# Paragon CEO admits no spyware abuse safeguards

Published: 2026-10-08 · Severity: routine · Sectors: media, non-profit
Canonical: https://vorant.io/reports/7f1779a9-bf69-5629-88fc-2ea2c38952bb/paragon-ceo-admits-no-spyware-abuse-safeguards

> Paragon Solutions' CEO confirmed the company cannot detect or stop misuse of its mobile spyware, already used against Italian journalists and activists.

This WIRED/Citizen Lab piece examines Paragon Solutions, a US-based commercial spyware vendor that has marketed itself as more ethical than competitors like NSO Group by promising not to sell to governments with poor human rights records and to cut off abusive customers. Citizen Lab researchers confirmed in 2025 that Paragon's spyware was used to target Italian activists and journalists, prompting WIRED to interview Paragon CEO Andrew Boyd, who acknowledged the company has no technical means to detect customer misuse and lacks a 'kill switch' to disable access for abusive clients.

Citizen Lab senior researcher John Scott-Railton stated that Paragon has less oversight, transparency, and contractual protection against abuse than NSO Group, directly contradicting the image Paragon has cultivated. The article frames this as evidence that the commercial spyware industry cannot be trusted to self-regulate, reinforcing calls for external oversight and regulation of mercenary spyware vendors.

No technical indicators, malware names, CVEs, or infection chains are disclosed in this piece; it is a policy/accountability story rather than a technical threat report. Defenders in civil society, media, and human rights sectors should be aware that commercial mobile spyware from vendors claiming ethical safeguards may still be deployed against journalists and activists without effective oversight, and should continue to apply mobile hardening and Citizen Lab/Mobile Verification Toolkit style forensic checks for known spyware indicators from related Paragon research.

## Mentioned in this report

- Threat actors: Paragon Solutions

Source reporting: https://citizenlab.ca/the-secrets-of-a-us-spyware-king

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/7f1779a9-bf69-5629-88fc-2ea2c38952bb/paragon-ceo-admits-no-spyware-abuse-safeguards.
In the app the same report carries its extracted indicators, its detections with Splunk SPL and Microsoft KQL already written, live profiles of the actors and CVEs it names, and the vendor research on the same campaign. Slack alerts fire on the vendors, sectors and countries a reader follows. A new account starts with three days of all of it, no card: https://vorant.io/signup
