The secret Uganda deal that has brought NSO to the brink of collapse 5 years ago
NSO used a zero-click exploit. Swapping the device for another vulnerable iPhone wouldn't put up much of a hurdle. They'd just a message with the exploit an reinfect the phone in under 30 seconds. Changing the phone and SIM would only work until the new phone number became known. For high-value public targets (with lot of contacts) it porobably won't take long until the new number leaks again.