Purported Graphite Spyware Linked to Paragon Solutions Allegedly Deployed Against Journalists and Civil Society Workers

Paragon Solutions' Graphite spyware was used in a zero-click campaign to compromise the devices of nearly 100 journalists and civil society members globally. The exploit involved sending malicious PDF files via WhatsApp group chats, allowing the spyware to bypass security and access encrypted communications. Following the disclosure, Paragon terminated its contract with Italy, and WhatsApp implemented server-side mitigations to block the attack vector.

Researchers at Citizen Lab and Censys reportedly identified spyware infections involving Graphite, a tool attributed to Israeli firm Paragon Solutions. The spyware was allegedly deployed against civil society actors, including journalists and aid workers, through a zero-click WhatsApp exploit. WhatsApp notified over 90 targeted individuals. Evidence reportedly suggests deployments in multiple democratic countries.

Source: AI Incident Database

Risk classification

  • Primary risk domain: 4 Malicious actors
  • Primary risk subdomain: 4.1 Disinformation, surveillance, and influence at scale

The incident involves the coordinated use of sophisticated spyware by state actors to conduct malicious surveillance at scale against journalists and human rights defenders.

Additional risk subdomains

  • 2.1 Compromise of privacy by obtaining, leaking or correctly inferring sensitive information: The spyware compromised the privacy of targeted individuals by covertly accessing and extracting non-public sensitive data from their personal devices.

Causal factors

  • Entity: Human
  • Intent: Intentional
  • Timing: Post-deployment

The incident was driven by human decisions to deploy surveillance software against civil society targets post-deployment.

EU AI Act risk tier

  • Risk tier: 2 High Risk

High Risk: The system is a surveillance tool deployed by law enforcement and intelligence agencies, which has significant implications for fundamental rights and public interest.

AI system and alleged parties

  • AI system: Graphite (Paragon Solutions)
  • AI purpose: Smart Surveillance; Activity Tracking
  • Behaviour type: Tool
  • Alleged developer: REDLattice, Paragon Solutions
  • Alleged deployer: York Regional Police Service (Ontario, Canada), Unidentified law enforcement or intelligence entity (Singapore), Unidentified law enforcement or intelligence entity (Israel), Unidentified law enforcement or intelligence entity (Denmark), Unidentified law enforcement or intelligence entity (Cyprus), Unidentified law enforcement or intelligence entity (Australia), Peel Regional Police (Ontario, Canada), Ontario Provincial Police, Hamilton Police Service (Ontario, Canada), External Intelligence and Security Agency, AISE, Agenzia Informazioni e Sicurezza Esterna
  • Alleged harmed parties: Refugees in Libya, National security and intelligence stakeholders, Mediterranea Saving Humans, Luca Casarini, Journalists, Humanitarian workers, Giuseppe "Beppe" Caccia, General public of countries in which Graphite is being deployed, Francesco Cancellato, Fanpage.it, David Yambio, Civil society workers, Ciro Pellegrino, Activists

Harm severity

Highest direct severity in any category: Substantial. Severity is scored from Negligible to Catastrophic in each harm category, for harm the reports describe as caused directly or indirectly by the AI system.

  • Physical: direct Negligible, indirect Negligible
  • Infrastructure: direct Negligible, indirect Negligible
  • Property: direct Negligible, indirect Negligible
  • Financial: direct Negligible, indirect Negligible
  • Environmental: direct Negligible, indirect Negligible
  • Malicious content: direct Negligible, indirect Negligible
  • Differential treatment: direct Negligible, indirect Negligible
  • Civil rights: direct Minor, indirect Minor
  • Democracy: direct Minor, indirect Minor
  • Privacy: direct Minor, indirect Minor
  • Psychological: direct Negligible, indirect Negligible
  • Epistemic: direct Negligible, indirect Negligible
  • Child sexual exploitation and abuse: direct Negligible, indirect Negligible

Civil rights

Reported: The report explicitly describes violations of human and civil rights, specifically targeting journalists and human rights defenders.

Directly caused: The deployment of Graphite spyware directly violated the rights to freedom of expression, press freedom, and association for approximately 90 targeted journalists and activists.

Indirectly caused: The surveillance created a chilling effect on civil society, hindering the ability of activists to safely advocate for human rights and protect confidential sources.

Inferred additional harm: It is likely that other unnamed civil society members and journalists were targeted, leading to broader, unrecorded violations of civil liberties and human rights across the affected countries.

Democracy

Reported: The report explicitly describes the erosion of democratic norms caused directly or indirectly by the incident.

Directly caused: State-sponsored surveillance of journalists and political critics directly undermines democratic accountability and press freedom.

Indirectly caused: The misuse of spyware by democratic governments like Italy and potentially Canada erodes public trust in state institutions and legal oversight mechanisms.

Inferred additional harm: The proliferation of unregulated commercial spyware threatens democratic governance globally by providing state actors with tools to covertly suppress dissent and monitor political opponents.

Privacy

Reported: The report explicitly describes severe privacy violations caused directly by the spyware.

Directly caused: The Graphite spyware covertly accessed and extracted private messages, call records, and sensitive personal data from the mobile devices of approximately 90 notified individuals.

Indirectly caused: The exploit compromised the end-to-end encryption expectations of users on messaging platforms like WhatsApp.

Inferred additional harm: Given that Android logs are sporadic and some targets may not have been detected, it is highly likely that many more individuals had their private communications compromised without their knowledge.

People affected

  • Occurrences reported: 1
  • People reportedly harmed: 90
  • People reportedly exposed: 90

Potential causes

Management

  • Ethical Safeguard Failure: Paragon's claimed safeguards failed to prevent the targeting of civil society.
  • Prioritization of Profit: Commercial vendors sold invasive tools globally to expand lucrative markets.
  • Lack of Client Oversight: Management failed to adequately monitor how clients used their software.

Technology

  • Zero-Click Zero-Day Vulnerability: Exploited auto-parsing in WhatsApp to load spyware without user interaction.
  • Sandbox Escape Capabilities: Spyware escaped Android sandbox to compromise other applications on devices.
  • Server-Side Impersonation: Bypassed device security by impersonating users on messaging platform servers.

Data Inputs

  • Malicious PDF Data Payload: Specially crafted PDF files triggered the zero-day exploit during auto-parsing.
  • Target Phone Numbers and IDs: Attackers used target phone numbers to add them to malicious group chats.

Human Factors

  • Unwitting Exposure by Operators: Government employees exposed infrastructure through poor operational security.
  • Targeting of Civil Society: Clients targeted journalists and activists instead of criminals or terrorists.

Process and Methods

  • Automatic Parsing of Documents: Messaging apps automatically parsed incoming PDFs, triggering the exploit.
  • Inadequate Independent Auditing: Invasive spyware products cannot be independently audited for human rights.
  • Weak Operational Security: Paragon left digital fingerprints like exposing server pages titled 'Paragon'.

Regulatory Environment

  • Lack of Binding AI Regulations: No binding national or international legislation governs AI and spyware tools.
  • Laissez-Faire Surveillance Policy: European authorities failed to implement PEGA recommendations on spyware.
  • Unregulated Dual-Use Exports: Israeli defense export controls failed to prevent sales to abusive clients.

Information quality

  • Classification confidence: High
  • Reason for confidence: The reports provide consistent, detailed, and cross-verified accounts from highly credible sources like Citizen Lab, Meta, and Amnesty International regarding the spyware's mechanism, targets, and the resulting actions taken by WhatsApp and Paragon.
  • Ambiguities identified: The exact identity of the government clients who initiated the specific attacks remains unconfirmed, though several countries are suspected deployments.
  • Alternative interpretations: None. The consensus across all reports is that this was a targeted state-sponsored surveillance campaign using commercial spyware.

A global surveillance campaign utilized Paragon Solutions' Graphite spyware to target journalists and civil society members via a zero-click WhatsApp exploit. The incident represents a substantial threat to information security and human rights, highlighting the ongoing national security challenges posed by the proliferation of commercial cyber-surveillance tools.

  • Overall national security impact: Substantial
  • Response level: Substantial
  • Scope: Multiple nations
  • Primary target: No clear primary
  • Other affected: Italy, Australia, Canada, Cyprus, Denmark, Israel, Singapore
  • Alleged perpetrator: Multiple state governments

Threat characteristics

  • Imminence: Long-term. The active campaign was disrupted and patched, representing an ongoing strategic concern regarding commercial spyware capabilities rather than an immediate crisis.
  • Autonomy: Human-controlled. The spyware operates as a highly specialized tool requiring human operators to target and initiate campaigns, without autonomous decision-making.
  • Novelty: Evolved capability. Represents an evolved capability in the established domain of zero-click commercial spyware, utilizing new vulnerability vectors.

Impact by dimension

  • Physical security: Negligible. No physical security threat, kinetic targeting, or critical infrastructure compromise was reported in this incident.
  • Information security: Substantial. Substantial intelligence security compromise via zero-click spyware targeting encrypted communications of journalists and civil society, potentially exposing sensitive sources.
  • Sovereignty: Minor. Limited direct threat to sovereignty, though it involves state agencies utilizing foreign-developed spyware to monitor civil society, raising domestic oversight concerns.
  • Economic security: Minor. Minor impact on economic security, primarily involving the commercial trade and acquisition of advanced cyber-surveillance tools.
  • Societal stability: Substantial. Notable impact on human rights and civil liberties, as the spyware directly targeted journalists and activists, threatening freedom of expression and press freedom.
Explore in the interactive Incident Tracker