A/HRC/41/35 purchase sophisticated commercial spyware on the international surveillance market. 2 In the present report, the Special Rapporteur is most concerned with the last category of tools. Digital surveillance is no longer the preserve of countries that enjoy the resources to conduct mass and targeted surveillance based on in-house tools. Private industry has stepped in, unsupervised and with something close to impunity. According to Privacy International, in 2016 there were well over five hundred companies developing, marketing and selling such products to government purchasers.3 Types of surveillance considered in the present report 7. In the present report, the Special Rapporteur is principally concerned with technologies that enable an actor to gain surreptitious access to the digital communications, work product, browsing data, research, location history and online and offline activities of individuals. Key targeted surveillance technologies and practices are described below. Computer interference 8. Surveillance technologies may enable intruders to gain access to an individual’s computer or network. The range of such interference is substantial. 4 For instance, in 2017, an appeals court in the United States of America heard the case of foreign State-sponsored surveillance on United States soil.5 The case concerned a citizen of the United States born in Ethiopia and living in the state of Maryland who had been providing technical assistance to members of the Ethiopian diaspora community. A document originally sent to an activist by agents of the Government of Ethiopia infected his computer with an intrusive form of malware, a program called FinSpy marketed by a German-British company, Gamma Group.6 FinSpy allegedly recorded the man’s and his family’s Internet video calls, emails and other communications, including by logging his keyboard strokes, sending the data back to servers based in Ethiopia.7 Mobile device hacking 9. Private surveillance products also offer the capability of hacking directly into mobile devices. The NSO Group’s Pegasus spyware is a paradigmatic example and its alleged use in Mexico is instructive. Beginning in 2015, numerous individuals reporting on corruption and the drug trade received text messages or links on their mobile devices, some from seemingly legitimate sources suggesting detailed knowledge of the targets. Journalists, politicians, United Nations investigators, human rights advocates and others received these texts. A Canadian research and advocacy organization, Citizen Lab, found that the links infected the devices with the Pegasus spyware, allowing the targets to be monitored remotely. Citizen Lab has identified Pegasus software being used as a surveillance tool targeting individuals in 45 countries, including Bahrain, Saudi Arabia, Togo, the United Kingdom of Great Britain and Northern Ireland and the United States. 8 Social engineering 10. Many of the technologies described above are accompanied by strategies to lure a target into unwittingly downloading malware on their devices. For example, emails 2 3 4 5 6 7 8 4 Citizen Lab, Communities @ Risk: Targeted Digital Threats Against Civil Society (Toronto, Monk School of Global Affairs, University of Toronto, 2014), Executive Summary, pp. 8–11. Privacy International submission, p. 1. See, e.g., Ronald J. Deibert, Black Code: Inside the Battle for Cyberspace (Toronto, Signal, 2013), pp. 186–190. Doe v. Federal Democratic Republic of Ethiopia, 851 F.3d 7 (D.C. Cir. 2017). For FinSpy’s promotional material, see Wikileaks, “The spy files: remote monitoring and infection solutions: FINSPY”. For details of the allegations, see the first amended complaint, Doe v. Federal Democratic Republic of Ethiopia (18 July 2014). See Bill Marczak and others, “Hide and seek: tracking NSO Group’s Pegasus spyware to operations in 45 countries”, Citizen Lab, 18 September 2018.

Select target paragraph3

Connect to a paragraph
Connect to an entity
Disable highlights
Add to table of contents