Six additional countries identified as suspected Paragon spyware customers
Full article965 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
Researchers found suspected Graphite deployments in Australia, Canada, Cyprus, Denmark, Israel and Singapore.
Listen to this article
0:00
Learn more.
Researchers have identified suspected government customers of spyware company Paragon Solutions in six more countries that hadn’t previously been publicly identified, according to a report published Wednesday.
The University of Toronto’s Citizen Lab said it mapped the infrastructure of Paragon’s Graphite tool after a tip from a collaborator, and found a subset of suspected Paragon deployments linked to Australia, Canada, Cyprus, Denmark, Israel and Singapore. It also found potential links between Paragon and the Ontario Provisional Police.
The report also shines additional light on Paragon infections of activists and others in Italy, revealed in January. Citizen Lab concluded from its research that Paragon, a relatively new entrant in the spyware marketplace, might not have done enough to prevent abuses despite its marketing stance.
“Overall, the cases described in this report suggest that Paragon’s claims of having found an abuse-proof business model may not hold up to scrutiny,” the report reads. “We acknowledge that this report does not seek to cover the totality of Paragon cases, but rather a set of cases where targets have chosen to come forward at this time and in our report.
“However, the pattern in these cases challenges Paragon’s marketing approach which has claimed that the company would only sell to clients that ‘abide by international norms and respect fundamental rights and freedoms,’” it continued.
The six countries did not immediately respond to requests for comment. The Ontario Provincial Police said in a statement that “the interception of private communications requires judicial authorization in accordance with the [Canadian] Criminal Code, and is only used to advance serious criminal investigations. … Releasing information about specific investigative techniques and technology could jeopardize active investigations and threaten public and officer safety.”
A Paragon official responded to the report by saying, in part, that it keeps clients confidential and may be legally restricted from speaking on national security and foreign policy matters.
“The brief summary of the report you sent includes several inaccuracies, but without additional details we cannot be more specific or provide comment for the record,” wrote John Fleming, executive vice chairman of Paragon. He didn’t elaborate on the inaccuracies when asked to do so by Citizen Lab.
Citizen Lab provided additional details in its report about Italian Paragon activity, including about a potential cluster targeting sea rescue operations for migrants in the Sahel and Sub-Saharan regions and the targeting of a personal friend of Pope Francis.
David Yambio, an Italian activist who is founder of the organization Refugees in Libya and whose phone Citizen Lab analyzed, said he was targeted by spyware during a period when he was sharing confidential information about torture victims with the International Criminal Court, The Guardian reported.
Italy has denied that it used spyware on journalists and activists.
Citizen Lab’s report worsens a “digital surveillance crisis” in Europe, said Donncha Ó Cearbhaill, Head of Amnesty International’s Security Lab.
“Of particular concern is the targeting of sea rescue organizations engaged in life-saving activities in the Mediterranean,” he said. “This adds a dangerous new digital threat to organizations already grappling with legal threats, obstruction and criminalization in Italy.”
This story was updated March 19, 2025, with comments from the Ontario police.
More Scoops
Pegasus, NoviSpy variant spyware found on devices of Serbian activists
It’s the first Pegasus infection of 2026 that Citizen Lab is forensically confirming, and the SHARE Foundation said it’s the biggest wave of spyware surveillance in Serbia…
Paragon spyware found on the phones of Euro journos
WhatsApp says it disrupted spyware campaign aimed at reporters, civil society
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
Jail time for Maine child in 764 marks turning point in federal law enforcement
Technology
FCC proposes public scorecard to rate telecoms on anti-robocall efforts
Wyden seeks upgraded NSA security guidance on commercial VPN use
The Collective Cyber Defense letter wrote your next vendor questionnaire
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Threats
Chinese espionage groups swarm to exploit triple-link chain of zero-days
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Election official says Tina Peters would be consultant, won’t have access to election systems
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/six-countries-suspected-paragon-spyware-customers/