They should have a public first contact and then use an exclusive and private contact for each source. A cheap samsung or huawei. iphones can't be inexpensive.
It sounds like suing a gun manufacturer after a shooting. NSO software might not be used ethically but it certainly can be used legally. They have no responsibility to disclose anything.
Selling and/or using NSO and similar software in the US, with certain exceptions about use by the government, is very arguably a violation of a couple of different US laws, including the CFAA.