Stephanie Kirchgaessner
The Guardian / February 10, 2025
After WhatsApp claimed 90 users were targeted last year, experts concerned over how US could use cyberweapons.
Washington – Even as WhatsApp celebrated a major legal victory in December against NSO Group, the Israeli maker of one of the world’s most powerful cyberweapons, a new threat was detected, this time involving another Israel-based company that has previously agreed contracts with democratic governments around the world – including the US.
Late in January, WhatsApp claimed that 90 of its users, including some journalists and members of civil society, were targeted last year by spyware made by a company called Paragon Solutions. The allegation is raising urgent questions about how Paragon’s government clients are using the powerful hacking tool.
Three people – an Italian journalist named Francesco Cancellato; the high-profile Italian founder of an NGO that aids immigrants named Luca Casarini; and a Libyan activist based in Sweden named Husam al-Gomati – announced they were among the 90 people whose mobile phones had probably been compromised last year.
More is likely to be known soon, when researchers at the Citizen Lab at the University of Toronto, which investigates digital threats against civil society and has worked closely with WhatsApp, is expected to release a new technical report on the breach.
Like NSO Group, Paragon licenses its spyware, which is called Graphite, to government agencies. If it is deployed successfully, it can hack any phone without a mobile phone user’s knowledge, giving the operator of the spyware the ability to intercept phone calls, access photographs, and read encrypted messages. Its purpose, Paragon said, was in line with US policy, which calls for such spyware to only be used to assist governments in “national security missions, including counterterrorism, counter-narcotics, and counter-intelligence”.
In a statement to the Guardian, a Paragon representative said the company had “a zero-tolerance policy for violations of our terms of service”. “We require all users of our technology to adhere to terms and conditions that preclude the illicit targeting of journalists and other civil society leaders,” the representative said.
The company does appear to have acted swiftly in response to the cases that have emerged so far. The Guardian reported last week that Paragon had terminated its contract with Italy for violating the terms of its contract with the group. Italy had – hours before the Guardian’s story broke – denied any knowledge of or involvement in the targeting of the journalist and activists, and said it would investigate the matter.
David Kaye, who previously served from 2014 to 2020 as a special rapporteur on freedom of expression and opinion said the marketing of military-grade surveillance products, such as the kind made by Paragon, comes with “extraordinary risks of abuse”.
“Like the NSO Group’s Pegasus spyware, it is easy for governments easily to avoid basic principles of rule of law. Though not all the details are known, we are seeing the likelihood of scandalous abuse in the case of Italy, just as we have seen that in other contexts across Europe, Mexico and elsewhere,” Kaye said.
The issue seems particularly relevant in the US. In 2019, during the first Donald Trump administration, the FBI acquired a limited license to test NSO Group’s Pegasus. The FBI said the spyware was never used in a domestic investigation and there is no evidence that either the Trump or Joe Biden administrations used spyware domestically.
In the face of increasing reports of abuse, including use of NSO’s spyware against American diplomats abroad, the Biden administration put NSO on a blacklist in 2021, saying the company’s tools had enabled foreign governments to conduct transnational repression and represented a threat to national security.
Biden also signed an executive order in 2023 that discouraged the use of spyware by the federal government and allowed it to be used in limited circumstances.
It was therefore a surprise when it was reported by Wired last year that the US Immigration and Customs Enforcement (Ice) agency had – under the Biden administration – signed a $2m one-year contract with Paragon. The contract was reportedly paused after the news became public and its current status is unclear. Ice did not respond to a request for comment.
A Paragon representative said the company was “deeply committed to following all US laws and regulations” and that it was fully compliant with the 2023 executive order signed by Biden. The person also pointed out that Paragon was now a US-owned company, following its takeover by AE Industrial Partners. It also has a US subsidiary based in Virginia, which is headed by John Fleming, a longtime veteran of the CIA who serves as executive chair.
Unlike its predecessor, however, the new US administration has publicly stated that it will seek to use the levers of government against Trump’s perceived political enemies. Trump has repeatedly said he would try to use the military to take on “the enemy from within”. He has also singled out career prosecutors who have investigated him, members of the military, members of Congress, intelligence agents and former officials who have been critical of him, for potential prosecution. He has never explicitly stated that he would use spyware against these perceived rivals.
Researchers like those at Citizen Lab and Amnesty Tech are considered the leading experts in detecting illegitimate surveillance against members of civil society, which have occurred in a number of democracies, including India, Mexico and Hungary.
Stephanie Kirchgaessner is the deputy head of investigations for Guardian US, based in Washington DC
_________
WhatsApp says journalists and civil society members were targets of Israeli spyware
Stephanie Kirchgaessner
The Guardian / January 31, 2025
Messaging app said it had ‘high confidence’ some users were targeted and ‘possibly compromised’ by Paragon Solutions spyware.
Washington – Nearly 100 journalists and other members of civil society using WhatsApp, the popular messaging app owned by Meta, were targeted by spyware owned by Paragon Solutions, an Israeli maker of hacking software, the company alleged on Friday.
The journalists and other civil society members were being alerted of a possible breach of their devices, with WhatsApp telling the Guardian it had “high confidence” that the 90 users in question had been targeted and “possibly compromised”.
It is not clear who was behind the attack. Like other spyware makers, Paragon’s hacking software is used by government clients and WhatsApp said it had not been able to identify the clients who ordered the alleged attacks.
Experts said the targeting was a “zero-click” attack, which means targets would not have had to click on any malicious links to be infected.
WhatsApp declined to disclose where the journalists and members of civil society were based, including whether they were based in the US.
Paragon has a US office in Chantilly, Virginia. The company has faced recent scrutiny after Wired magazine in October reported that it had entered into a $2m contract with the US Immigration and Customs Enforcement’s homeland security investigations division.
The division reportedly issued a stop-work order for the contract to verify whether it complied with a Biden administration executive order that restricted the use of spyware by the federal government. The Trump administration has revoked dozens of the Biden administration’s executive orders in its first two weeks in office, but the 2023 order, which prohibited the use of spyware that posed a risk to national security remains in effect.
WhatsApp said it had sent Paragon a “cease and desist” letter and that it was exploring its legal options. WhatsApp said the alleged attacks had been disrupted in December and that it was not clear how long the targets may have been under threat.
The company is currently notifying victims of the alleged hacking, who will be contacted by WhatsApp.
“WhatsApp has disrupted a spyware campaign by Paragon that targeted a number of users including journalists and members of civil society. We’ve reached out directly to people who we believe were affected. This is the latest example of why spyware companies must be held accountable for their unlawful actions. WhatsApp will continue to protect people’s ability to communicate privately,” a company spokesperson said.
Paragon Solutions declined to comment.
A person close to the company told the Guardian that Paragon had 35 government customers, that all of them could be considered democratic, and that Paragon did not do business with countries, including some democracies, that have previously been accused of abusing spyware. The person said that included Greece, Poland, Hungary, Mexico and India.
Paragon’s spyware is known as Graphite and has capabilities that are comparable to NSO Group’s Pegasus spyware. Once a phone is infected with Graphite, the operator of the spyware has total access to the phone, including being able to read messages that are sent via encrypted applications like WhatsApp and Signal.
The company, which was founded by the former Israeli prime minister Ehud Barak, has been the subject of media reports in Israel recently, after it was reported that the group was sold to a US private equity firm, AE Industrial Partners, for $900m.
Reports suggested the deal had not yet received full regulatory approval in Israel. Cyberweapons like Graphite and Pegasus are regulated by the Israeli ministry of defence. The Guardian reached out to AE Industrial Partners, which is based in Boca Raton, Florida. Paragon is not listed among the company’s investments on its website.
“For some time Paragon has had the reputation of a ‘better’ spyware company not implicated in obvious abuses, but WhatsApp’s recent revelations suggest otherwise. This is not just a question of some bad apples – these types of abuses are a feature of the commercial spyware industry,” said Natalia Krapiva, senior tech legal counsel at Access Now.
WhatsApp said it believed the so-called vector, or means by which the infection was delivered to users, was through a malicious pdf file that was sent to individuals who were added to group chats. WhatsApp said it could say with “confidence” that Paragon was linked to this targeting.
John Scott-Railton, a senior researcher at the Citizen Lab at the University of Toronto, which tracks and identifies digital threats against civil society, said Citizen Lab provided WhatsApp with some information that helped the company understand the vector that was used against the company’s users.
The group is expected to publish a report in the future that will provide more details about the alleged targeting.
WhatsApp announced the news just weeks after a judge in California ruled in the company’s favour in a landmark case against NSO Group, the high-profile spyware maker that in 2021 was placed by the Biden administration on a commerce department blacklist. At the time, the Biden administration said it had placed NSO on the so-called entity list because the company had engaged in activities “that are contrary to the national security or foreign policy interests of the United States”.
NSO has lobbied members of Congress to be taken off the list.
WhatsApp filed a lawsuit against NSO in 2019 after it said 1,400 users had been infected by the company’s spyware. In December, a judge, Phyllis Hamilton, ruled that NSO was liable for the attacks, and that NSO had violated state and federal US hacking laws and WhatsApp’s own terms of service.
Stephanie Kirchgaessner is the deputy head of investigations for Guardian US, based in Washington DC










