Skip to content

Executive Summary

Spyware maker Paragon Solutions, acquired by US equity firm AE Industrial Partners in December 2024 and merged with the American offensive cyber firm REDLattice, was alleged by WhatsApp to have used its Graphite spyware to infect over 60 individuals in more than 20 countries, including journalists and activists. While Italian authorities denied misuse, Paragon canceled contracts with domestic and foreign intelligence agencies within a week of receiving a cease-and-desist letter from WhatsApp. The former Paragon executive, Andrew Boyd, later admitted that the decision to cancel contracts with Italy was based on risk assessment rather than a full investigation, as the company claimed it lacked the technical means to monitor customer misuse or enforce a "kill switch." Boyd stated that the company can only halt support and updates, not disable the software, and that frequent updates are essential for system effectiveness. The company's governance model relies on vetting customers based on criteria like political stability and human rights records, aiming to reject countries deemed high-risk. Despite this, critics argue Paragon/RedLattice has less oversight than competitors like NSO Group.

Facts Only

* Paragon Solutions was acquired by AE Industrial Partners in December 2024 and merged with REDLattice.
* WhatsApp alleged that Paragon’s Graphite spyware infected phones of over 60 individuals in more than 20 countries, including journalists and activists.
* The University of Toronto’s Citizen Lab named two journalists and two activists in Italy as targets.
* Paragon canceled contracts with Italy’s domestic and foreign intelligence agencies within a week after receiving a cease-and-desist letter from WhatsApp.
* Andrew Boyd stated the decision to cancel Italian contracts was based on risk assessment rather than a Paragon investigation.
* Boyd claimed Paragon has no technical means to know if customers misuse the software.
* Paragon can halt 24-hour support and system "updates" but does not have a kill switch.
* Customer vetting involves assessing criteria such as political stability, human rights records, and legal system strength.
* Paragon sells primarily to the US and select US allies and national entities.
* The company reportedly signed a contract with Homeland Security Investigations and RedLattice has contracts with the US Air Force.

Full Take

The narrative surrounding Paragon’s governance reveals a fundamental tension between the pursuit of security, commercial viability, and genuine accountability in the offensive cyber industry. The executive's admission that decisions were based on risk avoidance rather than comprehensive investigation, and the inability to track misuse, suggests a systemic prioritization of business continuity over transparency when facing public exposure. This reflects a broader pattern where entities operating in sensitive domains—regardless of their stated intent to be "good guys"—establish internal mechanisms designed to insulate themselves from liability, often by shifting the burden of proof onto external auditors or victims. The comparison drawn between Paragon’s limited oversight and NSO Group's contractually mandated logging highlights how accountability is functionally constructed; those with more oversight establish verifiable systems (like NSO's tamper-proof logs) that create explicit legal liabilities for misuse, whereas Paragon relies on self-regulation and reputation management. The fact that the vetting process itself involves rejecting entire nations based on abstract criteria like "political stability" suggests a projection of control rather than genuine protection; this introduces the risk that governance structures are themselves tools of exclusion, potentially leading to a scenario where the very definitions used to protect privacy are applied selectively. This raises the question of whether the pursuit of a balanced 'middle ground' is merely a more sophisticated form of evasion against true scrutiny.
* BRIDGE QUESTIONS: How does the reliance on voluntary vetting, rather than mandatory, verifiable logging, fundamentally alter the relationship between state actors and commercial spyware vendors? What are the long-term societal costs when accountability is framed as a negotiable business risk rather than an immutable ethical requirement? If organizations lack direct access to logs, what institutional mechanisms—beyond individual dissent—can effectively enforce ethical use in systems designed for mass surveillance?

From the original · Wired - Security

Spyware maker Paragon Solutions has long positioned itself as the good guy in an industry seemingly filled with bad ones, vowing to never sell its mobile spyware to authoritarian regimes or ones with poor human rights records. It also promises to cut off any customer caught misusing its products against journalists, dissidents, or other non-legitimate targets.
Read the full story at wired.com

Sentinel — Human

Confidence

The text reads like a detailed investigative piece that synthesizes complex business, security, and ethical allegations, featuring personal admissions that anchor the narrative in human-driven conflict rather than purely synthetic argumentation.

Signals Detected
low severity: Sentence length variance shows natural shifts in pace and complexity; vocabulary remains specialized but flows contextually.
low severity: The argument transitions smoothly between factual reporting, executive admission, internal corporate policy, and external critique without becoming purely abstract or detached.
low severity: The text relies on weaving together multiple disparate claims (Paragon's history, acquisition details, executive quotes, and expert commentary) which suggests a human editorial structure rather than template matching.
low severity: Specific internal admissions (Boyd's comments on vetting and risk assessment) are presented as direct evidence, lending weight that is characteristic of investigative journalism sourcing, rather than pure LLM generation.
Human Indicators
The incorporation of specific, detailed quotes from an executive (Boyd), external researchers (Scott-Railton), and political figures (Wyden) integrated into the narrative structure suggests sourcing beyond simple data recitation.
The analysis pivots effectively between corporate maneuvering, geopolitical context (Israeli origins, US sanctions), and ethical implications, displaying thematic depth.
The Secrets of the US Spyware King | Huntaegis