Inside Paragon: The US-Backed Offensive Cyber Firm Facing Fresh Scrutiny Over Oversight and Logging DeficitsSecurity
1 Oct 2026, 3:48 pm (26 min ago)· 0

Inside Paragon: The US-Backed Offensive Cyber Firm Facing Fresh Scrutiny Over Oversight and Logging Deficits

The chief executive of newly American-owned Paragon and REDLattice has confirmed the company cannot monitor how foreign clients deploy its Graphite spyware. Following contract terminations in Italy and WhatsApp allegations, cybersecurity experts warn about self-regulation gaps.

The commercial spyware industry underwent a dramatic consolidation when the Israeli-founded offensive surveillance firm Paragon was acquired in December 2024 by American private equity group AE Industrial Partners. Soon merged with REDLattice, a US-based offensive cyber contractor owned by the same private equity firm that recently revealed ambitions to go public, the combined entity seemed positioned to capture the American defense market. However, only weeks following the transaction, encrypted communications service WhatsApp asserted that Paragon's flagship surveillance tool, known as Graphite, had been weaponized against more than 60 individuals located in over 20 countries. Among those targeted were journalists and political activists, with the Citizen Lab at the University of Toronto identifying four specific victims in Italy, split evenly between reporters and civil society organizers.

Italian authorities swiftly rejected claims of unauthorized surveillance, while Paragon and its fresh American leadership initially refrained from public statements, exploring potential legal action after WhatsApp served a cease-and-desist demand. Yet within one week, the vendor took decisive action by canceling two separate contracts with Italy's domestic and foreign intelligence branches. While industry observers assumed the cancellation followed a rigorous internal technical audit to verify the surveillance claims, REDLattice and Paragon chief executive officer Andrew Boyd has clarified that the company simply severed ties with Rome because the public relations exposure and ongoing risk made maintaining the relationship economically unviable.

Also read

The Abrupt Exit From Italy and Absence of Inquiries

Andrew Boyd stated that there was never any formal internal investigation conducted by the company to verify the truth of the allegations surrounding the Italian agencies. Italian state investigators later concluded that no illegal activity took place, but Paragon declined to examine the underlying forensic logs or review target lists. Furthermore, the company did not reach out to WhatsApp or the Citizen Lab to request technical indicators that could help determine whether operations conducted by clients in the other 19 nations flagged in the original alert warranted contract cancellations as well.

This managerial reaction underscores how defensive legal maneuvers frequently replace comprehensive operational audits within the private intelligence sector. By terminating the contract without examining the technical footprints, the company insulated its bottom line against public backlash while leaving unexamined whether the surveillance software had indeed been turned against civil society members.

The Structural Absence of Usage Visibility and System Logs

Perhaps the most concerning revelation regarding the operation of Graphite is that Paragon lacks any remote technical apparatus to observe how purchasing agencies deploy the software. The vendor cannot inspect targeted device identifiers, intercept the transmission of exfiltrated data, or see customer analytical queries. Because it operates in total technical blindness once the software is deployed, the firm can learn of improper surveillance only if a customer volunteers the information or if independent external entities discover and document the infection.

When compared to NSO Group, the developer behind the Pegasus spyware suite, this operational model reveals surprising accountability differences. Despite facing intense global condemnation and sanctions for transactions with regimes carrying dismal human rights track records, NSO Group has established a framework in its transparency disclosures asserting the existence of a central kill switch that allows engineers to shut off client access when abuse is alleged. Moreover, NSO mandates tamper-resistant logging on client infrastructure, legally compelling customers to submit these records during investigations or face immediate service suspension.

In sharp contrast, Boyd noted that Paragon allows customers to activate logging mechanisms optionally on selected systems, but Paragon retains no administrative access to those files and has no desire to see them. The executive argued that retaining such visibility would destroy the company's business model, as sovereign security services refuse to procure surveillance platforms if a vendor can scrutinize their classified targets and sensitive operational logs. While oversight bodies such as parliamentary committees can technically review these local logs, this creates an environment where internal state investigators might conceal operational abuses uncovered during domestic reviews, knowing the vendor will never inspect the records independently.

Relying on Updates Rather Than a Kill Switch

Unlike competing surveillance platforms that integrate emergency shutdown mechanisms, Paragon maintains no software kill switch capable of disabling rogue client infrastructure at will. Instead, the firm's sole enforcement mechanism rests on halting technical customer support and suspending the delivery of ongoing software updates.

According to Boyd, these updates are both frequent and vital to the functional persistence of the spyware. Because modern mobile operating systems continuously modify their internal architecture and security patches, the hacking modules degrade rapidly without continuous vendor calibration. Without these proprietary updates, the surveillance system becomes nonfunctional within roughly 12 hours. While the company views this dependency as an effective operational leash, critics emphasize that a 12-hour window provides ample runway for sensitive data exfiltration before a system degrades.

Independent Observers and Lawmakers Voice Alarm

John Scott-Railton, a senior researcher at the Citizen Lab who has tracked unlawful state hacking campaigns for over a decade, described the vendor's admission of zero operational visibility and the absence of mandatory audit logs as irresponsible. He noted that Paragon's operational structure offers substantially less transparency, weaker oversight, and fewer contractual guardrails against misuse than even NSO Group. By acknowledging that clients will not tolerate vendor scrutiny, the leadership effectively confirmed that independent oversight conflicts directly with profitability in the offensive surveillance trade, demonstrating that commercial vendors cannot be trusted to regulate themselves.

Scott-Railton also pointed out the deep irony in a vendor relying on academic watchdogs to uncover client abuses when the primary engineering objective of the company is to make its malware completely undetectable. Because surveillance developers spend millions of dollars concealing infections, civil society researchers succeed in documenting only a minute fraction of all actual deployments, meaning the real scale of misuse remains substantially higher than documented incidents.

United States Senator Ron Wyden expressed severe criticism of the vendor's posture, maintaining that unmonitored surveillance tools inevitably lead to widespread civil rights violations. Wyden noted that it is easy for an offensive hacking company to claim its tools remain uncompromised by abuse when management intentionally structures the technology so it cannot see what customers are doing. He stated that Paragon's refusal to audit customer deployments or match the investigative diligence of independent researchers constitutes a profound warning sign for federal regulators.

Origins in Unit 8200 and the Race for American Capital

Paragon was established in 2019 by Brigadier General Ehud Schneorson, the former commander of the Israeli military's signals intelligence organization, Unit 8200. Schneorson established the firm alongside three fellow veterans of the intelligence unit and former Israeli Prime Minister Ehud Barak. Although the enterprise spent its initial two years without revenue while perfecting Graphite, its long-term corporate target was always the highly lucrative United States intelligence and defense market.

However, the global market shifted drastically when the United States Commerce Department intervened in 2021 by placing export sanctions on foreign spyware manufacturers NSO Group and Candiru following evidence that Pegasus and DevilsTongue were deployed against diplomats, journalists, dissidents, and academic researchers. Simultaneously, the Israeli defense establishment slashed the roster of authorized export destinations from 102 nations down to 37, banning shipments to Saudi Arabia, the United Arab Emirates, Morocco, and Mexico. Legislative directives from Congress and executive orders under the Biden administration subsequently blocked American agencies from purchasing foreign-manufactured commercial spyware that presented counterintelligence or human rights risks.

While Paragon had secured a modest foothold by supplying the Drug Enforcement Administration with tools targeting foreign narcotics cartels outside US borders, broader federal acquisition remained blocked by its foreign ownership structure. To circumvent these regulatory restrictions, AE Industrial Partners purchased Paragon in December 2024 for an estimated 900 million dollars, executing an acquisition that re-domiciled the company as an American corporation on paper.

The Cross-Border Corporate Architecture

Despite being reorganized under REDLattice in the United States, Paragon functions largely as an Israeli enterprise in its operational reality. While Paragon maintains no independent web footprint and REDLattice makes no mention of the entity on its primary corporate site, the business retains its Tel Aviv engineering facilities staffed by more than 600 personnel. Furthermore, any hardware or software developed on Israeli soil remains subject to export licensing requirements administered by the Israeli Ministry of Defense, while REDLattice products provided to international buyers fall under the jurisdiction of the United States International Traffic in Arms Regulations.

REDLattice founder John Ayers indicated that the private equity firm spent more than two years consulting with national security authorities before concluding the acquisition. Boyd stated that while federal entities never issue formal endorsements of private mergers, officials from the National Security Council and related agencies raised no structural objections or mandatory compliance stipulations prior to closing. Following this precedent, competing foreign vendors mirrored the strategy: a US investment consortium acquired controlling authority over NSO Group, installing David Friedman, who served as US ambassador to Israel under President Donald Trump, as executive chairman. Concurrently, Candiru was acquired by the American firm Integrity Partners, creating an environment where three historically Israeli surveillance suites now compete under American flags.

Executive Background and Product Breadth

Andrew Boyd assumed executive leadership over both REDLattice and Paragon eight months after the consolidation, leveraging a background that includes service as a military intelligence officer, diplomatic assignments within the State Department, and tenure as director of the Central Intelligence Agency's Center for Cyber Intelligence until his departure from public service in 2023. This background provides the vendor with direct channels into American defense, covert intelligence, and homeland security agencies.

The combined entity maintains a product catalog ranging between five and 10 distinct systems, an expansion from the fewer than five tools Paragon operated prior to the merger. These technologies encompass both remote data collection mechanisms and tactical platforms requiring hands-on interaction with physical devices. Although Boyd resists the spyware label, characterizing the products as defensive capabilities designed to neutralize state adversaries and organized criminal syndicates, their technical architecture serves intrusive electronic surveillance and offensive digital operations.

Graphite operates by extracting messages directly from secured, end-to-end encrypted messaging applications such as WhatsApp and Signal. Unlike Pegasus, which provides complete administrative control over a mobile device, including covert camera and microphone activation, Graphite focuses primarily on message extraction, though modular extensions can expand its capabilities. It utilizes zero-click, zero-day vulnerabilities that compromise target devices without requiring any user engagement. REDLattice reinforces this engineering with an internal staff of over 200 vulnerability research specialists.

In addition to software suites, the firms supply tailored engineering tools and contract-cleared operational specialists to select clients. As the Trump administration moves forward with plans to contract commercial offensive cyber companies to strike organized cybercrime cartels overseas, REDLattice has confirmed its intent to bid on these operational government task orders.

Customer Vetting and Geographic Constraints

Lacking automated behavioral oversight, the vendor relies on an internal risk committee led by Boyd and corporate board members to vet potential foreign buyers. The evaluation examines political stability, democratic governance, corruption ratings, legal institutional strength, and adherence to domestic statutory limits. The company claims to maintain an approved export list of 20 to 30 nations, serving over 100 client accounts across 23 sovereign states.

Sales are restricted strictly to national-level entities, barring state, provincial, or municipal police departments from procurement. Even among recognized American allies, sales are frequently denied. The company maintains an absolute prohibition on transactions with Saudi Arabia, having previously refused an Israeli government request to absorb NSO Group's Saudi contracts following the assassination of Washington Post contributor Jamal Khashoggi. Boyd confirmed that the firm holds zero commercial agreements in the Middle East. Similarly, the company refuses to do business in Venezuela due to chronic internal instability, despite the departure of President Nicolas Maduro. However, the firm secured a contract valued in the tens of millions of dollars with Singapore in 2023, despite the country's documented statutory constraints on domestic press freedoms and civil assembly.

Protective Technical Filters and Future Market Strategy

To prevent domestic surveillance misuse, all platforms delivered to foreign governments incorporate a hardcoded geographical exclusion blocking any phone number bearing the North American dialing prefix (+1). This restriction can be lifted solely for certified American law enforcement entities possessing appropriate judicial warrants. Boyd maintained that if an American customer attempted to divert Graphite to an unauthorized third-party nation, the vendor would detect the transfer because its engineers personally manage installation and user training.

Despite public positioning, documented federal contracts remain modest. Prior to the 2024 acquisition, Paragon booked a 2 million dollar contract with Homeland Security Investigations, a unit of US Immigration and Customs Enforcement, focused on neutralizing transnational fentanyl distribution networks and foreign terrorist cells. While REDLattice holds ongoing engagements with the US Air Force, additional procurement records remain obscured behind classified operational budgets. Boyd continues to position the company for lucrative awards from the Pentagon and the CIA, noting that multiple components of the national security community have yet to realize their need for sophisticated offensive surveillance capabilities.

Questions & Answers

What is Paragon and what technology does it develop?
Paragon is an offensive cyber contractor formerly based in Israel, now acquired by an American private equity firm, known for developing the Graphite spyware suite that targets encrypted messaging platforms.
What allegations did WhatsApp and Citizen Lab bring against Paragon?
They asserted that Paragon's Graphite tool compromised devices belonging to more than 60 individuals across over 20 countries, including journalists and activists in Italy.
Why did Paragon terminate its surveillance contracts with Italian agencies?
CEO Andrew Boyd explained that the firm dropped Italy because maintaining the commercial relationship was not worth the ongoing public relations and corporate risk.
Can Paragon monitor which individuals its clients target with spyware?
No, Paragon possesses no remote technical visibility into target lists, device identifiers, or data extracted by customer agencies.
How does Paragon's accountability mechanism differ from NSO Group's Pegasus?
While NSO Group claims to maintain an operational kill switch and mandatory user logs, Paragon holds no kill switch and declines all access to client operational logs.
Are there technical guardrails preventing foreign clients from targeting US numbers?
Yes, systems sold to foreign intelligence agencies feature an embedded block restricting surveillance operations against phone numbers with the +1 country code.

Comments 0

No comments yet — be the first.

Citizen journalism

Become a TrendKia journalist

Voice of the people

Share news, photos and videos from your area with TrendKia and let your voice reach the nation. Every citizen a journalist.

Join now
CH 01 LIVE
TrendKia TV ON AIR
Chamar no WhatsApp