// WIRED US/UK — CYBERSECURITY
The Secrets of the US Spyware King
Spyware maker Paragon Solutions has long positioned itself as the good guy in an industry seemingly filled with bad ones, vowing to never sell its mobile spyware to authoritarian regimes or ones with poor human rights records. It also promises to cut off any customer caught misusing its products against journalists, dissidents, or other non-legitimate targets.
Yet weeks after Paragon, then Israeli-owned, was acquired by the US equity firm AE Industrial Partners in December 2024 and merged with REDLattice—an American offensive cyber firm owned by AE that this week announced plans to go public—WhatsApp alleged that Paragon’s Graphite spyware was used to infect the phones of more than 60 individuals in more than 20 countries, including journalists and activists. Most of the targets were not identified, but the University of Toronto’s Citizen Lab named two journalists and two activists in Italy.
Italian authorities denied misuse. Paragon and its new US owners, despite their zero-tolerance policy for customer abuse of their software, initially declined to comment on the allegations, and reportedly was exploring potential legal action against WhatsApp after the company sent a cease-and-desist letter to Paragon. Within a week, however, Paragon had canceled the two contracts it had with Italy’s domestic and foreign intelligence agencies.
From the outside, it seemed Paragon must have conducted an investigation and verified the allegations before canceling the contracts. But Paragon and RedLattice’s new CEO, Andrew Boyd, now says in an exclusive and surprisingly candid interview with WIRED that the company simply “fired” Italy because it “just was not worth it, from a risk perspective, to maintain the relationship” following the allegations.
In other words, there was no Paragon investigation and no interest in conducting one to determine if the allegations were true—Italian government investigators concluded they were not. Paragon didn’t even follow up with WhatsApp or Citizen Lab to obtain details about the alleged abuse and determine if any contracts in the other countries named by WhatsApp should be canceled as well. More damning, according to critics, is what Boyd revealed next: Paragon has no technical way to know if customers misuse its software, because it can’t see who customers target or the data they extract from targeted devices. It can only learn about misuse if customers admit to it or third parties uncover it. He says WhatsApp and Citizen Lab did the company a great service when they exposed the alleged misuse last year.
Paragon also doesn’t have a “kill switch” to disable customers when misuse occurs. All they can do is halt customers’ 24-hour support and system “updates.” But Boyd says the updates, the nature of which he won’t specify, are frequent and essential to using the spyware, and without them the system is rendered ineffective in about 12 hours.
“Things start falling apart quite quickly,” he says.
Boyd’s comments mark the first time a Paragon executive has spoken in detail about the secretive company or its handling of the Italian affair. He agreed to speak with WIRED now because he says more public discussion is needed about the offensive cyber industry and what it means for a US company to operate responsibly in this space. Prior to the interview, REDLattice founder John Ayers wrote in an email that they were “not looking for a favorable write-up.”
“If the honest assessment is still damning, that's a conversation we're prepared to have,” he wrote.
But Boyd’s admissions reveal that despite priding itself on being better than competitors, Paragon/RedLattice has less oversight and accountability than its most significant one—NSO Group, the Pegasus spyware maker, which has been excoriated for selling its tool to Saudi Arabia and other countries with poor human rights records. According to NSO’s transparency reports, which the company began publishing in recent years in response to criticism, it sets up inf