Court, Explained
U.S. Federal District Courts
Back to docket
N.D. Cal.Procedural orderFiled Jan. 23, 2024

Apple Inc. v. NSO Group Technologies Limited

Judge
James Donato
Docket
3:21-cv-09078
Court
U.S. District Court · Northern District of California
Pages
8
Civil ProcedureMotion to Dismiss
In one sentence

Apple v. NSO Group: Judge Donato denied NSO’s motion to dismiss Apple’s hacking-related claims, allowing the lawsuit to proceed.

Who this affects

Apple Inc., NSO Group Technologies Limited, and Q Cyber Technologies Limited; the case proceeds against NSO after the court denied the motion to dismiss.

What happened

In Apple Inc. v. NSO Group Technologies Limited, Apple alleged that NSO created and distributed Pegasus malware, used fake Apple IDs, and attacked Apple servers and devices through a zero-click exploit. Apple brought claims for breach of contract, computer hacking, unfair competition, and unjust enrichment.

NSO asked the court to dismiss the case or several claims, arguing that Israel was a better place for the lawsuit, that Apple had not included NSO’s customers, and that Apple’s claims were legally insufficient. The court rejected each argument and denied NSO’s motion to dismiss in all respects.

Judge Donato ruled that NSO had not shown that Israel was a more appropriate forum, that NSO’s customers were required parties, or that Apple’s computer-hacking, unfair-competition, and unjust-enrichment claims were inadequately pleaded. NSO was ordered to answer the complaint by February 14, 2024.

The detailed version

For law students, journalists, and other readers who want the full reasoning

Case
Apple Inc. v. NSO Group Technologies Limited · No. 3:21-cv-09078
Judge
James Donato
Date
Jan. 23, 2024

Background

Apple sued NSO Group Technologies Limited and Q Cyber Technologies Limited, referred to together as NSO. Apple alleged that NSO created and distributed Pegasus, malware that could remotely extract information from mobile devices. Apple also alleged that NSO created fake Apple IDs to access Apple’s servers and used the FORCEDENTRY exploit to attack Apple consumer devices without the victims’ action or awareness.

Apple asserted claims for breach of contract, violations of the Computer Fraud and Abuse Act (CFAA), violations of California’s Unfair Competition Law, and unjust enrichment. Apple alleged that it incurred continuing costs to investigate the attacks, develop security measures, communicate with personnel and users, and respond to the alleged conduct.

NSO moved to dismiss under Federal Rules of Civil Procedure 12(b)(6) and 12(b)(7). NSO argued that the entire case should be dismissed under the doctrine of forum non conveniens because NSO was based in Israel and Apple should have sued there. NSO also argued that the CFAA, unfair-competition, and unjust-enrichment claims were not adequately pleaded and that Apple failed to join NSO’s foreign-government customers as required parties. The court noted that NSO mentioned Rules 12(b)(1) and 12(b)(3) for the first time in its reply brief without presenting arguments under those rules and did not address those grounds.

Forum non conveniens

Forum non conveniens allows a court to dismiss a case when an adequate foreign forum exists and the relevant private and public-interest factors favor litigation there. The parties agreed that an Israeli court was a potential alternative forum, so the dispute concerned whether the factors favored dismissal.

The court held that NSO did not meet its heavy burden. It gave substantial weight to Apple’s choice to sue in its home forum. The court found that the burdens involving witnesses and evidence were roughly balanced between this District and Israel, and that electronic document production, remote depositions, protective orders, and judicial oversight could reduce those burdens. The court also found that this District had a strong interest because Apple servers and devices were allegedly hacked there and Apple was allegedly conducting an ongoing defense against the attacks there.

The court declined to decide at that time whether a forum-selection clause in Apple’s iCloud terms of service applied. Apple alleged that NSO accepted those terms by creating Apple IDs, but NSO did not expressly agree that it had done so. The court said that acceptance of the terms and the scope of any forum-selection clause involved disputed facts that could not be resolved on the current record. Apple could raise the issue again as the case and discovery developed.

Required parties under Rule 19

NSO argued that Apple had to name NSO’s customers as indispensable parties because Apple sought an injunction that might affect information gathered by those customers. The court rejected the argument. It said the complaint’s general request for an injunction did not clearly seek relief beyond NSO’s own conduct involving Apple’s servers and users’ devices. The court also noted that Rule 19 allows courts to shape relief or use other measures to avoid complications. An undefined request for an injunction was not enough to establish that NSO’s customers were essential parties.

Computer Fraud and Abuse Act claim

The court held that Apple plausibly alleged a CFAA claim. The CFAA permits civil suits for certain damage or loss caused by unauthorized access to computer systems and data. The court concluded that the statute’s focus on technological harms from hacking fit Apple’s allegations.

NSO argued that Apple identified only devices owned by Apple users as protected computers. The court found that the complaint also alleged that NSO exploited Apple’s own servers and services to place Pegasus on user devices. The court further held that Apple adequately alleged qualifying losses, including the costs of investigating the attacks, assessing damage, restoring or protecting systems, deploying security updates, and responding to the alleged conduct. The court noted that Apple alleged losses exceeding $5,000 during one year. It left open the possibility that NSO could raise a defense concerning a protected computer as the factual record developed.

California Unfair Competition Law claim

The court declined to dismiss Apple’s claim under the unlawful-practices section of California’s Unfair Competition Law. NSO had not shown at the pleading stage that applying the law would necessarily reach conduct occurring outside California. The court said the effect of any geographic limitation would depend on facts developed later, and NSO could revisit the issue as the case progressed.

Unjust enrichment claim

The court also declined to dismiss Apple’s unjust-enrichment claim. Apple pleaded that claim as an alternative to its breach-of-contract claim, which was sufficient at this stage. The court left for a more developed factual record the question of whether equitable restitution and legal damages were overlapping or otherwise presented a problem.

Disposition and next steps

The court denied NSO’s motion to dismiss in all respects. The order stated that NSO would answer Apple’s complaint by February 14, 2024, and set a case-management conference for April 4, 2024, at 10:00 a.m.

The authoritative version

Read the full 8-page opinion on CourtListener, the free public archive maintained by the Free Law Project.

Open opinion PDF →
Summary written with AI assistance. See how summaries are made. Spot something wrong? Tell us.