HomeRapidalertIsraelis behind interception of mobile phones and WiFi at airports in Greece

Israelis behind interception of mobile phones and WiFi at airports in Greece

While companies like NSO are reeling from the backlash against Israel’s aggressive cyberweapons industry, with some of them closing down, Intellexa, owned by a former Israeli intelligence officer, has set up shop in Athens – and business is booming. An investigation by Haaretz’s Omer Benyakom in collaboration with Inside Story reveals that Israelis are orchestrating hacking campaigns and intercepting cell phones and airport WiFi in Greece.
Israelis behind interception of mobile phones and WiFi at airports in Greece

The Larnaca International Airport is the main gateway into Cyprus, known for its seaside resorts and relaxed taxation. Approximately 300,000 Israelis passed through Hermes Airport only in 2019. They and others may be shocked to learn that earlier this year, an Israeli-owned company was found guilty of personal data interceptions from people using some of the airport's free WiFi systems. Over roughly six months in 2019, the company WiSpear, as courts in Cyprus determined, collected information via three access points it had installed at the airport, allegedly to help boost the wireless signal and provide faster internet to travelers.

Learn more: Cyberattack at Larnaca Airport hermesairports.com

Although the courts found that the company never intended to personalize the data it collected and that no individual suffered direct harm as a result, they noted that the information collected was protected by Cypriot and European privacy legislation. The company, which, according to the court, collected the information solely for demonstration purposes, was fined €26,000 for the incident.

Israelis behind interception of mobile phones and WiFi at airports in Greece
intellexa.com

Personal but anonymous data collected from over 600 individuals were found on the company's servers, which, as they said, were not deleted due to negligence. Theoretically, any person who passed through the airport at any time during the period May – November 2019 could have had their data –for example the number that identified their SIM card– recorded in the company's system, all without their knowledge.

To understand the strange case of the three WiFi access points that were installed on the third floor of the Hermes airport in Cyprus, we need to shift our focus beyond the eastern Mediterranean basin: to Greece. In a suburb of Athens, in an undefined office building that towers above a common Greek shopping center, not far from the old city airport, the Hellenic, there is a company called Intellexa. The entrance to its offices, which it leased in December 2020, is located right next to an Adidas store and sources that have gone inside say it spans five floors. It is said to include sleeping areas, a training center –with a demonstration system for training customers– and even a space with prayer mats, so that those coming from Muslim countries such as Bangladesh to receive training can pray.

Even though Israeli companies are prohibited from doing business with Bangladesh, when journalists knocked for the first time on the doorbell outside Intellexa's door a few months ago, the person on the other side answered in Hebrew. When I was there this summer, no one answered. Towards the end of the summer, the company had sent its employees to work from their homes – among other things also from Israel – and had moved its activities to another location of the Greek capital.

This is not the first time Intellexa has been forced to move out of its offices. Intellexa is not actually a single company – although a company with that name is registered in Ireland – so much as it is a trademark for a collection of different companies, offering offensive technologies and services in cyberspace, from spyware to open-source information. They are run by or associated with Tal Dillian, who once headed the secretive Israeli military intelligence unit known as Unit 81, which was tasked with technological development. Dillian is an Israeli national who also holds Maltese citizenship. However, the various companies he is involved with that make up Intellexa are incorporated in countries all over the world, forming a complex corporate web that is almost impossible to untangle.

What is known is that since 2019, Dillian operated from Cyprus, where the so-called «Intellexa alliance» of his companies was advertised as the «Star Alliance» of the cyber-world and digital intelligence.

Israelis behind interception of mobile phones and WiFi at airports in Greece
Tal Dillian in a photo from his personal website taldilian.com, where he is described as «information-gathering specialist, community builder and serial entrepreneur».

Among the companies Dillian founded that are part of the alliance are WiSpear, an offensive cyber firm that can hack phones and track targets via WiFi , and Cytrox, a company founded by Dillian’s predecessor in the secret intelligence unit, whose flagship product is Predator, a spyware that resembles the infamous Pegasus spyware made by NSO Group. Predator is considered Pegasus’s biggest competitor, after spyware made by Israeli company Paragon.

However, while the activity of NSO, Paragon, Verint and other Israeli companies operating in the cyber‑weapons market is strictly regulated by the Israeli defense authorities, industry sources say that Intellexa is not under Israeli supervision. Sources say that, as a result, the company can provide services that Israeli companies officially cannot, due to fears that defensive know‑how or secrets would leak, and can do business with states to which Israelis are prohibited from selling, for security or diplomatic reasons.

A joint investigation by the sister edition of Haaretz, TheMarker, and the Greek investigative journalism website Inside Story, reveals a complex cyber and information services company for hire that has been run by Dillian from Greece for the past two years.

«Cyber pirates»

Israel's law on defensive exports requires every Israeli citizen who sells classified expertise or technology whose origin is in Israel to register and be under the supervision of an agency known as DECA. De jure, the law has a fairly broad scope, but de facto it is applied exclusively to businesses that are truly registered in Israel and consider it their homeland.

DECA refuses to confirm or deny which companies are under its supervision and whether Intellexa operates with its blessing or not. However, over the past year, senior sources from Israel's cyber‑weapon industry – which is also overseen by DECA– complained that the new strict regulations imposed by DECA are choking the industry. They say that while companies like NSO lost contracts and were forced to lay off employees and others shut down completely due to compliance issues, Dillian's companies thrived and his empire grew – with new offices, new teams, and even new capital.

«Intellexa essentially operates in a piratical way – refuses to comply with regulations», says a senior industry source. «As a result, they can close hefty agreements in parts of the world where Israelis can no longer obtain a license to operate – for example, in the Gulf countries– or even in those places where Israelis were never allowed to work».

«If NSO could be said to be an entity with problematic ethics, at least whatever it did was legal and clarified with the Israeli state – that is something different and much more serious», they add.

Intellexa, despite its Israeli ownership and the fact that many of its executives and key staff live in Israel, is not considered an Israeli company. The companies that make up Intellexa are registered in places like Ireland, France, Hungary, North Macedonia, Greece and the British Virgin Islands. Industry sources say the company had sales representatives in Indonesia, Dubai, Paris – and of course Tel Aviv. It seems that in recent years the center of their operations has been Athens, while Dilian himself lives mainly in Cyprus. This complex web of companies, the sources say, makes regulating the companies’ activity almost impossible and presents a new and unique challenge for regulators – both in Israel and in Europe.

Israelis behind interception of mobile phones and WiFi at airports in Greece
Israelis behind interception of mobile phones and WiFi at airports in Greece

The rise of Intellexa, sources say, is directly linked to Israel's effort to consolidate its cyber industry, as a response to a series of investigations from the past year, mainly related to NSO and the abuse of its spyware by state clients, which caused a storm. After the news that officials of the U.S. State Department were spied on in Africa by an NSO client, the company landed on the so-called blacklist and Israel was pressured to curb the industry. Sources say that in the wake of U.S. pressure, the number of countries that DECA allows Israeli companies to sell their cyber-weapons to has been drastically reduced and now includes only 37 nations, mainly Western and democratic states with a clean human-rights record.

The result, sources say, is that Israeli businesses cannot currently get the green light from regulatory authorities to sign almost any new agreement – including those with liberal Western democracies, which should be acceptable targets. As the client bases of Israeli companies shrink, sources say, Intellexa's increase. The reason, they say, is that with the help of Israeli intermediaries, Intellexa invades and takes the agreements that Israeli companies cannot get approval for.

For example, an Israeli company named Nemesis shut down, after two deals it had been authorized to negotiate with potential clients in Africa and Asia failed to receive approval at the final stage. Both contracts, sources say, went to companies linked to Intellexa.

Nemesis’ decision to withdraw was based on the understanding that any new deals it might have struck would also not be approved. It’s not alone. In recent months, two other such companies have closed. Meanwhile, companies affiliated with Intellexa have appointed new employees — including a former senior sales executive who worked for Verint and then NSO.

«The EU and the US are not big enough markets to sustain the entire local offensive cyber industry», explains a senior source in the sector. «NSO has a very strong presence in Europe and continues to fight to survive», they note, emphasizing that the company recently laid off about 100 employees. «The [Israeli] Defense Ministry is making a mistake. It crushes the local industry under the bus because it does not want to clash with the Americans. There are some European companies that profit from this – but the big winners are China, Russia and Tal Dillian».

It is almost impossible to verify the identity of Intellexa’s clients – both because of the secretive nature of the sector and because of the complex corporate ownership structure of this cyber firm. However, well‑informed sources report that alongside the countries where Israeli companies were once allowed to operate –for example Mexico, Ghana, Colombia and Greece– the companies linked to Dillian have also concluded agreements over the past year and a half with clients in countries such as Saudi Arabia, Oman, Malaysia, Indonesia and Sri Lanka. Although Israel refuses to confirm or deny the list of countries for which such sales have been approved (in reality the list is considered a state secret), sources say that all these are countries where Israeli companies have long been barred from doing business.

According to data submitted in Greece by one of the companies linked to Intellexa, the company also has clients in Bangladesh and another anonymous “Arab country». A recent report in Israeli media by Ronen Bergman said that they have also cooperated with Ukraine and Sudan – two countries where Israel does not allow sales. Sources also said that the company or companies linked to it also operated in Egypt, Oman, Ghana and perhaps even in Turkey – also regions that are now prohibited for Israeli cyber agreements.

Citizen Lab, the digital forensics research team based at the University of Toronto that has become the «plague» of the cyber industry, as it works with the aim of exposing the misuse of spyware, wrote in a December 2021 report that it is very likely that there are customers operating the Predator spyware from places such as Greece, Egypt, Indonesia, Oman and Saudi Arabia. They said there may also be customers in Armenia, Madagascar and Serbia. Even when agreements are signed with the blessings of regulatory authorities, it is almost impossible to verify – this holds doubly when they are made with companies operating from various countries through different jurisdictions, thus remaining covered by a veil of mystery.

Circles and red lines

Even the biggest critics of Dillian consider him a genius. A senior officer of the Israeli secret services, who was his commander, describes him as a very clever man – but also a man who is not afraid to bend the rules. His departure from the Israeli armed forces, after leading Unit 81, cut in half what everyone agrees was an extremely promising career, which, as some say, could have ended with Dillian serving as head of Israel's military intelligence service. However, a small scandal involving some financial irregularities in the unit caused a postponement of his rise in the hierarchy and ultimately led him to decide to leave the army, with honor.

After the end of his military career, Dillian started a successful business career: He founded one of the first cyber companies, Circles, which provided tracking services and claimed it could locate the position of any mobile device in the world using only a phone number. Circles, which was registered in Cyprus to avoid Israeli oversight at a time when the export of cyber weapons was not yet permitted, did work for clients in places such as Nigeria and the United Arab Emirates, to name just two well-known examples. Eventually it was bought by an American fund that, at that time, also owned NSO. Dillian received over $20 million from the deal.

However, despite its success, Circles «crossed a red line», sources say, causing a rift between Dillian and the Israeli military intelligence establishment, specifically Unit 8200. A similar split would later occur between the secret intelligence unit and NSO.

Since 2020, Dylan appears to still split his time between Israel, Cyprus, and Greece. He even had offices in Israel. Since 2021, he also participated in many other business initiatives in Israel – among them a 3D printing company, a phytopharmaceutical company, and even a skin care company– as well as impressive charitable activities – among them, one was focused on education and another on the development of the northern and southern regions of Israel.

Delian founded Intellexa together with Abraham Sahak Avni, an Israeli living in Cyprus who is considered close both to the local Jewish community and the ruling party, and with an Israeli named Liv Oz, who was head of Unit 81 before Delian and created the company Cytrox, which produced the espionage software Predator. The company was registered abroad. In 2020, Delian, Oz and another partner were sued by one of their earliest investors. The lawsuit, which leaked to the media and caused great embarrassment for Intellexa, describes the company's early steps, providing details about some futile attempts to purchase «exploits» (methods for breaching a system) on the dark web. However, the core of the lawsuit is that Delian caused damage to the company by doing something unimaginable in the cyber services sector: exposing himself to the media.

What is happening in Larnaca

In 2019, Dillian gave an unprecedented interview to Forbes magazine, showcasing the capabilities of his company WiSpear and the «espionage van of 9 million dollars», which could hack any device within a 500‑meter radius – including the interception of encrypted communications that occur via applications such as WhatsApp. In the interview Dillian bragged about things like the ability to scrape information from Facebook (bypassing the restrictions on its API), facial recognition and, of course, geographic location tracking based on phone numbers.

WiSpear remains registered in Cyprus, albeit under a slightly different name, and even though the country is a well-known tax and espionage haven, the interview caused a storm in the country. The police carried out a raid on the company's offices and the van was seized, along with the antennas and more than ten WiFi transmitters and receivers. Three employees were arrested and the Israeli embassy was forced to get involved. Intellexa moved its activities to Greece, but the uproar caused by the interview showed no signs of calming down.

In the end, over 100 individuals were interrogated by the authorities of Cyprus for a series of offenses, ranging from privacy violations to telecommunications breaches and even possible customs issues. The concern was that WiSpear was spying illegally or collecting data via the van or other of its capabilities.

The investigation started around the van, but soon was led to the airport, as they initially thought the van was parked outside it – but they quickly discovered the operation with WiFi. The WiFi systems installed at the airport, as revealed by the decision and earlier police documents, were installed by one of the employees who were arrested and the data was streamed to a server at the company's offices in Larnaca.

Israelis behind mobile phone and airport WiFi interceptions in Greece Intellexa
Israelis behind interception of mobile phones and WiFi at airports in Greece

The same Dillian was forced to return by air from Greece to Cyprus, where he was questioned by the police for 50 hours, according to sources, overall. Sahak Avni was also questioned. Although both were ultimately cleared of all personal charges – as were all the other employees of WiSpear– the company itself was eventually found guilty of privacy violations by the Cypriot courts in February 2022.

The court ruled that WiSpear had illegally collected personal data for more than 600 citizens in the form of so‑called IMSI numbers (a unique 15‑digit code that identifies SIM cards and serves as a kind of identity for mobile devices during international roaming) and MAC numbers (numbers that help identify devices connected to the internet).

«Between 13/6/18 and 15/11/19, through the system operating in the company's offices, more than 100,000 unique MAC address numbers corresponding to electronic devices… were collected and stored illegally, via access points» at the airport, the decision states.

«During the period from 5/5/19 to 15/11/19, 626 international subscriber identities (IMSIs) of the corresponding SIM card numbers, which are used in citizens' mobile devices that entered the range of the antennas, were stolen, via the above system», it is also noted in the decision.

WiSpear, explains the ruling, «had a specific computer program named Spearhead, which provided, under certain conditions, the capability of illegal interception of electronic data». This, when combined with «mobile phone equipment that was also installed in the truck… had the capability, under conditions, to eavesdrop on private communications».

Although the fine in the criminal procedure was only €26,000, a few months earlier, in November 2021, the Cyprus Data Protection Authority imposed a fine of almost €1 million on WiSpear.

The same Dillian did not respond to repeated requests to comment immediately on the case, but a statement via email from the lawyer representing him and WiSpear in Cyprus emphasized that all charges – criminal or otherwise – against Dillian or any WiSpear employee were withdrawn and that all the information collected was not personal or private. They said that the court itself noted that no one was harmed and that devices were not breached – and that the data collected was only for demonstration purposes.

This is true. A court document from 2019 linked to the case states that during its investigation, the Cypriot police discovered that WiSpear representatives had conversations with Hermes officials about improving the airport's WiFi as early as 2016.

Indeed, when the story first broke out and the employees of WiSpear were arrested, the company said to the Cypriot media that the WiFi system was installed as part of an agreement between them and Hermes Airport: "It appears that the Cypriot police also have something against the Wi‑Fi antennas… Nine innovative‑technology antennas, of which three were installed in the first phase to be tested as a long‑range Wi‑Fi access point, so that visitors and tourists can enjoy high‑quality, high‑speed internet access»", WiSpear said.

The WiSpear, at least in 2019, was unyielding in its response that it had done nothing wrong: “This type of equipment is usually used from Japan to the USA and in all developed countries… This witch hunt against us is now expanding to include and affect entities such as Hermes (airport operator) that did nothing else except examine the testing of our innovative technology for optimizing their services to the public».

The police in Cyprus were puzzled, however, as to why a cyber company that provides wifi hacking technology would also offer wifi infrastructure services at the airport. According to WiSpear's lawyers and the decision, the data were collected for demonstration purposes. However, the conversations the company had with the airport had nothing to do with data collection – they had, according to WiSpear's own statement, the purpose of improving the airport's wireless internet. How would data collection demonstrate the upgraded wifi?

Meanwhile, sources that know well the dark world of data brokerage – where massive databases are sold – note that Israeli brokers have offered data sets that are alleged to have been taken from airport wireless networks.

The police also found that another company linked to Dillian had contacted the airport: According to a police investigation document seen by Haaretz-TheMarker, the police also investigated another company called GO Networks, which they also identified as linked to WiSpear. The company, which closed this year, is also known as GoNet System and according to its now-defunct website provided wifi infrastructure services.

GoNet, according to the 2020 lawsuit filed against Dylan and his associates, is also linked to Intellexa through shared corporate ownership in Ireland. According to well-informed sources, one of the former senior officials of GoNet System now holds a top role at Intellexa.

A Service

A presentation by Intellexa that was seen by Haaretz-TheMarker reveals that not only its staff has increased, but also the services it provides and its capabilities. The presentation clearly shows how data collection via Wi‑Fi and the routine interception of mobile communications (the professional term for hacking smartphones) are merely two services in a broader package.

According to the presentation, Intellexa consists of four companies: WiSpear, Cytrox, Nexa and Poltrex. Although each provides a different limited service, together they form a one-stop-shop for digital espionage that ranges from targeted breaches to broad data collection and even includes software for integrating the two with each other.

For example, Cytrox extracts data from mobile phones of specific targets, while WiSpear does the same via wireless networks («WiFi surveillance»). Nexa, however, conducts «GSM surveillance» to exploit global mobile communication systems, while also providing «switching solutions» – a term for compromising either devices that connect other devices to the internet, or actual internet service provider systems (such as routers). The «field collection» services of WiSpear, as shown in the presentation, are supplemented by «OSINT» data collected from open sources by Nexa. Even the geographic location of mobile phones via a communication protocol called SS7 (which was done by Circles) is also included.

Israelis behind mobile phone and airport WiFi interceptions in Greece Intellexa
Israelis behind interception of mobile phones and WiFi at airports in Greece

Services also offered «social engineering» – a euphemism of this particular industry for creating deceptive and personalized messages that trick people into clicking malicious links that infect their phone with spyware, for example, or to provide personal details that could be used to expose them to danger (for example, their password).

There are also identity‑spoofing services that provide clients with operational security, hiding their identities behind a massive chain of servers and online proxies.

Another promotional flyer seen by Haaretz-TheMarker shows how the company's technology has improved: What once required a truck can now fit into a backpack and any device within a 300‑meter radius of it can be compromised. The product, called Triton, appears to be only one of the new means used for cyber‑warfare purposes, and, according to the presentation, Intellexa also offers «εναέρια» surveillance (likely a drone that operates in the same way as a van – but from the air).

The presentation also shows that the company can now do things it couldn’t do before: for example, hack Apple ’s iOS or be what’s called “persistent.” Many spyware “washes out” of a phone’s system if the device is rebooted. Spyware’s ability to be persistent means it can survive a reboot — and persistence is considered a high-stakes indicator in the spyware industry. While in the past, Dillian’s companies had to buy exploits and, according to the 2020 lawsuit, had no in-house development capabilities, that’s no longer the case, according to the sources and the new and improved products.

Intellexa combines all of this into a software – a program that goes by many names, but in the past was called InSight, which can «merge» all data sources together. However, the main thing that makes Intellexa unique is that it is packaged as a service.

Indeed, the now-deleted versions of Intellexa's website boasted about «active» cyber‑intelligence – an industry term for hacking as a service– and support for «field information».

The Intellexa documents that leaked online show how its model differs from that of the Israeli companies from this perspective: The company provides a three‑part service for 8 million euros. The first part is hacking – accompanied by a «filler» 100 successful «interceptions» mobile phones and the ability to spy on 10 targets simultaneously. The second part is the software that aggregates all data – which in this leaked document is called Nova, but was previously also named Nebula and likely has many other names.

This is how Israeli companies operate, in a package that provides hacking technology with a usage license model and some software for displaying the data that has been breached.

However, the third facet of Intellexa's model is the one that makes it different: Project management services. Israeli businesses are allowed to sell only technology, not services. Intellexa offers not only installation and initial training on the system (something that Israeli companies also do, sometimes through companies registered in Cyprus), but real «technical, operational and methodological» support – with the latter term meaning espionage practices.

«There is a big difference between selling someone a weapon and teaching them how to use it», says a source with experience in Israel's laws on defense exports. «Although many provide training as a service, pulling the rope from the regulatory perspective, they cannot work with a client on a real project», as the leaked document appears to indicate.

The provision of hacker-to-rent services as such is not permitted by Israel's defense export organization, as it could expose the tactics of Israeli secret services or the so-called «methodologies». Although many Israeli companies have used the so-called «Cypriot workaround» to sell their Israeli technologies alongside their services, sources say that Intellexa took it a step further in the form of a cyber‑espionage company for rent.

Local talent

Even though Intellexa can do all of this because it is not Israeli, many of its employees are. In fact, Intellexa's ties to the local market are a well-known secret – just this year it hired the services of a well-known software company that in recent years has turned to defense projects and is based in the center of Tel Aviv.

Αποκαλύπτουμε επίσης εδώ για πρώτη φορά το γεγονός ότι ορισμένα ανώτερα στελέχη των εταιρειών ζουν και δραστηριοποιούνται εκτός Ισραήλ: για παράδειγμα, ο CTO του ομίλου ζει στο Τελ Αβίβ και δεν έχει καν ακίνητο στην Αθήνα – ο πρώην επικεφαλής πωλήσεων που συμμετείχε στη ρύθμιση της συμφωνίας με το Μπαγκλαντές ζει επίσης στο Τελ Αβίβ, όπως και ο νέος επικεφαλής πωλήσεων, ο οποίος επίσης ζει στο Ισραήλ τουλάχιστον για ένα μέρος του έτους.

Legal experts say that the regulatory landscape is blurry from this perspective, as sales of foreign products, for example, are not regulated and can be carried out by Israel without oversight. However, if the sales involve technology or know-how that is considered confidential or sensitive and its origin is Israel, that, they say, is something different. The case, they say, challenges the existing regulatory system and presents a unique dilemma.

An investigation by the inside story journalists in Greece also revealed that at least five Israelis have moved to Greece to work for the company in some capacity.

According to sources, Dylan enjoys the best of all worlds: talent from Tel Aviv, corporate representation in EU states, and all the privileges of business activity in the third world – and all of this without supervision.

It is not only a challenge for the Israeli regulatory authorities: Intellexa previously claimed that it was under EU export supervision – a claim that now no longer appears on its website. A recent investigation by Inside Story found that they were not registered as exporters of defense products in Greece and previous reporting has indicated that, since Cytrox is registered in North Macedonia, it is exempt from EU supervision.

«The Greek government will fall»

After signs of the Predator spyware were detected on the phone of a distinguished Greek researcher journalist, who was investigating a massive corruption scandal involving the country's economic and political elite, the country has gone mad to see who else has been placed under surveillance.

«There's no way I'm the only one», the journalist, Thanasis Koukakis, told me, drinking coffee in Athens. He was right. In the months that have passed since I met him, the scandal shook Greece and it was revealed that the head of the country's socialist party was also under surveillance.

In August, the head of the Greek Intelligence Service, Panagiotis Kontoleon, resigned when the agency's surveillance practices came under scrutiny, including the accusation by the opposition party leader that his phone had been intercepted by the Predator software in 2021. Greece admitted that it carried out the surveillance, emphasizing that it was legal, but did not say whether it used the Predator espionage software and did not mention Intellexa.

Israelis behind interception of mobile phones and WiFi at airports in Greece
Panagiotis Kontoleon at a hearing of the Committee on Institutions and Transparency of the Parliament on July 29, 2022.

The inside story has revealed many connections between Greek government officials and companies linked to Intellexa, even noting that three specific companies were founded in Greece to allow Intellexa to transfer its operations to the country after its collapse in Cyprus.

A source in Greece said a few weeks ago that if another case were revealed, “the Greek government would collapse.” Last week, a third case was revealed: former MP and Minister of Infrastructure and Transport Christos Spirtzis, a member of the left-wing SYRIZA party, was hacked in 2021 using the same malicious link that also infected journalist Koukakis’ phone.

Intellexa
Christos Spirtzis shows the message on his phone, with which he was infected, to the journalists, on September 9, 2022.

Although legal, perhaps, the case of Intellexa, its services and its activities over the past two years, falls within a broader discussion currently being conducted regarding the industry of offensive cyber weapons – both in Israel and abroad.

A few weeks ago, a group of European lawmakers came to Israel to investigate NSO and Pegasus in the wake of the so‑called CatalanGate, during which the leaders of the Catalan separatists were spied on by the Spanish government, a client of NSO. The spying sparked intense political debate in Europe – especially as it was later revealed that it was done legally. Last week, the lawmakers arrived in Greece.

While Israel's cyber espionage industry is now feeling the blow of regulatory backlash, many want to push this field completely out of the law and ban the sale of such technologies, treating them as the nuclear weapons of the digital age. However, others propose regulating them and preventing their sale to private customers or to states that use them against journalists or regime critics.

The case of Intellexa shows that even the existing oversight has not yet been fully enforced. In the final ruling against WiSpear, it was noted, almost indifferently, that the devices collected from its offices did not carry the CE marking, which refers to EU standards for electronic devices. These small details show how deep the contempt is even for insignificant regulations. If the industry wants to survive, the regulatory mechanisms of national states must be imposed – before the entire industry is banned worldwide.

«All categories were withdrawn»

The Israeli Ministry of Defense, the defense products export organization and DECA declined to comment on this report, despite repeated attempts. None of the owners or partners of Intellexa, including officials of WiSpear, Cytrox and GoNetSystems, responded to the present.

However, a lawyer from Pelecanos & Pelecanou LLC representing Dylan, WiSpear and other unnamed officials associated with the company, responded. Although they refused to answer specific questions regarding their compliance or activities in Israel, Greece, or Cyprus, they gave a detailed response concerning the wifi case at airports:

«In November 2019, after an interview published on an online site and the blatant misinformation and false claims by official and unofficial actors in Cyprus, an investigation was launched by the Cypriot authorities regarding the operation of the company WiSpear. The investigation was conducted thoroughly with full cooperation and assistance from Mr. Tal Dillian and the company's representatives. Mr. Dillian voluntarily returned to Cyprus, submitted a detailed statement of facts regarding the operation of WiSpear and was available for questioning in 18 cases.».

All charges against Mr. Tal Dilian and all individuals who were questioned as part of the investigation were withdrawn without compensation. None of the individuals who were investigated suffered any form of personal sanctions, whether criminal or administrative.

In February 2022, the Larnaca Criminal Court published the final decision on the case.

The Court of Misconduct noted and stipulated that the violation attributed to the company never involved any intent, hacking, or interception, stating that there was never any effort or purpose to personalize any data. The court emphasized that no damage was caused to any natural person.

In its ruling, the Court criticized the large-scale and negative publicity the issue received from the media and the irreparable damage, stating: «we condemn the excessive and reckless publicity that can cause various negative repercussions».

The Court emphasized that any activity that was not carried out for any malicious purpose – and noted full cooperation with the police without any reservation or hesitation, since from the first moment the defendant not only facilitated but also assisted the police investigative work.

The Court also emphasized that the defendant contributed to avoiding a complex and time‑consuming judicial hearing process for a case that was on the brink of acceptance or rejection and, therefore, saved time for the Court.

It should be noted that ’ throughout the investigation, the company emphasized that it cooperates only with official state law enforcement agencies that operate under the law and that it does not sell its products nor provides its services to private and commercial entities. As emerges from the content of the filing, ultimately the company's position on these issues was neither refuted nor challenged.

It should further be noted that in specific procedures initiated by the defense during the investigative stage, the Supreme Court of Cyprus condemned the Cypriot law enforcement agencies for taking unconstitutional and unjustified investigative measures».

This article was originally published in Haaretz-TheMarker and is republished here in Greek as part of their collaboration with Inside Story.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS