Paragon CEO admits no spyware abuse safeguards
Free public brief. The indicators, the detections with Splunk and KQL already written, and a Slack alert the next time this touches a vendor you run are in the app — free account, no card.
Paragon Solutions' CEO confirmed the company cannot detect or stop misuse of its mobile spyware, already used against Italian journalists and activists.
This WIRED/Citizen Lab piece examines Paragon Solutions, a US-based commercial spyware vendor that has marketed itself as more ethical than competitors like NSO Group by promising not to sell to governments with poor human rights records and to cut off abusive customers. Citizen Lab researchers confirmed in 2025 that Paragon's spyware was used to target Italian activists and journalists, prompting WIRED to interview Paragon CEO Andrew Boyd, who acknowledged the company has no technical means to detect customer misuse and lacks a 'kill switch' to disable access for abusive clients.
Citizen Lab senior researcher John Scott-Railton stated that Paragon has less oversight, transparency, and contractual protection against abuse than NSO Group, directly contradicting the image Paragon has cultivated. The article frames this as evidence that the commercial spyware industry cannot be trusted to self-regulate, reinforcing calls for external oversight and regulation of mercenary spyware vendors.
No technical indicators, malware names, CVEs, or infection chains are disclosed in this piece; it is a policy/accountability story rather than a technical threat report. Defenders in civil society, media, and human rights sectors should be aware that commercial mobile spyware from vendors claiming ethical safeguards may still be deployed against journalists and activists without effective oversight, and should continue to apply mobile hardening and Citizen Lab/Mobile Verification Toolkit style forensic checks for known spyware indicators from related Paragon research.
Mentioned in this report
Source reporting: https://citizenlab.ca/the-secrets-of-a-us-spyware-king
What this brief leaves out
This page is the free tier: the write-up, the severity, the names. In the app the same report carries its extracted indicators, its detections with the Splunk SPL and Microsoft KQL already written, the actors and CVEs it names as live profiles, and the vendor research on the same campaign — the primary source the news paraphrased, cited and read directly.
It sits in a corpus of 11,067 reports from 148 sources, 477 of them written in the last seven days, and it grows through the day.
A new account starts with three days of all of it, no card, then keeps the government and CERT reporting free. Name the vendors you run and Slack hears about the reports that touch them — about forty a week that are yours, not the four hundred that are not.
Create a free account What it costs