Skip to content

Product1 publisher3 min readPublished

Paragon relies on outsiders to catch misuse of its Graphite spyware

Paragon CEO Andrew Boyd says the spyware maker cannot see whom its customers target, and that halting updates leaves their systems ineffective in about 12 hours. Its promise to drop abusive customers therefore waits on outsiders finding the abuse first.

The Product Desk · Product desk

Illustration accompanying Paragon relies on outsiders to catch misuse of its Graphite spyware

What happened

  • Weeks after AE Industrial Partners bought Paragon in December 2024, WhatsApp alleged Graphite spyware had infected the phones of more than 60 people in more than 20 countries.
  • Most targets were never identified, but Citizen Lab named two journalists and two activists in Italy among them.
  • Within a week, Paragon canceled its two contracts with Italy's domestic and foreign intelligence agencies.
  • Paragon ran no investigation and did not ask WhatsApp or Citizen Lab whether customers in the other named countries should also lose their contracts, WIRED reported.
  • WIRED concluded that Paragon has less oversight and accountability than NSO Group, the Pegasus maker it prides itself on outdoing.

Compiled by The Product DeskSomething wrong?How this is made

Why it matters

  • contradiction Paragon's one enforcement action cannot be cited as proof the policy catches abuse, because the company never tested the allegation and Italy's investigators say there was nothing to find.
  • exposure Anyone targeted outside Italy is protected by the pledge only if a lab or a platform such as WhatsApp finds the infection and makes it public.
  • precedent Government clients now have a working standard: Paragon will drop a customer over public allegations once the relationship looks too risky, whether or not misuse is proven.

Cutting off a Paragon customer is a job for the support desk. The company has no kill switch, Boyd told WIRED, so its only lever is to stop the round-the-clock support and the system updates [13]. He will not say what the updates contain, only that they are frequent and essential to running the spyware [13]. "Things start falling apart quite quickly," he said [14].

Here is what Paragon promises: no sales to authoritarian regimes or governments with poor human rights records, and a cutoff for any customer caught using its tools on journalists, dissidents or other non-legitimate targets [1]. Here is what the product lets Paragon know. By Boyd's account, it hears about misuse in two ways: a customer admits it, or a third party uncovers it [11]. He credited WhatsApp and Citizen Lab with doing the company a great service by exposing the alleged abuse [12]. When WhatsApp first went public, Paragon declined to comment and was reportedly exploring legal action against it after WhatsApp sent a cease-and-desist letter [7].

Boyd's explanation for the Italian cancellations is short. The company "fired" Italy, he said, because it "just was not worth it, from a risk perspective, to maintain the relationship" [9]. Italian authorities denied misuse, and the government's investigators concluded the allegations were not true [6].

NSO Group cannot see its customers' targets either, according to its own transparency reports [16]. It says it does have a kill switch, and that its systems keep "tamper-proof" logs that customers are contractually bound to hand over when misuse is alleged, or face "immediate suspension" [16]. Those are NSO's descriptions of itself. At Paragon, Boyd says, logging is something customers can enable [17].

The pledge is about to reach a new set of readers. REDLattice, the AE-owned firm Paragon merged with [2], announced this week that it plans to go public [3]. Before the interview, REDLattice founder John Ayers wrote that the company was "not looking for a favorable write-up" [15]. "If the honest assessment is still damning, that's a conversation we're prepared to have," he wrote [15].

For a ministry signing a spyware contract or an investor looking at a REDLattice listing, two tests sort a misuse pledge. The first is detection: whether the vendor can learn of abuse without the customer or an outside lab telling it. The second is shutoff: whether it can stop a customer without that customer's cooperation. By their own accounts, NSO fails the first and claims to pass the second [16]. Paragon fails the first and passes the second only through the update dependency Boyd described [13]. A vendor that fails detection can enforce only after someone else publishes. In my view that makes Paragon's promise a reputational policy, triggered when an allegation goes public and the contract looks riskier than it is worth, as Boyd said of Italy [9].

What to watch

  • Whether REDLattice's public-listing documents describe Paragon's misuse policy, customer logging or shutoff controls.
  • Whether Paragon cuts off customers in any of the other countries WhatsApp named, and on what evidence.
  • Whether Paragon makes customer logging mandatory and contractual, as NSO says it does.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories