WhatsApp Inc. v. NSO Group Technologies Limited
- Phyllis Hamilton
- 4:19-cv-07123
- U.S. District Court · Northern District of California
- 45
WhatsApp v. NSO Group: Judge Hamilton granted in part and denied in part dismissal, dismissed the trespass claim with leave to amend, and denied a discovery stay.
WhatsApp Inc. and Facebook, Inc. may continue pursuing the claims that were not dismissed against NSO Group Technologies Limited and Q Cyber Technologies Limited. The trespass-to-chattels claim was dismissed with leave to amend, and discovery was not stayed.
What happened
In WhatsApp Inc. v. NSO Group Technologies Limited, WhatsApp and Facebook alleged that NSO Group Technologies Limited and Q Cyber Technologies Limited used Pegasus malware through WhatsApp’s system to target about 1,400 devices. They brought claims under the Computer Fraud and Abuse Act, a California computer-access law, contract law, and trespass to personal property.
The court rejected the defendants’ arguments that the case lacked federal jurisdiction, that California could not exercise authority over them, and that foreign governments were required parties. It also allowed the computer-fraud claim to proceed, but dismissed the trespass claim because the complaint did not allege actual damage to or impairment of WhatsApp’s computer systems. The dismissal allowed amendment, and the court denied the request to pause discovery as moot.
Judge Phyllis J. Hamilton granted in part and denied in part the motion to dismiss, denied it in all other respects, and denied as moot the motion to stay discovery. WhatsApp could amend only the trespass claim within 21 days, without adding parties or claims unless permitted by the court or agreed to by the defendants.
The detailed version
- WhatsApp Inc. v. NSO Group Technologies Limited · No. 4:19-cv-07123
- Phyllis Hamilton
- July 16, 2020
Background
WhatsApp Inc. and Facebook, Inc. alleged that NSO Group Technologies Limited and Q Cyber Technologies Limited created, licensed, and supported Pegasus, a surveillance program. According to the complaint, the defendants used WhatsApp accounts and servers to send malicious code to about 1,400 mobile phones and devices between April 29 and May 10, 2019. The alleged targets included attorneys, journalists, human-rights activists, political dissidents, diplomats, and senior foreign-government officials.
The complaint asserted four causes of action: violation of the federal Computer Fraud and Abuse Act (CFAA), violation of California Penal Code section 502, breach of contract, and trespass to chattels. Trespass to chattels is a claim alleging unauthorized interference with someone’s personal property. The defendants moved to dismiss and separately moved to stay discovery while the dismissal motion was pending.
Subject-Matter Jurisdiction and Immunity
The court denied the motion to dismiss for lack of subject-matter jurisdiction. The CFAA claim invoked federal-question jurisdiction. The defendants argued that the alleged conduct was performed by foreign sovereigns and that the Foreign Sovereign Immunities Act, or related immunity doctrines, barred the lawsuit.
The court concluded that the defendants were private foreign entities and did not qualify directly for protection under the Foreign Sovereign Immunities Act. It also rejected conduct-based foreign-official immunity because exercising jurisdiction would not enforce a legal rule against the foreign governments. The court declined to extend derivative sovereign immunity to these foreign entities and stated that the defendants’ motion to dismiss for lack of subject-matter jurisdiction was denied.
Personal Jurisdiction
The court denied the motion to dismiss for lack of personal jurisdiction. It rejected the defendants’ argument that WhatsApp’s terms of service showed their consent to jurisdiction because the forum-selection clause covered claims held by a user against WhatsApp, not claims brought by WhatsApp against a user.
The court nevertheless found a sufficient basis for specific personal jurisdiction. It held that the complaint adequately alleged that the defendants intentionally targeted WhatsApp’s California-based servers to route malicious code. The court treated this as conduct expressly aimed at California, rather than merely conduct affecting a company that happened to be located there. The court also found that exercising jurisdiction would be reasonable after balancing the relevant factors.
The court found that the plaintiffs had not shown purposeful availment based on the terms of service, but that was not necessary because they had shown purposeful direction based on the alleged intentional conduct. The court also held that the breach-of-contract claim arose from the same core facts as the tort claims, so the court could exercise pendent personal jurisdiction over that claim.
Failure to Join Foreign Sovereign Customers
The court denied the motion to dismiss for failure to join necessary parties. The defendants argued that their foreign sovereign customers had to be added under Federal Rule of Civil Procedure 19.
The court held that the foreign sovereign customers were not necessary parties because the court could provide meaningful relief between the existing parties. It also reasoned that any injunction could be written to exclude the foreign sovereigns and apply only to the defendants.
Computer Fraud and Abuse Act Claim
The court denied the motion to dismiss the CFAA claim. The CFAA prohibits intentionally accessing a protected computer without authorization or exceeding authorized access. The court distinguished between having no permission at all and having permission to access some parts of a computer while improperly accessing other parts.
The court held that the complaint did not adequately allege that the defendants accessed WhatsApp’s servers without any authorization because the defendants had created WhatsApp accounts and had at least some permission to send messages through the service. But the complaint did adequately allege that they exceeded authorized access. Specifically, it alleged that the defendants evaded technical restrictions, manipulated call settings, concealed malicious code, and used relay servers to activate the code on users’ devices.
The court also rejected the argument that the plaintiffs had not alleged the required financial loss from access to users’ devices. The complaint alleged that the plaintiffs had rights to at least some data on those devices and incurred costs responding to the intrusion and upgrading the WhatsApp system. The court found those allegations sufficient at the pleading stage. Because the defendants’ only challenge to the CFAA conspiracy claim depended on defeating the underlying CFAA claims, the conspiracy claim also survived.
Trespass to Chattels Claim
The court granted the motion to dismiss the fourth cause of action for trespass to chattels, with leave to amend. Under California law, that claim requires intentional, unauthorized interference with a possessory interest in a computer system and damage caused by that interference.
The court concluded that the complaint did not allege actual damage to or impairment of WhatsApp’s servers. The alleged malware transmissions used the servers as intended to send code to users’ devices, and the complaint did not allege that the servers were degraded, damaged, slowed, or prevented from functioning. The court held that expenses for investigating and responding to the incident, and alleged loss of goodwill, were consequential economic injuries rather than the required injury to the servers themselves.
The plaintiffs were allowed to file an amended complaint within 21 days, but only to amend the trespass claim. They could not add new parties or causes of action without the court’s permission or the defendants’ agreement.
Discovery Stay
The court denied as moot the defendants’ motion to stay discovery. The defendants had offered no reason for a stay apart from the pending motion to dismiss, and the court’s order resolved that motion.
Disposition
The court granted in part and denied in part the defendants’ motion to dismiss. It granted the motion as to the fourth cause of action for trespass to chattels, with leave to amend, and denied the motion in all other respects. It separately denied as moot the motion to stay discovery.
Read the full 45-page opinion on CourtListener, the free public archive maintained by the Free Law Project.