Light bulb Limited Spots Available: Secure Your Lifetime Subscription on Gumroad!

Oct 04, 2026 · 8 min read

El Faro's Pegasus Lawsuit Against NSO Dismissed Again

On September 30, 2026, U.S. District Judge James Donato dismissed Dada v. NSO Group, the Salvadoran journalists' Pegasus case, for lack of personal jurisdiction. It is the second time he has thrown the case out, and the Knight First Amendment Institute says it will appeal again.

For almost four years, reporters from El Faro have tried to make NSO Group answer in an American courtroom for the spyware found on their iPhones. On September 30, a federal judge in San Francisco told them, for the second time, that they had come to the wrong place.

"None of this has anything to do with California," Judge James Donato wrote, according to Courthouse News. The ruling lands in the same courthouse where WhatsApp beat NSO in front of a jury in 2025. One Pegasus case got a trial. The other cannot get past the front door.

Key Takeaways

  • Judge James Donato of the Northern District of California dismissed Dada v. NSO Group on September 30, 2026, for lack of personal jurisdiction over the Israeli spyware maker.
  • El Faro employees were hit with at least 226 Pegasus infections between June 2020 and November 2021, according to the Knight First Amendment Institute, which filed the suit in November 2022.
  • Donato first dismissed the case in March 2024 on forum non conveniens grounds; the Ninth Circuit revived it on July 8, 2025, before this second dismissal.
  • WhatsApp's own suit against NSO reached a jury because Pegasus code passed through WhatsApp's servers in California, while El Faro's only California link was Apple, which Donato ruled is not the conduct being sued over.
  • The Knight Institute says it intends to appeal, which would send the case back to the Ninth Circuit for a second time.

What Did the Court Decide on September 30?

The court decided it has no power to hear the case at all, because NSO's conduct toward the El Faro journalists had no meaningful connection to California. The Knight Institute's case page records the September 30 order as a dismissal "for lack of personal jurisdiction."

In a 10 page ruling, Donato framed the dispute this way: "The gravamen of plaintiffs' claims is that NSO supplied spyware to an unnamed government outside the United States to access the Apple iPhones of plaintiffs working for a newspaper in El Salvador." The journalists had sued in Northern California because Apple is headquartered there and, they argued, NSO used Apple's servers to reach their phones. Donato was not persuaded. "Defendants' dealings with Apple's servers that may have been located in California do not constitute the conduct or claim for which plaintiffs seek redress," he wrote.

The ruling was reported by The Record on October 2. The plaintiffs had asked the court to order NSO to identify, return and delete everything it obtained through the attacks, and to name the client that ordered the surveillance. Neither request will be heard unless the dismissal is reversed.

How Did Dada v. NSO Group Get Here?

The case has now been dismissed twice and revived once in under four years. The Knight Institute timeline lays out the sequence:

  • November 30, 2022: The Knight Institute files suit on behalf of El Faro journalists and staff. It was the first case brought by journalists against NSO in a U.S. court. LatAm Journalism Review counted 15 plaintiffs, including 13 journalists.
  • March 8, 2024: Donato dismisses the case on forum non conveniens grounds. "The nub of this case is entirely foreign," he wrote, as reported by Courthouse News. "It belongs in a court in Israel or El Salvador, and not here."
  • July 8, 2025: A Ninth Circuit panel reverses. Judges Jennifer Sung and Michael Simon found the district court "gave little to no deference to Plaintiffs' choice of forum," according to CyberScoop. Judge Bridget Bade dissented. The panel faulted Donato for overlooking that one plaintiff is a U.S. citizen and two are U.S. residents.
  • September 11, 2025: NSO files a renewed motion to dismiss.
  • September 30, 2026: Donato dismisses again, this time on personal jurisdiction, a different doctrine from the one the Ninth Circuit reviewed in 2025.

That last point is the procedural story. Forum non conveniens asks whether another country's courts would be a better place for a case the U.S. court could hear. Personal jurisdiction asks whether the U.S. court can hear it at all. The Ninth Circuit's deference to the American plaintiffs did not carry over to the new question.

What Did Pegasus Do to El Faro?

Pegasus gave an unknown operator remote, silent access to the phones of most of El Faro's newsroom for well over a year. The Knight Institute says El Faro employees suffered at least 226 infections between June 2020 and November 2021, during which "their iPhones were accessed remotely and surreptitiously, their communications and activities were monitored, and their personal data was accessed and stolen." Courthouse News reports that at least 22 of El Faro's 35 employees were compromised.

Spread across those 17 months, 226 infections works out to roughly one new compromise every two to three days. The attacks were first documented in January 2022 by the Citizen Lab at the University of Toronto in its Project Torogoz report, which confirmed "35 cases of journalists and members of civil society whose phones were successfully infected." The report found the hacking "took place while the organizations were reporting on sensitive issues involving the administration of President Bukele." Access Now, which worked on the investigation, described "a single device reinfected over 40 times."

Empty newsroom desk at night with a smartphone face down beside a reporter's notebook, a courthouse visible through the window

Why Did WhatsApp's Case Survive When El Faro's Did Not?

WhatsApp's case survived because the hacked machinery sat in California: NSO pushed Pegasus code through WhatsApp's own servers there. In the December 2024 liability ruling, summarized by Columbia University's Global Freedom of Expression project, Judge Phyllis Hamilton found that NSO "caused a digital transmission to enter California, which then effectuated a breaking and entering of a server in California." The evidence showed the code passed through those servers 43 times in May 2019. NSO had also agreed to WhatsApp's terms of service, then broke them by reverse engineering the app.

The result was a trial. In May 2025 a jury ordered NSO to pay $167,254,000 in punitive damages and about $444,719 in compensatory damages, TechCrunch reported. In October 2025 Hamilton cut the total to roughly $4 million by capping punitive damages at a 9 to 1 ratio, but granted a permanent injunction barring NSO from targeting WhatsApp users, according to the Business and Human Rights Resource Centre. We covered how WhatsApp later caught NSO running a new Pegasus campaign after that injunction took effect.

Put the two rulings side by side and the asymmetry is plain. When a platform is the victim, its California servers are the crime scene. When a journalist is the victim, the crime scene is a phone in San Salvador, and California servers that carried the attack are just infrastructure. Most coverage frames this as a loss for El Faro. The bigger precedent is that, under Donato's reasoning, the people Pegasus is aimed at have a weaker path into U.S. court than the companies whose apps it travels through. Unless that changes on appeal, victims abroad depend on a platform choosing to sue. That discovery is already paying off: Amnesty's October 1 report used NSO documents from the WhatsApp case to map how Morocco's DGST aimed Pegasus at 22 journalists.

What This Means for Your Inbox

A phone infected with mercenary spyware exposes every account signed in on it, including any email app signed into a newsroom or personal account. The Knight complaint describes monitored communications and stolen personal data.

Email is also how many targets first learn they were hit. Apple's threat notification support page says alerts arrive on the lock screen, by email to the Apple Account address, and as a banner at account.apple.com, and that Apple has notified users in over 150 countries since 2021. Apple also says these notifications "never ask the user to click any links, open files, install apps or profiles, or provide an Apple Account password or verification code." That sentence is your phishing filter: an "Apple security alert" in your inbox that asks you to click is not from Apple. We explained how to read these alerts in our piece on Apple's spyware warnings to targets in 110 countries.

What Should Journalists Do Now?

Journalists in high risk beats should harden their phones now rather than count on a court to make spyware vendors pay later. Concrete steps:

  1. Turn on Lockdown Mode. Apple calls Lockdown Mode "an optional, extreme protection" for people targeted because of who they are or what they do. It blocks most message attachment types, disables link previews, and blocks FaceTime calls from people you have not contacted in the past 30 days. It requires iOS 16 or later.
  2. Treat threat notifications as real, and verify them safely. Sign in at account.apple.com directly instead of clicking anything in an email. A genuine alert will show a banner there.
  3. Call for help early. Access Now's Digital Security Helpline is free for journalists and civil society, runs 24/7, supports ten languages, and says it responds to all requests within two hours. Apple itself points notified users there.
  4. Get a forensic check. Amnesty International's Mobile Verification Toolkit facilitates "consensual forensic analysis of Android and iOS devices." It is a technical tool, so pair it with the helpline's incident response.
  5. Separate devices and accounts. Keep source communications off the phone you carry to press events and border crossings, and keep the number of accounts signed in on that phone to a minimum. Neither step stops a determined operator, but both limit what one infected device exposes.

What Happens Next?

The next step is a second trip to the Ninth Circuit. "The court's decision is disappointing, but we intend to appeal," Carrie DeCell, senior staff attorney at the Knight Institute, said in the Institute's statement. "Spyware manufacturers that participate in the persecution of journalists shouldn't be able to operate with impunity."

The same appeals court is already holding NSO's challenge to the WhatsApp injunction. The Knight Institute lists that appeal, No. 25-7380, as fully briefed and awaiting an oral argument date, after civil society groups filed the amicus brief we covered in May. Between the two appeals, the Ninth Circuit will set the terms for both kinds of Pegasus victim: the platform whose servers were abused, and the journalists whose phones were the target.

Stop Email Tracking in Gmail

Spy pixels track when you open emails, where you are, and what device you use. Gblock blocks them automatically.

Try Gblock Free for 30 Days

No credit card required. Works with Chrome, Edge, Brave, and Arc.