They state: " NSO is a technology company. We do not operate the system, nor do we have access to the data of our customers " Yet they also state: " The list is not a list of targets or potential targets of Pegasus. " How do they know it is not a list of targets if they don't have access to their customer's lists of targets? None of this is trustworthy and neither are NSO.
It sounds like the "list" is from HLR lookups, which get done all the time without NSO being involved.
If you think about it, none of NSO's clients would want NSO (or anyone else) to know who they are spying on in the first place, so it stands to reason that there'd not be a centralized list anywhere of targets for their software. I'm sure the list is real and all, but there's a distinct lack of clarity about how that list links to NSO and Pegasus specifically.
Now the other bit that the Pegasus Project did was look at phones they suspected of being compromised. I think that's telling in the sense of, "journalists, activists and business people are being targeted". That seems pretty credible, but NSO doesn't seem to be denying that aspect of the story.