# Spyware accountability through software liability framework

Published: 2025-09-30 · Severity: routine · Sectors: government-national, defense, media, non-profit, technology
Canonical: https://vorant.io/reports/e3725c04-09b0-5dc1-99b4-6d965565d8b6/spyware-accountability-through-software-liability-framework

> Atlantic Council proposes safe-harbor legislation to incentivize technology companies to detect and notify users of spyware infections by shielding them from products-liability suits.

This Atlantic Council report examines the failure of existing legal mechanisms to hold spyware vendors accountable for human rights abuses and national security harms. Over 80 countries have procured spyware tools targeting journalists, activists, dissidents, and opposition figures. Litigation against spyware vendors has achieved limited success—no US or UK victim lawsuit has reached final judgment against a spyware vendor, despite cases like WhatsApp's $167M jury award against NSO Group remaining in ongoing appeal. The report identifies four barriers to accountability: victims' lack of awareness of compromise (spyware is designed to be undetectable), the deliberate obscurity of the spyware market through vendor name-changes and jurisdictional arbitrage, jurisdictional hurdles in establishing which courts can hear claims, and the risk that litigation discovery exposes threat-detection methods to vendors, enabling them to evade future detection. The authors propose a legislative safe-harbor framework that would shield compliant technology companies from products-liability claims related to spyware, contingent on their meeting standards including comprehensive threat notification, rapid vulnerability patching, responsible information-sharing with researchers, and enhanced security features for high-risk users. The framework acknowledges that perfect security against nation-state actors is not feasible, and aims to align incentives toward proactive mitigation rather than penalizing inevitable exploitation.

## Mentioned in this report

- Threat actors: Candiru, Gamma Group, Intellexa Consortium, NSO Group, Paragon
- Malware: FinSpy, Graphite, Pegasus
- Campaigns: CatalanGate, Pegasus Project

Source reporting: https://www.atlanticcouncil.org/in-depth-research-reports/report/404-accountability-not-found-spyware-accountability-through-software-liability

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/e3725c04-09b0-5dc1-99b4-6d965565d8b6/spyware-accountability-through-software-liability-framework.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
