Yovao News · The World, In Focus. From Local to Global, Never Miss a Beat

US Spyware Firm Admits Lack of Oversight After Italian Contracts Were Cut

US Spyware Firm Admits Lack of Oversight After Italian Contracts Were Cut

In an exclusive interview with WIRED, Andrew Boyd, the new CEO of Paragon Solutions following its acquisition by US equity firm AE Industrial Partners, disclosed that his company lacks the technical capability to detect customer misuse of its Graphite spyware. The admissions cast doubt on Paragon’s longstanding reputation as an ethical player in the offensive cyber industry, particularly after it terminated contracts with Italian intelligence agencies just weeks after WhatsApp alleged its tools were used to hack journalists and activists.

Although Paragon had previously positioned itself as distinct from competitors by promising never to sell to authoritarian regimes or targets such as dissidents, Boyd revealed that the decision to drop Italy’s domestic and foreign intelligence services was driven purely by risk assessment rather than an internal investigation. Italian authorities had denied the allegations of spying, yet Paragon canceled the contracts within a week without engaging with WhatsApp or the University of Toronto’s Citizen Lab to verify the claims.

“There was no Paragon investigation,” Boyd stated, adding that the company simply determined the relationship “was not worth it, from a risk perspective.” He further admitted that Paragon has no “kill switch” to remotely disable customer access when misuse is suspected. Instead, the company can only halt 24-hour support and system updates, which Boyd noted renders the spyware ineffective within approximately 12 hours because “things start falling apart quite quickly.”

These revelations highlight a significant gap in accountability compared to industry rival NSO Group, maker of the Pegasus spyware. NSO publishes transparency reports and maintains tamper-proof logs of user activity, claiming customers must provide these logs for audit if misuse is alleged. In contrast, Boyd explained that while Paragon customers can enable logging on some systems, the company itself does not access these logs. Boyd framed this lack of access as a feature rather than a bug, arguing that clients would not purchase the software if Paragon could view sensitive targeting information.

John Scott-Railton, a senior researcher at Citizen Lab, criticized the stance as “reckless,” noting that Paragon’s model offers less oversight and transparency than NSO. “Accountability is bad for business,” Scott-Railton said, suggesting the comments signal to regulators that the spyware industry cannot be trusted to self-regulate. He also pointed out the irony of Paragon relying on external researchers to uncover misuse while actively working to hide its infections.

US Senator Ron Wyden also weighed in, stating that surveillance tools lacking transparency are “inevitably abused.” He called Paragon’s refusal to audit its tools a “massive red flag,” emphasizing the difficulty of proving non-misuse when a company deliberately avoids knowing how its products are used.

Founded in 2019 by former Israeli military intelligence officers, including Brigadier General Ehud Schneorson and former Prime Minister Ehud Barak, Paragon originally operated as an Israeli firm. After facing US sanctions against competitors like NSO and Candiru, and strict Israeli export controls, the company sought a US buyer to bypass ownership restrictions. AE Industrial Partners acquired Paragon in December 2024 for $900 million and merged it with its existing cyber firm, REDLattice. The deal was approved without US government conditions, allowing Paragon to rapidly expand its client base among Western allies despite the ongoing controversy over its oversight mechanisms.

3 responses to “US Spyware Firm Admits Lack of Oversight After Italian Contracts Were Cut”

  1. NSO at least publishes logs. Paragon deliberately stays blind. This isn’t a feature, it is negligence wrapped in corporate strategy.

  2. I am shocked they admitted to having no kill switch. How can we trust companies with this power when they cannot even verify usage?

  3. So they cut ties for risk, not innocence? That is a damning distinction. Accountability should never be optional.

Leave a Reply

Your email address will not be published. Required fields are marked *