Society & surveillance
The phone traces that exposed spyware marketed as leaving no trace
The strongest evidence came from devices and their timelines. A phone number on a list and a confirmed infection are different findings.
An invisible intrusion still has a history
A spyware investigation does not begin with a cinematic image of someone controlling a phone. It begins with small, ordinary records: a database entry, a process name, a network request, a file created at a particular time. Amnesty International's 2021 forensic report explains how those fragments supported findings of Pegasus infections.
Its case timelines connect suspicious activity to other artifacts on the same device. Some examples involve iMessage events followed by network requests and unfamiliar processes. The evidential strength comes from the sequence and corroboration, rather than the mere appearance of one alarming string. These are observations about particular examined devices at particular dates.
Three claims that need separate evidence
Selection, attempted compromise and successful compromise are not interchangeable. A number included in material associated with possible targeting does not establish that its phone was infected. An attack message establishes an attempt more directly, but still does not demonstrate execution. Traces of execution or a recovered payload support a different and stronger claim.
The reverse inference also needs care. Failure to find a trace cannot automatically clear a device: logging differs, records expire, and investigators may lack access to the necessary data. A negative result has meaning only in relation to the test's ability to detect what it is looking for. This is why a forensic report must describe its method as well as its conclusion.
What independent review added
Citizen Lab examined a sample of Amnesty's evidence independently. In its July 18, 2021 peer-review statement, the laboratory said it received backups and a methodology brief without additional context about the people or investigation. It validated Pegasus infection findings in four backups.
That exercise matters because another team could evaluate technical evidence without relying on a target's public profile or the story investigators expected to find. It remains a sample review. Four validated cases do not independently certify every number, device or political attribution connected to the larger investigation. Technical infection evidence and attribution to a particular customer require separate reasoning.
Read the date as carefully as the indicator
The report is a historical forensic account, not a current diagnostic guarantee. A vulnerability discussed as unpatched in July 2021 describes that moment. Software versions, attacker tools and available defensive evidence subsequently change. Repeating a historical version number without its date would turn a carefully bounded finding into a misleading present-day claim.
For readers, the most useful path is through a worked timeline and then the methodology. Ask which artifact was observed, what alternative explanation was considered, and what independent observation connects it to the proposed cause. The lesson reaches beyond spyware: confidence should grow from converging evidence, and the public claim should stop where that evidence stops.
Sources and further reading
- Forensic Methodology Report: How to Catch NSO Group's Pegasus ↗
Forensic Methodology Report, sections 6–7; device timelines pp 20–26
- Citizen Lab independent peer review, 18 July 2021 ↗
Opening review statement and four-backup validation