spyware company NSO Group, which was blacklisted earlier this month following weeks of听听about how its technology was being deployed against civil society.听听
Meta is already suing NSO in a US court. Nathaniel Gleicher, Meta鈥檚 head of security policy, told Reuters that Thursday鈥檚 crackdown was meant to signal that 鈥渢he surveillance-for-hire industry is much broader than one company.鈥澨听
听said it was suspending roughly 1,500, mostly fake accounts run by seven organizations across Facebook, Instagram, and WhatsApp. Meta said the entities targeted people in more than 100 countries.听听
Meta did not provide a detailed explanation of how it identified the surveillance firms, but it operates some of the world鈥檚 biggest social and communications networks and regularly touts its ability to find and remove malicious actors from its platforms.听听
Among them is Israel鈥檚 Black Cube, which became notorious for deploying its spies on behalf of Hollywood rapist Harvey Weinstein. Meta said the intelligence firm was deploying phantom personas to chat its targets up online and gather their emails, 鈥渓ikely for later phishing attacks.鈥澨听
In a statement, Black Cube said it 鈥渄oes not undertake any phishing or hacking鈥 and said the firm routinely ensured 鈥渁ll our agents鈥 activities are fully compliant with local laws.鈥澨听
Others called out by Meta include听BellTroX, an Indian cyber mercenary firm exposed by Reuters and the internet watchdog Citizen Lab last year, an Israeli company called Bluehawk CI, and a European firm named听Cytrox听鈥 all of whom Meta accused of hacking.听听
Cognyte, which was spun off from security giant Verint Systems Inc. in February, and Israeli firms Cobwebs Technologies were accused not of hacking but of using fake profiles to trick people into revealing private data.听听
Cognyte, Verint, and Bluehawk did not immediately return messages seeking comment.听听
In an e-mail, Cobwebs spokesperson Meital Levi Tal said the company drew on open sources and that its products 鈥渁re not intrusive by any means.鈥 Messages left with Ivo Malinovski 鈥 who until recently identified himself as听Cytrox鈥檚听chief executive on LinkedIn 鈥 received no immediate response.听BellTroX听founder Sumit Gupta has not returned Reuters reporters鈥 messages since his firm was exposed last year. He had previously denied wrongdoing.听听
Mr. Gleicher refused to identify any of the targets by name but Citizen Lab, in a听听at the same time as Meta鈥檚, said that one of听Cytrox鈥檚听victims was Egyptian opposition figure Ayman Nour.听听
Mr. Nour blamed the Egyptian government for the spying, telling Reuters in an interview from Istanbul that he had long suspected he was under surveillance by officials there.听听
鈥淔or the first time I have evidence,鈥 he said.听听
Egyptian authorities did not immediately respond to a request for comment.听听
Mr. Gleicher said other targets of the spy firms included celebrities, politicians, journalists, lawyers, executives and regular citizens. Friends and family of the targets were also swept up in the espionage campaigns, he said.听听
Meta cybersecurity official David听Agranovich听said he hoped Thursday鈥檚 announcement would 鈥渒ickstart the disruption of the surveillance-for-hire market.鈥 There were some signs that other social media firms were taking similar action, with Twitter announcing the removal of 300 accounts a few hours after Meta鈥檚 announcement.听听
Whether the takedowns deal the companies involved more than a temporary setback remains to be seen. Two of the companies, Black Cube and听BellTroX, have bounced back after being embroiled in previous spy scandals.听听
Mr. Gleicher said that targets of the spy firms would receive automated warnings, but he said Facebook would stop short of identifying the specific firms involved or their clients. That鈥檚 despite the fact that Facebook said it had identified several customers of Cobwebs,听Cognyte,听Cytrox, and Black Cube 鈥 the latter of which includes law firms.听听
Marta听Pardavi, one of several Hungarian human rights defenders who say they were targeted by Black Cube in 2017 and 2018, said she was gratified by the news of Facebook鈥檚 report but wanted more information.听听
鈥淭hey name law firms,鈥 she said. 鈥淏ut law firms have clients. Who are the clients for these law firms?” 鈥斕Raphael Satter and Elizabeth听Culliford/Reuters听


