What the court did
The U.S. District Court for the Northern District of California has dismissed Dada v. NSO Group for lack of personal jurisdiction. The Knight First Amendment Institute's case page dates the dismissal order to September 30, 2026, and The Record reported it on October 2. Journalists at El Faro, the Salvadoran outlet, say Pegasus was used against them at least 226 times between June 2020 and November 2021. The Knight Institute filed the suit on November 30, 2022. It was the first suit against NSO Group by journalists in a U.S. court.
The Knight Institute says it intends to appeal. The Record's account of the order says the plaintiffs argued California was a proper forum because the attacks relied on infrastructure in the state. I could not retrieve the order's reasoning, so this piece does not characterize the judge's analysis beyond what those sources report.
The procedural history matters
This is the second dismissal. In March 2024 the district court threw the case out on forum non conveniens grounds. On July 8, 2025, the Ninth Circuit vacated that ruling, holding the district court had abused its discretion. It reasoned that NSO allegedly carried out the attacks by creating Apple ID accounts and engaging with Apple's California-based servers. NSO then filed a renewed motion to dismiss on September 11, 2025, which has now succeeded on the narrower ground of personal jurisdiction.
So the plaintiffs have spent nearly four years without any court reaching the merits: whether selling a zero-click intrusion tool to a government that then targets journalists is actionable under U.S. law.
The strongest case for the court's caution
The jurisdictional rules the court is applying are not arbitrary. Personal jurisdiction protects defendants from being hauled into courts with no real connection to them, and U.S. judges are wary of becoming a global forum for disputes between foreign nationals, a foreign vendor, and a foreign government's conduct. There is also a legitimate concern about courts second-guessing foreign sovereigns' intelligence and law-enforcement activity. Those worries are the reason doctrines like forum non conveniens and minimum contacts exist, and a speech-protective publication should not wish them away merely because the defendant is unsympathetic.
Why the outcome is still a problem
The difficulty is that the cost of that caution falls entirely on the targeted. El Faro's reporters are exactly the people a free-expression framework should protect: the Knight Institute says the attacks grew more frequent in the days before major investigations were published. If a vendor can build and operate the intrusion chain, partly through U.S.-based technology, and still be beyond the reach of U.S. courts, there is no private remedy for the victims. The goals the plaintiffs sought were modest: deletion of the collected data and disclosure of the client that ordered the surveillance.
This does not mean courts should be open to every claim. Evidence-based regulation means targeting the vendor-side conduct that actually causes harm, not punishing the open internet or legitimate security research. Commercial spyware sold to governments with documented records of abuse is a narrow, identifiable category.
What is actually working
Two other U.S. levers show the picture is not empty, though neither helps El Faro directly.
First, export controls. On November 4, 2021, the Commerce Department's Bureau of Industry and Security added NSO Group and Candiru to the Entity List, stating they supplied spyware to foreign governments that used it to target journalists, activists and others. The listing imposes a license requirement with a presumption of denial. That is a proportionate, targeted tool: it constrains a specific vendor without restricting security research or general-purpose software.
Second, platform litigation. In WhatsApp v. NSO Group, Judge Phyllis Hamilton granted a permanent injunction on October 18, 2025 barring NSO from targeting WhatsApp users, while cutting damages from $167.3 million to $4 million. CyberScoop reports the injunction covers only WhatsApp, not other Meta products, and does not restrict NSO's customers' use of its technology. NSO has appealed.
The contrast is instructive. WhatsApp could sue because the company is a U.S. platform whose servers were abused. Individual journalists abroad, whose phones were the target, face a much harder path.
What a proportionate response looks like
Nothing here requires a sweeping new regime. Three narrow steps would fit the evidence:
- Let the appeal run. The Ninth Circuit has already corrected one overreach in dismissal once; appellate review of the jurisdiction question is the system working as intended.
- Keep export controls targeted and evidence-based. Entity List decisions should rest on documented abuse by named vendors, with clear paths to delisting for companies that change behavior, so the tool does not chill legitimate security work.
- Clarify jurisdiction by statute only if courts keep splitting. If U.S.-based infrastructure used in an attack is not enough for jurisdiction, Congress can decide whether it should be. That should be a deliberate, narrow choice, not a side effect of procedural dismissals.
The free-expression stakes are real. Surveillance of reporters chills sources and suppresses the journalism that holds governments accountable. But a free and open internet is also defended by rules of the road that courts can apply predictably. Right now, the predictable result is that vendors face targeted U.S. sanctions and platform suits, while the journalists they surveil face a closed courtroom door.