What Haaretz Found
A Haaretz investigation published July 11, 2026 reports that a group of Washington consultants approached NSO Group about a month before President Trump announced Yehuda Kaploun's appointment as the U.S. Special Envoy to Monitor and Combat Antisemitism. Their pitch: hire a lobbyist who also served as Kaploun's personal attorney, use that proximity to the incoming envoy, and leverage it to help lift NSO's placement on the Commerce Department's Entity List. The asking price was $125,000. NSO rejected it.
Kaploun's appointment was announced in April 2025; he was confirmed by the Senate on a party-line 53-43 vote on December 19, 2025, and sworn in three days later. The lobbying approach, by Haaretz's account, predates all of that — the pitch traded on Kaploun's expected proximity to power, not on any formal authority he held or would ever hold over export licensing. That distinction matters for judging culpability. It does not make the episode less revealing about how NSO's American reentry campaign has operated.
Why NSO Is on the List
NSO Group has been on the Entity List since November 3, 2021, when the Commerce Department's Bureau of Industry and Security found the company had "developed and supplied spyware to foreign governments that used these tools to maliciously target government officials, journalists, businesspeople, activists, academics, and embassy workers." The designation imposes a license requirement on all U.S.-origin items exported to NSO, with a standing "presumption of denial" on any application — cutting the firm off from American software, cloud infrastructure, and hardware inputs it had previously relied on.
The case for keeping NSO listed is not hypothetical or stale. Human rights researchers, including the group DAWN, have documented Pegasus infections of journalists and activists years after the 2021 designation and argue NSO "has ample capacity to enforce compliance" through the licensing and maintenance relationships it retains with client governments, but chooses not to exercise it. In October 2025, a federal judge in California entered a permanent injunction barring NSO from targeting WhatsApp, after a jury found the company liable for exploiting the platform to install Pegasus on users' devices; the court cut a $167 million punitive award to just over $4 million but left the injunction and underlying liability finding intact, and NSO's pending Ninth Circuit appeal does not stay it. By mid-2026, WhatsApp was telling the court NSO-linked activity had resumed anyway — precisely the pattern the Entity List exists to punish, not paper over.
A Legitimate Case for Review, Pursued the Wrong Way
None of this puts the Entity List beyond scrutiny. Reasonable critics can argue that a five-year-old blanket designation, applied without a formal sunset review or a defined compliance pathway back to good standing, gives a company like NSO little incentive to reform if delisting is functionally unreachable regardless of behavior. Israeli officials pressed Washington on exactly this as early as 2022, arguing that isolating one firm does little to govern the broader lawful-intercept market Pegasus competes in, and that a narrower, conduct-based licensing regime might police misuse more effectively than a categorical ban. NSO's ownership has also genuinely changed: American investors led by Hollywood producer Robert Simonds acquired the company in October 2025, wiped out roughly $600 million of its debt, and installed former U.S. Ambassador David Friedman as chairman that November — facts a serious Commerce Department review should weigh, not dismiss on reputation alone.
But there is a real difference between petitioning Commerce through the actual delisting process and paying $125,000 to rent influence with an incoming envoy whose job has nothing to do with export licensing. Kaploun was nominated to monitor antisemitism, not to run BIS or shape the Entity List. The pitch consultants brought NSO wasn't a policy argument for reconsideration — it was proximity for sale, dressed up as strategy. That NSO turned it down is the one detail in this story that reflects well on the company's judgment, even as its broader Washington spending on lobbyists and public-relations firms, disclosed in the Justice Department's Foreign Agents Registration Act filings NSO has made for years, shows how much commercial weight rides on regulatory relief.
The Standard That Should Apply
Export controls on offensive cyber tools exist because the harm is real, transnational, and often invisible until a journalist's or dissident's phone turns up compromised. NSO's own record since 2021 — the WhatsApp verdict, the 2026 contempt allegations, the cases DAWN has documented — gives Commerce ample grounds to keep licensing decisions tied to conduct rather than to who a company can reach informally in Washington. If NSO's new ownership wants relief, the credible route is a transparent compliance record, independent audits of end-use by client governments, and enforceable public commitments — backed by the same courts that just enjoined it — not access purchased through an unrelated appointee's incoming personal attorney. Congress and BIS should treat this episode as reason to formalize a public, criteria-based delisting review, so companies compete on demonstrated compliance rather than on connections. That standard would serve both a healthy export-controlled tech sector, which benefits from predictable rules, and the human rights case for keeping genuinely abusive surveillance vendors out of the U.S. supply chain.