Description: Researchers at Citizen Lab and Censys reportedly identified spyware infections involving Graphite, a tool attributed to Israeli firm Paragon Solutions. The spyware was allegedly deployed against civil society actors, including journalists and aid workers, through a zero-click WhatsApp exploit. WhatsApp notified over 90 targeted individuals. Evidence reportedly suggests deployments in multiple democratic countries.
Editor Notes: For the full report by Citizen Lab, please visit this URL: https://citizenlab.ca/2025/03/a-first-look-at-paragons-proliferating-spyware-operations/. Timeline notes: WhatsApp reportedly notified over 90 individuals of targeting with Paragon spyware on January 31, 2025. Subsequent investigation by Citizen Lab and Censys, published on March 19, 2025, identified additional infrastructure and implicated law enforcement agencies in multiple democratic countries. This record uses January 31, 2025 as the incident date based on first confirmed exposure.
Entities
View all entitiesAlleged: REDLattice and Paragon Solutions developed an AI system deployed by York Regional Police Service (Ontario, Canada) , Unidentified law enforcement or intelligence entity (Singapore) , Unidentified law enforcement or intelligence entity (Israel) , Unidentified law enforcement or intelligence entity (Denmark) , Unidentified law enforcement or intelligence entity (Cyprus) , Unidentified law enforcement or intelligence entity (Australia) , Peel Regional Police (Ontario, Canada) , Ontario Provincial Police , Hamilton Police Service (Ontario, Canada) , External Intelligence and Security Agency , AISE and Agenzia Informazioni e Sicurezza Esterna, which harmed Refugees in Libya , Mediterranea Saving Humans , Luca Casarini , Journalists , Humanitarian workers , Giuseppe "Beppe" Caccia , General public of countries in which Graphite is being deployed , Francesco Cancellato , Fanpage.it , David Yambio , Civil society workers and Activists.
Incident Stats
Incident ID
1069
Report Count
2
Incident Date
2025-01-31
Editors
Daniel Atherton
Incident Reports
Reports Timeline
AIID editor's note: Please read the original source for the full report. It can be accessed here: https://citizenlab.ca/2025/03/a-first-look-at-paragons-proliferating-spyware-operations/.
Key Findings
-
Introducing Paragon Solutions. Parago…
Researchers are beginning to unravel global surveillance operations targeting journalists, humanitarian aid workers, and other civilians via messaging apps.
On Jan. 31, WhatsApp contacted more than 90 individuals whom it believed had been t…
Variants
A "variant" is an incident that shares the same causative factors, produces similar harms, and involves the same intelligent systems as a known AI incident. Rather than index variants as entirely separate incidents, we list variations of incidents under the first similar incident submitted to the database. Unlike other submission types to the incident database, variants are not required to have reporting in evidence external to the Incident Database. Learn more from the research paper.