
US Judge Donato: NSO Group El Faro California Jurisdiction Dismissal
Summary
- A federal judge dismissed a lawsuit by Salvadoran journalists against Israeli firm NSO Group over alleged Pegasus spyware attacks.
- The journalists claimed NSO Group used Apple's California servers to target their iPhones, but the court found no sufficient connection to California.
- U.S. District Judge James Donato denied dismissal based on *forum non conveniens* but granted it due to a lack of specific personal jurisdiction.
- The court ruled that NSO Group's alleged interactions with Apple's servers did not constitute tortious conduct within California for jurisdictional purposes.
- The plaintiffs failed to prove NSO Group knew the servers were in California or that its actions would cause harm in the state.
Spyware Lawsuit Dismissed in California
This ruling in the NSO Group El Faro California jurisdiction dismissal underscores the significant challenges plaintiffs face in establishing specific personal jurisdiction over foreign technology companies in U.S. courts, particularly in cases involving cross-border cyber litigation.
A federal judge recently dismissed a lawsuit brought by a group of Salvadoran investigative journalists against the Israeli cyber intelligence firm NSO Group, ruling that California was not the appropriate venue for their claims. The journalists, affiliated with the news outlet El Faro, had alleged that they were targeted by NSO Group's Pegasus spyware between June 2020 and November 2021, asserting that hackers utilized the sophisticated tool to access their Apple iPhones. This alleged intrusion, affecting at least 22 of El Faro's 35 employees, was characterized by the plaintiffs as a deliberate campaign to undermine independent journalism in El Salvador.
The lawsuit, filed in 2022, named NSO Group and its parent company as defendants. NSO Group, which was blacklisted by the U.S. government in 2021, stands accused of supplying the Pegasus spyware to an unidentified government outside the United States. The journalists contended that the spyware allowed unauthorized access to their calls, texts, contacts, and other personal data. Their decision to file the case in the Northern District of California stemmed from Apple's corporate headquarters being located there, with the plaintiffs claiming NSO Group purportedly leveraged Apple's servers to facilitate the attacks on their devices.
U.S. District Judge James Donato, an appointee of former President Barack Obama, presided over the case. In his 10-page ruling, Judge Donato concluded that the core allegations of the Salvadoran journalists' spyware lawsuit had no substantive connection to California. This finding ultimately led to the NSO Group El Faro California jurisdiction dismissal, despite the plaintiffs' efforts to establish a link through Apple's presence in the state.
Jurisdictional Arguments and Judicial Findings
NSO Group sought the dismissal of the case on two primary grounds: *forum non conveniens* and a lack of specific personal jurisdiction. While Judge Donato rejected the *forum non conveniens* argument, he ultimately agreed with NSO Group regarding the absence of specific personal jurisdiction. The judge stated that the defendants failed to meet the stringent burden required for a *forum non conveniens* dismissal, which demands a clear showing of oppression and vexation disproportionate to the plaintiff's convenience.
However, the court found the plaintiffs' arguments for specific personal jurisdiction over NSO Group unpersuasive. Specific personal jurisdiction requires a defendant to have purposefully directed activities toward the forum state, with the claims arising from those forum-related activities, and the exercise of jurisdiction being reasonable. Judge Donato noted that NSO Group's sole operational presence is in Israel, and all the journalists whose devices were allegedly compromised resided in El Salvador at the time of the attacks. These facts significantly weakened the plaintiffs' ability to demonstrate sufficient ties to California for the case to proceed there.
The Elusive California Connection
The central contention by the Salvadoran journalists regarding a California connection revolved around the assertion that the alleged spyware attacks necessitated extensive interaction between NSO Group and Apple's servers, which they believed were located in California. Judge Donato, however, found this argument insufficient to establish specific personal jurisdiction. He explicitly stated that such dealings with Apple's servers, even if they were indeed located in California, did not constitute the tortious conduct or the basis for the claims for which the plaintiffs sought redress.
Furthermore, the judge highlighted critical deficiencies in the plaintiffs' jurisdictional claims. They did not definitively allege that the servers were, as a matter of fact, physically located in California. Crucially, they also failed to allege that NSO Group possessed knowledge of the servers' California location or that the company knew its actions would cause harm within California. Consequently, the court determined that the record did not support the journalists' attempt to establish jurisdiction, reinforcing the ruling that the alleged activities lacked a direct and purposeful connection to the state.
Implications for Cross-Border Cyber Litigation
This ruling in the NSO Group El Faro California jurisdiction dismissal underscores the significant challenges plaintiffs face in establishing specific personal jurisdiction over foreign technology companies in U.S. courts, particularly in cases involving cross-border cyber litigation. The decision by U.S. District Judge James Donato clarifies the stringent requirements for demonstrating 'purposeful availment' and direct forum-related activities, especially when the alleged harm originates from cyber operations conducted outside the forum state.
The outcome serves as an important precedent for future cases involving international tech entities and alleged digital harms. It emphasizes that merely alleging the use of a U.S.-based company's infrastructure, without concrete evidence of the defendant's direct and knowing engagement with that infrastructure within the forum state, and an intent to cause harm there, may not be enough to overcome jurisdictional hurdles. This high bar for NSO Group specific personal jurisdiction will likely influence legal strategies in similar international disputes.
Practical Implications
This ruling clarifies the stringent requirements for establishing specific personal jurisdiction over foreign technology companies in US courts, particularly when the alleged harm originates from cyber activities outside the forum state but involves its infrastructure. Lawyers should note the high bar for proving 'purposeful availment' and direct forum-related activities when advising clients on cross-border litigation against international tech entities.
Source
How does this affect you?
Get an AI analysis of this article grounded in your jurisdictions, practice areas, and any policy documents you've uploaded to Wansom.
Finish Reading the Full Story and the Expert Analysis.
Get the latest legal & regulatory intelligence in United States
Wansom is AI and can make mistakes.
