Skip to Content
logologo
AI Incident Database
Open TwitterOpen RSS FeedOpen FacebookOpen LinkedInOpen GitHub
Open Menu
Discover
Submit
  • Welcome to the AIID
  • Discover Incidents
  • Spatial View
  • Table View
  • List view
  • Entities
  • Taxonomies
  • Submit Incident Reports
  • Submission Leaderboard
  • Blog
  • AI News Digest
  • Risk Checklists
  • Random Incident
  • Sign Up
Collapse
Discover
Submit
  • Welcome to the AIID
  • Discover Incidents
  • Spatial View
  • Table View
  • List view
  • Entities
  • Taxonomies
  • Submit Incident Reports
  • Submission Leaderboard
  • Blog
  • AI News Digest
  • Risk Checklists
  • Random Incident
  • Sign Up
Collapse

Incident 1069: Purported Graphite Spyware Linked to Paragon Solutions Allegedly Deployed Against Journalists and Civil Society Workers

Description: Researchers at Citizen Lab and Censys reportedly identified spyware infections involving Graphite, a tool attributed to Israeli firm Paragon Solutions. The spyware was allegedly deployed against civil society actors, including journalists and aid workers, through a zero-click WhatsApp exploit. WhatsApp notified over 90 targeted individuals. Evidence reportedly suggests deployments in multiple democratic countries.
Editor Notes: For the full report by Citizen Lab, please visit this URL: https://citizenlab.ca/2025/03/a-first-look-at-paragons-proliferating-spyware-operations/. Timeline notes: WhatsApp reportedly notified over 90 individuals of targeting with Paragon spyware on January 31, 2025. Subsequent investigation by Citizen Lab and Censys, published on March 19, 2025, identified additional infrastructure and implicated law enforcement agencies in multiple democratic countries. This record uses January 31, 2025 as the incident date based on first confirmed exposure.

Tools

New ReportNew ReportNew ResponseNew ResponseDiscoverDiscoverView HistoryView History

Entities

View all entities
Alleged: REDLattice and Paragon Solutions developed an AI system deployed by York Regional Police Service (Ontario, Canada) , Unidentified law enforcement or intelligence entity (Singapore) , Unidentified law enforcement or intelligence entity (Israel) , Unidentified law enforcement or intelligence entity (Denmark) , Unidentified law enforcement or intelligence entity (Cyprus) , Unidentified law enforcement or intelligence entity (Australia) , Peel Regional Police (Ontario, Canada) , Ontario Provincial Police , Hamilton Police Service (Ontario, Canada) , External Intelligence and Security Agency , AISE and Agenzia Informazioni e Sicurezza Esterna, which harmed Refugees in Libya , Mediterranea Saving Humans , Luca Casarini , Journalists , Humanitarian workers , Giuseppe "Beppe" Caccia , General public of countries in which Graphite is being deployed , Francesco Cancellato , Fanpage.it , David Yambio , Civil society workers and Activists.
Alleged implicated AI systems: WhatsApp , iOS , Graphite (Paragon spyware) , Cloudflare and Android

Incident Stats

Incident ID
1069
Report Count
2
Incident Date
2025-01-31
Editors
Daniel Atherton

Incident Reports

Reports Timeline

Incident OccurrenceVirtue or Vice? A First Look at Paragon’s Proliferating Spyware OperationsNation-State 'Paragon' Spyware Infections Target Civil Society
Virtue or Vice? A First Look at Paragon’s Proliferating Spyware Operations

Virtue or Vice? A First Look at Paragon’s Proliferating Spyware Operations

citizenlab.ca

Nation-State 'Paragon' Spyware Infections Target Civil Society

Nation-State 'Paragon' Spyware Infections Target Civil Society

darkreading.com

Virtue or Vice? A First Look at Paragon’s Proliferating Spyware Operations
citizenlab.ca · 2025

AIID editor's note: Please read the original source for the full report. It can be accessed here: https://citizenlab.ca/2025/03/a-first-look-at-paragons-proliferating-spyware-operations/.

Key Findings

  • Introducing Paragon Solutions. Parago…

Nation-State 'Paragon' Spyware Infections Target Civil Society
darkreading.com · 2025

Researchers are beginning to unravel global surveillance operations targeting journalists, humanitarian aid workers, and other civilians via messaging apps.

On Jan. 31, WhatsApp contacted more than 90 individuals whom it believed had been t…

Variants

A "variant" is an incident that shares the same causative factors, produces similar harms, and involves the same intelligent systems as a known AI incident. Rather than index variants as entirely separate incidents, we list variations of incidents under the first similar incident submitted to the database. Unlike other submission types to the incident database, variants are not required to have reporting in evidence external to the Incident Database. Learn more from the research paper.
Previous IncidentNext Incident

Research

  • Defining an “AI Incident”
  • Defining an “AI Incident Response”
  • Database Roadmap
  • Related Work
  • Download Complete Database

Project and Community

  • About
  • Contact and Follow
  • Apps and Summaries
  • Editor’s Guide

Incidents

  • All Incidents in List Form
  • Flagged Incidents
  • Submission Queue
  • Classifications View
  • Taxonomies

2024 - AI Incident Database

  • Terms of use
  • Privacy Policy
  • Open twitterOpen githubOpen rssOpen facebookOpen linkedin
  • 86fe0f5