When you think of hacking, you probably imagine some nerd alone in a dark room staring into one of those old green and black screens.
He’s typing furiously for a bit until, suddenly, he says to himself, “…I’m in!”
Naturally, that’s not actually how it works.
Hacking takes a lot of time, and a lot of really talented people. A whole team of the world’s best hackers could spend months finding one little crack in the software of your average smartphone.
But that one crack is just enough to let them see everything on your phone: where you are, who you are talking to, what your camera can see… Yes, even your Candy Crush high score.
Finding the cracks
Big spying agencies like the NSA and GCHQ are some of the only organisations in the world that can hire – and pay – the huge teams of expert coders necessary to find those cracks faster than tech companies can patch them.
Hacking companies make software that can invisibly spy on anyone’s iPhone. Source: Associated Press
But smaller, less technically advanced countries want to spy on smartphones too. The question is, how?
It turns out the answer is pretty simple: they can outsource it.
‘Under the table’
And not just to shady characters on the back alley of the internet. Nowadays, hacking is a billion-dollar industry backed by the City of London and Wall Street.
Brian Bartholomew, a security analyst at Russia’s Kaspersky Labs, is the closest thing there is to a hacking market watcher. As he explains it, the industry has matured dramatically over the past few decades.
“The way that it used to be done was very under the table,” he says.
“A researcher maybe had their hands on something they had found. They wanted to make some cash. A government was looking for an exploit. They would broker a deal. Things would happen.”
Going mainstream
Like many cottage industries, though, it started to grow to meet demand. Smartphones were ubiquitous, and governments were clamouring to take advantage of their potential as eavesdropping tools.
“You had a lot of not developing countries as you would think of it but developing in their in their offensive capabilities,” Bartholomew says.
“A lot of the countries that wanted to get involved also had a lot of money. So it opened the market up for purchasing this stuff, making it easier and making a business out of it.”
Hacking companies even started exhibiting their tools at arms fairs. Source: Associated Press
The first truly mainstream players in this space were the Anglo-German Gamma Group, and the bluntly-named Hacking Team. Both were open about their work, even exhibiting at arms fairs.
In a stroke of poetic justice, however, both became themselves became the victims of hackers, and their clients’ information was spread around the internet.
‘The new hotness’
Stepping to the void was NSO, an Israeli-based firm started by some of the Israeli defence and intelligence establishment’s top brass.
They became, as Bartholomew calls the, “the new hotness” in the hacking-for-hire world.
Pegasus is NSO’s flagship hacking tool. It allows governments to invisibly gain full access to a subject’s smartphone.
With that access, they can spy on encrypted chat logs or even turn on the microphone to listen to a subject’s private conversations.
NSO has been much more secretive than the firms that came before it. What little we know about their work mostly comes from the investigative efforts of a Canadian academic named John Scott-Railton.
He and his team at the University of Toronto’s CitizenLab have found evidence of Pegasus being used in over a dozen countries, from Mexico to Thailand to Saudi Arabia.
Canadian academic John Scott-Railton uncovered NSO’s hacking tool Pegasus and its use against journalists and dissidents. Source: Associated Press
A billion-dollar business
Business is clearly booming at NSO. Their management team recently completed a management buyout that valued the company at $1 billion.
As if to show just how this industry is, the deal was backed by a British private equity fund called Novalpina and funded by Credit Suisse and the Wall Street bank Jefferies.
There are many legitimate uses for a tool like Pegasus. NSO declined our interview request.
But, in a statement, they said they had saved ‘thousands of lives’, helping authorities to ‘prevent terrorist attacks, stop drug and sex trafficking rings, and rescue kidnapped children.’
They also claim their tool was helped catch the notorious Mexican drug lord Joaquin ‘El Chapo’ Guzman.
NSO claims Pegasus was instrumental in helping capture the Mexican drug lord Joaquin Guzman, AKA ‘El Chapo’ Source: Associated Press
Lowering the bar
But selling these tools to whoever can afford them carries huge risks.
“What NSO is doing,” Scott-Railton says, “is lowering the bar for states to enter into the game of hacking phones.”
Scott-Railton and his team have found Pegasus on smartphones owned by Mexican MPs, Emirati activists and even associates of murdered Saudi journalist Jamal Khashogggi (NSO denies any involvement in Khashoggi’s death).
“What we’re seeing is that in cases where the technology is sold to countries that don’t have the safeguards, or where there’s a culture of lawlessness, there’s just a very high likelihood that the technology will be abused.”
These concerns may have started to rub off on NSO’s potential investors. There have been reports that Wall Street is shying away from backing the management buyout, leaving Jefferies and Credit Suisse holding the bag.
Credit Suisse and Wall Street bank Jefferies have reportedly found it difficult to get investors to back NSO and its controversial work. Source: Associated Press
But the fact remains NSO is now at the forefront of a mainstream hacking industry worth billions.
John Scott-Railton worries what this private sector proliferation of hacking tools means.
“The technology has always existed somewhere,” he says.
“The question is, ‘how many people have it and what are they using it for.'”
Submitted Article
Headline
Short Headline
Standfirst
Published Article
HeadlineThe City-funded hackers worth $1 billion
Short HeadlineThe City-funded hackers worth $1 billion
StandfirstForget shady characters in dark basements: computer hackers have gone corporate.
When you think of hacking, you probably imagine some nerd alone in a dark room staring into one of those old green and black screens.
He’s typing furiously for a bit until, suddenly, he says to himself, “…I’m in!”
Naturally, that’s not actually how it works.
Hacking takes a lot of time, and a lot of really talented people. A whole team of the world’s best hackers could spend months finding one little crack in the software of your average smartphone.
But that one crack is just enough to let them see everything on your phone: where you are, who you are talking to, what your camera can see… Yes, even your Candy Crush high score.
Finding the cracks
Big spying agencies like the NSA and GCHQ are some of the only organisations in the world that can hire – and pay – the huge teams of expert coders necessary to find those cracks faster than tech companies can patch them.
Hacking companies make software that can invisibly spy on anyone’s iPhone. Source: Associated Press
But smaller, less technically advanced countries want to spy on smartphones too. The question is, how?
It turns out the answer is pretty simple: they can outsource it.
‘Under the table’
And not just to shady characters on the back alley of the internet. Nowadays, hacking is a billion-dollar industry backed by the City of London and Wall Street.
Brian Bartholomew, a security analyst at Russia’s Kaspersky Labs, is the closest thing there is to a hacking market watcher. As he explains it, the industry has matured dramatically over the past few decades.
“The way that it used to be done was very under the table,” he says.
“A researcher maybe had their hands on something they had found. They wanted to make some cash. A government was looking for an exploit. They would broker a deal. Things would happen.”
Going mainstream
Like many cottage industries, though, it started to grow to meet demand. Smartphones were ubiquitous, and governments were clamouring to take advantage of their potential as eavesdropping tools.
“You had a lot of not developing countries as you would think of it but developing in their in their offensive capabilities,” Bartholomew says.
“A lot of the countries that wanted to get involved also had a lot of money. So it opened the market up for purchasing this stuff, making it easier and making a business out of it.”
Hacking companies even started exhibiting their tools at arms fairs. Source: Associated Press
The first truly mainstream players in this space were the Anglo-German Gamma Group, and the bluntly-named Hacking Team. Both were open about their work, even exhibiting at arms fairs.
In a stroke of poetic justice, however, both became themselves became the victims of hackers, and their clients’ information was spread around the internet.
‘The new hotness’
Stepping to the void was NSO, an Israeli-based firm started by some of the Israeli defence and intelligence establishment’s top brass.
They became, as Bartholomew calls the, “the new hotness” in the hacking-for-hire world.
Pegasus is NSO’s flagship hacking tool. It allows governments to invisibly gain full access to a subject’s smartphone.
With that access, they can spy on encrypted chat logs or even turn on the microphone to listen to a subject’s private conversations.
NSO has been much more secretive than the firms that came before it. What little we know about their work mostly comes from the investigative efforts of a Canadian academic named John Scott-Railton.
He and his team at the University of Toronto’s CitizenLab have found evidence of Pegasus being used in over a dozen countries, from Mexico to Thailand to Saudi Arabia.
Canadian academic John Scott-Railton uncovered NSO’s hacking tool Pegasus and its use against journalists and dissidents. Source: Associated Press
A billion-dollar business
Business is clearly booming at NSO. Their management team recently completed a management buyout that valued the company at $1 billion.
As if to show just how this industry is, the deal was backed by a British private equity fund called Novalpina and funded by Credit Suisse and the Wall Street bank Jefferies.
There are many legitimate uses for a tool like Pegasus. NSO declined our interview request.
But, in a statement, they said they had saved ‘thousands of lives’, helping authorities to ‘prevent terrorist attacks, stop drug and sex trafficking rings, and rescue kidnapped children.’
They also claim their tool was helped catch the notorious Mexican drug lord Joaquin ‘El Chapo’ Guzman.
NSO claims Pegasus was instrumental in helping capture the Mexican drug lord Joaquin Guzman, AKA ‘El Chapo’ Source: Associated Press
Lowering the bar
But selling these tools to whoever can afford them carries huge risks.
“What NSO is doing,” Scott-Railton says, “is lowering the bar for states to enter into the game of hacking phones.”
Scott-Railton and his team have found Pegasus on smartphones owned by Mexican MPs, Emirati activists and even associates of murdered Saudi journalist Jamal Khashogggi (NSO denies any involvement in Khashoggi’s death).
“What we’re seeing is that in cases where the technology is sold to countries that don’t have the safeguards, or where there’s a culture of lawlessness, there’s just a very high likelihood that the technology will be abused.”
These concerns may have started to rub off on NSO’s potential investors. There have been reports that Wall Street is shying away from backing the management buyout, leaving Jefferies and Credit Suisse holding the bag.
Credit Suisse and Wall Street bank Jefferies have reportedly found it difficult to get investors to back NSO and its controversial work. Source: Associated Press
But the fact remains NSO is now at the forefront of a mainstream hacking industry worth billions.
John Scott-Railton worries what this private sector proliferation of hacking tools means.
“The technology has always existed somewhere,” he says.
“The question is, ‘how many people have it and what are they using it for.'”
As e-bike riders weave through London’s busiest junctions, red lights are increasingly treated as optional. One software engineer says the problem may be baked into how hire firms charge users
Deliveroo has announced its sale to U.S. rival DoorDash, but concerns linger over the controversial ‘substitute’ feature at the heart of its operations.
Inside Success Union CIC claim to empower vulnerable young people, but allegations of underpayment and concerns over their fundraising practices are undermining their message.