TL;DR: On June 8, 2026 Meta disclosed that WhatsApp had caught and disrupted fresh spear-phishing campaigns and test-account infrastructure linked to NSO Group, the Israeli spyware vendor behind Pegasus.[1] The disclosure was published on Meta's newsroom on the same day, and Meta used it to announce that it will ask a US federal court to hold NSO in contempt of the permanent injunction Judge Phyllis Hamilton issued on October 17, 2025, barring NSO from using or accessing WhatsApp infrastructure for any reason.[1][2] Memeburn, which broke the secondary write-up on June 13, characterized the move as the first time a US court will be asked to enforce a standing spyware injunction against an active, named defendant whose new attack infrastructure has been caught on the platform the injunction was written to protect.[3] The contempt filing also lands the same week twelve civil-rights organizations filed amicus briefs opposing NSO's May 7 Ninth Circuit appeal of the underlying $167.25M verdict, and the same day Meta announced a major contribution to the Spyware Accountability Initiative (SAI), the civil-society coalition that has documented Pegasus abuse since 2018.[1] The "third round" framing in some coverage is shorthand for the new chapter in the same case. The case is now in its seventh calendar year, and the contempt filing is the first time Meta has had a court order it can hold NSO to, and the first time NSO has been caught on the record using the WhatsApp platform after that order was entered.
What Meta Disclosed on June 8
Meta's June 8 post on its company newsroom is the only primary source for the underlying technical events, and it is unusually specific for a corporate disclosure of this kind.[1] The post is signed by WhatsApp's leadership, not by a generic communications team, and it contains three concrete claims that anyone can verify against the public record.
First, WhatsApp says it "successfully disrupted NSO-linked social engineering attempts, after investigating user reports. They tried to trick people into clicking on malicious links to drive them to external websites outside of WhatsApp, similar to previously reported 1-click phishing campaigns linked to NSO."[1] This is the same attack pattern Citizen Lab and Lookout first documented in 2019, when NSO used a WhatsApp voice-call exploit to deliver Pegasus to roughly 1,400 users without any user interaction at all. The 2026 pattern is a step down in technical sophistication, and a step up in persistence: clicking the link takes the user outside WhatsApp, where the malicious site is hosted. End-to-end encryption does not protect against a user clicking a link on their phone, and that is exactly the seam NSO is now probing.
Second, WhatsApp says it "caught them creating test accounts and groups on WhatsApp, which we took down."[1] The test-account claim is the most legally consequential part of the disclosure. NSO is bound by the October 2025 injunction from "using or accessing WhatsApp servers, accounts, or infrastructure for any reason."[2] Creating a test account on WhatsApp is, on its face, using WhatsApp infrastructure. It does not matter whether the test account successfully delivered Pegasus. The injunction was written to bar the act of access, not the outcome of access.
Third, WhatsApp says it is "sharing threat indicators so that anyone can check if they were targeted by NSO-linked social engineering attempts across any platform: text message, email, WhatsApp message, or something else."[1] The threat-indicator share is Meta's most concrete contribution to the broader anti-spyware ecosystem this cycle, and the same model Citizen Lab and Apple used to notify victims of the 2019 attack. Meta is putting the infrastructure in place for cross-platform notification, which is the precondition for any future coordinated civil-society response.
The Injunction They're Trying to Enforce
The October 2025 injunction is the legal hook for everything Meta is doing this week, and it is worth reading carefully.[2] The injunction was issued by Judge Phyllis Hamilton of the US District Court for the Northern District of California on October 17, 2025, three months after a federal jury returned a verdict finding NSO liable for violating the Computer Fraud and Abuse Act and California state law in the May 2025 trial. The jury awarded Meta $444,719 in compensatory damages (the actual cost of the engineering work WhatsApp did to block the 2019 Pegasus exploit chain) and $167.25 million in punitive damages (the jury's signal that NSO's conduct warranted a deterrent-scale award). Hamilton reduced the punitive award to roughly $4 million in October 2025, applying a 9-to-1 ratio against the compensatory figure and citing Supreme Court precedent that punitive damages should not exceed compensatory damages by more than 4-to-1 in cases where the underlying conduct was not specifically targeted at the plaintiff.[2]
The injunction is the part NSO is fighting hardest, and the part that actually hurts. The October 17 order permanently bars NSO from "using or accessing WhatsApp servers, accounts, or infrastructure for any reason," and the Ninth Circuit is currently weighing NSO's argument that the injunction alone, even with the punitive award cut, will "force NSO out of business."[2] NSO told the court in its May 7 appellate brief that "code destruction" arising from the injunction "cannot be undone or remedied by money damages."[2] The contempt filing is now the second front in NSO's two-front appellate fight: the company is appealing the injunction on the merits, and it is now facing a motion in the trial court that it has violated the injunction while the appeal is pending.
Memeburn, in its June 13 secondary write-up, makes the legal-economic point cleanly: "That injunction may matter more than the money because it directly limits how NSO can operate around WhatsApp."[3] The contempt motion, if granted, is the first time a US court will be asked to enforce the injunction against an active defendant caught on the record continuing the conduct the injunction was written to bar. Reuters' June 8 wire-service report is the standing public record of the contempt filing itself.[4]
The 2019 Origin Story, and Why It Matters Now
The 2026 contempt filing is unintelligible without the 2019 origin.[1] In May 2019, Citizen Lab reported that WhatsApp voice calls had been used to deliver Pegasus to roughly 1,400 users across twenty countries. The exploit used a buffer overflow in WhatsApp's voice-call stack to install Pegasus without any user interaction, and Citizen Lab's forensic work traced the exploit chain to NSO Group infrastructure. WhatsApp sued NSO in November 2019, alleging violations of the Computer Fraud and Abuse Act and California state law. NSO's defense rested on two pillars: foreign sovereign immunity (NSO argued it was an agent of the Israeli government and therefore immune from suit), and the argument that Pegasus was a tool of foreign sovereigns and not a commercial product subject to US jurisdiction. Both defenses were rejected at the trial court level, the immunity defense was rejected at the Supreme Court in early 2024, and the case went to trial in 2025.
The 2025 jury verdict, the October 2025 injunction, and the May 2026 Ninth Circuit appeal are all the same case, in the same court, on the same docket. Memeburn's June 13 framing of "the third round" is shorthand for a new chapter in the same case, not a new lawsuit. The contempt filing is part of that new chapter, and it is the first time Meta has had the procedural tool to ask a court to enforce the October 2025 order against a defendant that has been caught on the record continuing the underlying conduct.[1][3]
The 12-Organization Amicus Coalition and the Spyware Accountability Initiative
Meta's June 8 post also names the civil-society infrastructure that has made the WhatsApp v. NSO arc possible.[1] "Last month," Meta writes, "we were joined by 12 prominent civil rights organizations, a coalition of security researchers, privacy advocates, and digital rights experts, who filed their amicus briefs to fight NSO's appeal against the permanent injunction."[1] The "last month" reference dates the amicus filings to May 2026, the same window as the Ninth Circuit appeal NSO filed on May 7. The amicus coalition is not named in the post, but the standing reference set is the same one that has been on the record in the case since 2019: Citizen Lab (the University of Toronto research group that first documented the 2019 Pegasus-on-WhatsApp attack), the Electronic Frontier Foundation, Access Now, the ACLU, Amnesty International, and the civil-society litigation tracking coalition that has filed amicus briefs in every prior round.
The same June 8 post announces a "significant contribution to the Spyware Accountability Initiative (SAI)," the civil-society coalition that supports forensic research, victim notification, and advocacy against commercial spyware.[1] SAI is the same coalition that funded the Citizen Lab work that led to Apple's billion-device security update, and that supported the Greek court case that produced the first-ever criminal conviction of spyware company executives earlier in 2026.[1] Meta's contribution is the first direct corporate funding SAI has accepted from a platform company, and it is the first time a major platform has institutionalized the civil-society infrastructure that has been doing the bulk of the forensic and victim-support work on commercial spyware.
The Litigation Is No Longer a Precedent. It Is a Recurring Incident.
The 2019 WhatsApp v. NSO case was the first time a major platform sued a commercial spyware vendor and won an injunction. The 2026 contempt filing is the first time that injunction has been put to the test against an active defendant caught in the act.[1][3] The pattern that has emerged across the seven-year arc is the standing pattern in commercial spyware more broadly: a vendor deploys, a victim is forensically documented, a case is filed, a verdict is won, an appeal is filed, the cycle repeats. The Greek court case that produced the first criminal conviction of spyware executives earlier in 2026 is the same pattern, in a different court, against a different vendor (Intellexa, the maker of Predator).[1] The pending French TCHAP encryption-backdoor push is the same pattern in a different policy venue.
Two structural facts make the 2026 contempt filing different from every prior round. First, the 2025 injunction is the first court order in any major commercial-spyware case to be written in terms that bar the act of access to a specific platform's infrastructure, not just the outcome of access.[2] The 2019 verdict was about the cost of the engineering work WhatsApp did to block the exploit. The 2025 injunction is about NSO's continued use of the WhatsApp platform. The contempt motion is the first test of the access-bar language. Second, the 12-organization amicus coalition is the first time a cross-platform civil-society coalition has filed on the merits of a commercial-spyware injunction, not just on damages or procedural posture. The amicus briefs are the standing record the Ninth Circuit will use when it rules on NSO's appeal of the injunction, and the contempt motion is now part of the same appellate record.
What It Means for You Today
Three groups are affected, and the consequences diverge.
If you are a WhatsApp user who has received a suspicious link in a chat in the last 30 days. The threat indicators Meta has released are the first place to look. The June 8 post links to the indicator feed, and Citizen Lab's standard practice is to provide a free forensic check for anyone who reports a suspicious link to its tipline.[5] The 1-click phishing pattern NSO is using in 2026 is the same pattern NSO has used in every prior round: the link lands on a page outside WhatsApp, and the page is the attack surface. End-to-end encryption does not protect against a user clicking a link on their phone. The protection is the same protection that has worked since 2019: do not click links in messages from people you do not know, and do not click links in messages from people you do know if the message is out of character. The threat model is not the platform, the threat model is the user.
If you are a civil-society researcher, journalist, or human-rights defender who has been a Pegasus target in the past. The Meta newsroom post is the first time a major platform has published a threat-indicator feed on the same day as the disclosure that triggered the feed. The June 8 post invites cross-platform checking. In Meta's own words: "across any platform: text message, email, WhatsApp message, or something else." That phrasing is the precondition for coordinated civil-society notification.[1] The SAI contribution Meta announced the same day is the funding vehicle for the next round of forensic work. The civil-society infrastructure that has documented Pegasus abuse since 2018 now has direct corporate funding from a platform company, and that funding is the most concrete shift in the spyware-accountability field in 2026.
If you are a commercial-spyware vendor, a commercial-spyware investor, a commercial-spyware regulator, or a government customer of a commercial-spyware vendor. The contempt motion is the first time the 2025 injunction has been put to the test. The injunction language is the part to read carefully: "using or accessing WhatsApp servers, accounts, or infrastructure for any reason."[2] That language is broad enough to cover the test-account creation Meta says it caught on the record. If the court grants the contempt motion, the financial penalty is the smaller of NSO's problems. The bigger problem is the precedent: the first court-ordered enforcement of a commercial-spyware injunction against an active, named defendant, in a case where the defendant has been caught on the record continuing the conduct the injunction was written to bar. The next round of commercial-spyware litigation will write around this precedent, or will rely on it. Both options are now on the table.
The Bottom Line
On June 8, 2026, WhatsApp disclosed that it had disrupted fresh spear-phishing campaigns and test-account infrastructure linked to NSO Group, and Meta announced that it will ask a US federal court to hold NSO in contempt of the October 17, 2025 permanent injunction.[1] The contempt filing is the first time the 2025 injunction has been put to the test against an active defendant caught in the act.[3] The 2025 injunction is the first court order in any major commercial-spyware case to be written in terms that bar the act of access to a specific platform's infrastructure, not just the outcome of access.[2] The 12-organization amicus coalition that filed against NSO's Ninth Circuit appeal of the injunction in May 2026 is the first cross-platform civil-society coalition to file on the merits of a commercial-spyware injunction, and Meta's June 8 announcement of a significant contribution to the Spyware Accountability Initiative is the first direct corporate funding SAI has accepted from a platform company.[1]
The "third round" framing in some coverage is shorthand for a new chapter in the same case. The case is now in its seventh calendar year. The contempt filing is the first time Meta has had a court order it can hold NSO to, and the first time NSO has been caught on the record using the WhatsApp platform after that order was entered. The litigation is no longer a precedent. It is a recurring incident, and the contempt filing is the first time the court has been asked to enforce the precedent against an active, named defendant.
Watch for three things over the next 30 days. First, the actual contempt motion filing in the Northern District of California, and the specific factual allegations the motion attaches to the test-account and spear-phishing incidents. Second, the Ninth Circuit's schedule for oral argument on NSO's May 7 appeal of the underlying injunction, and whether the contempt motion is consolidated into the appellate calendar. Third, the first SAI grant announcement funded by the Meta contribution, and the first forensic project the grant supports. The answers to those three questions will determine whether the 2026 contempt filing is a one-off or the standing pattern for every future commercial-spyware case.
Sources
- Meta Newsroom: "Fighting Spyware: An Update From WhatsApp" (June 8, 2026, primary source for the June 8 spear-phishing disruption, the test-account takedown, the contempt-of-court announcement, the 12-organization amicus coalition reference, and the Spyware Accountability Initiative contribution)
- State of Surveillance: "NSO Group Calls $167M WhatsApp Verdict Catastrophic" (May 8, 2026, the prior SOS piece on the October 17, 2025 injunction, the $167.25M to $4M punitive reduction, and the May 7 Ninth Circuit appeal, the standing context for the June 8 contempt filing)
- Memeburn: "WhatsApp catches fresh NSO spyware attacks in 2026" by Temaz Tra, June 13, 2026 (open-access secondary source that breaks down the contempt-of-court framing, the 1-click phishing pattern, and the South African user-protection angle)
- Reuters: "Meta takes legal action against Israeli spyware firm NSO Group" (June 8, 2026, paywalled, the wire-service report on the contempt filing; the Memeburn write-up cites the Reuters report on the $167M to $4M punitive reduction as the standing record of the damages history)
- Citizen Lab (Munk School of Global Affairs and Public Policy, University of Toronto), the standing primary source for the 2019 WhatsApp-Pegasus attack, the long-running NSO Group Pegasus research program, and the cross-platform victim-notification work that Meta's June 8 post explicitly cites. The standard reference set is searchable at citizenlab.ca/research.