Full Report
The plaintiffs, who all worked for the independent and Salvadoran news outlet El Faro, failed to convince the court that their case had jurisdiction in California, according to the judge’s order.
Analysis Summary
# Regulation/Compliance: Jurisdictional Requirements for Extraterritorial Surveillance Litigation
## Overview
This legal matter concerns the ability of foreign plaintiffs to hold surveillance technology manufacturers accountable in U.S. courts for actions occurring abroad. The core issue involves the "Personal Jurisdiction" requirement, specifically whether the use of U.S.-based cloud infrastructure by a foreign entity (spyware manufacturer) to target foreign citizens constitutes sufficient "minimum contacts" to allow a U.S. court to hear the case.
## Key Details
- **Issuing Authority:** U.S. District Court for the Northern District of California.
- **Effective Date:** Dismissal order issued October 2, 2026.
- **Jurisdiction:** United States (Federal Court), specifically affecting international cyber-litigation.
- **Status:** Final (at District level); Appeal pending.
## Requirements
### Mandatory Requirements
1. **Establishment of Jurisdiction:** To bring a suit in a specific U.S. state, plaintiffs must prove the defendant "purposefully availed" themselves of that state's laws or that the injury arose from activities directed at that state.
2. **Standing:** Plaintiffs must demonstrate a concrete injury that can be redressed by a U.S. court order.
3. **Territorial Nexus:** Under current rulings, the mere transit of data through U.S. servers (infrastructure) by a foreign actor targeting foreign victims may be insufficient to establish jurisdiction.
### Recommended Practices
1. **Infrastructure Documentation:** Organizations seeking to litigate against spyware manufacturers should document specific U.S. nodes, IP addresses, or services utilized in the attack.
2. **Alternative Jurisdictions:** Consider filing in the domestic jurisdiction of the manufacturer or the location where the command-and-control (C2) servers are physically managed.
## Affected Organizations
- **Industries:** Journalism, Human Rights Organizations, Surveillance Technology Manufacturers (e.g., NSO Group).
- **Organization Size:** All sizes (independent news outlets to multinational tech firms).
- **Geographic Scope:** International entities attempting to use U.S. courts for cyber-surveillance redress.
## Compliance Timeline
- **June 2020 – Nov 2021:** Period of alleged Pegasus spyware deployment.
- **Nov 2022:** Initial lawsuit filed (Dada v. NSO Group).
- **March 2024:** First dismissal based on the case being "entirely foreign."
- **October 2, 2026:** Final dismissal by California federal judge for lack of jurisdiction.
- **TBD:** Appellate court review (pending filing by Knight First Amendment Institute).
## Implementation Guidance
### Assessment Phase
- Evaluate if a cyber-attack leveraged specific U.S. infrastructure (e.g., California-based cloud providers).
- Determine if the "effects" of the attack were felt within U.S. territory.
### Implementation Phase
- Legal counsel must bridge the gap between technical "zero-click" exploits and the legal definition of "purposeful availment" in the chosen forum.
### Validation Phase
- Court review of jurisdictional discovery to see if the defendant’s contacts with the forum are "continuous and systematic."
## Technical Requirements
- **Forensic Analysis:** Identification of "zero-click" exploit chains.
- **Network Mapping:** Tracing data exfiltration paths to determine if compromised infrastructure was physically located in the United States.
- **Data Remediation:** Plaintiffs sought mandatory deletion of collected data and disclosure of the "Client" (Government) identity.
## Penalties & Enforcement
- **Dismissal:** Failure to meet jurisdictional standards results in the case being thrown out without a trial on the merits.
- **Enforcement:** If jurisdiction had been found, the court could have enforced injunctions requiring NSO Group to delete data and identify state-sponsored clients.
## Related Standards
- **Rule 12(b)(2) of the Federal Rules of Civil Procedure:** Motion to dismiss for lack of personal jurisdiction.
- **Foreign Sovereign Immunities Act (FSIA):** Often cited in spyware cases involving government clients (though not the primary focus of this specific dismissal).
## Resources
- **Official Documentation:** [https://storage.courtlistener.com/recap/gov.uscourts.cand.404482/gov.uscourts.cand.404482.108.0.pdf]
- **Knight First Amendment Institute Case Summary:** [https://www.knightcolumbia.org/cases/dada-v-nso-group]
## Practical Recommendations
- **Risk Assessment:** Journalists and NGOs operating abroad should recognize that U.S. courts may not provide a venue for redress even if U.S. technology/infrastructure is utilized in an attack.
- **Cyber Hygiene:** Implement high-assurance security measures (e.g., Lockdown Mode on iOS) to mitigate zero-click exploits, as legal recourse remains difficult.