Paragon Spyware's Accountability Crisis: No Logs, No Kill Switch, No Oversight
A recent acquisition and subsequent allegations have cast a harsh spotlight on **Paragon Solutions**, a spyware maker that once prided itself on ethical practices. Despite its vows to prevent misuse, a candid interview with its new CEO reveals a startling lack of internal oversight mechanisms, raising serious questions about accountability in the offensive cyber industry.
# Paragon's Ethical Facade Crumbles Amidst Spyware Misuse Allegations
**Paragon Solutions**, a company that has long positioned itself as a 'good guy' in the often-maligned spyware industry, is now facing intense scrutiny. The Israeli-founded firm, recently acquired by US equity firm **AE Industrial Partners** and merged with **REDLattice**, had pledged to never sell its mobile spyware to authoritarian regimes or those with poor human rights records. It also promised to sever ties with any customer found misusing its products against non-legitimate targets like journalists or dissidents.
## WhatsApp Allegations and Citizen Lab Revelations
Weeks after the acquisition in December 2024, **WhatsApp** alleged that **Paragon's** **Graphite** spyware was deployed to infect the phones of over 60 individuals across more than 20 countries, including journalists and activists. While most targets remained unnamed, the **University of Torontoβs Citizen Lab** identified two journalists and two activists in Italy as victims.
Italian authorities denied any misuse of the spyware. Initially, **Paragon** and its new US owners declined to comment, reportedly exploring legal action against **WhatsApp** after receiving a cease-and-desist letter. However, within a week, **Paragon** canceled its two contracts with Italyβs domestic and foreign intelligence agencies.
## A Surprisingly Candid Admission
**Andrew Boyd**, the new CEO of **Paragon** and **REDLattice**, recently offered a surprisingly candid interview. He revealed that the company did not conduct an investigation into the allegations before canceling the Italian contracts. Instead, **Paragon** simply 'fired' Italy because it 'just was not worth it, from a risk perspective, to maintain the relationship' following the public accusations.
Boyd's admissions highlight a critical flaw: **Paragon** has no technical means to detect if customers are misusing its software. The company cannot see who customers target or what data they extract. It relies solely on customers admitting misuse or third parties, like **WhatsApp** and **Citizen Lab**, exposing it.
> "There's a balancing act between privacy and security and being able to ensure that our customers are using these things correctly," Boyd says. "And I think we've landed on the best balance."
## No Kill Switch, Limited Accountability
Adding to the concerns, **Paragon** lacks a 'kill switch' to disable customer access in cases of misuse. Their only recourse is to halt 24-hour support and system updates. Boyd claims these updates are frequent and essential, rendering the spyware ineffective within approximately 12 hours if discontinued.
This stands in stark contrast to **NSO Group**, the maker of **Pegasus** spyware, which, despite its own controversies, claims to have a kill switch and maintain 'tamper-proof' logs of user activity. **NSO Group** also contractually obligates customers to provide these logs during misuse allegations.
**Paragon**, however, offers customers the *option* to enable logging on *some* systems, but the company itself has no access to these logs, nor does it desire access. Boyd argues this protects customer privacy and allows government oversight bodies to investigate internally. Critics, however, fear this creates an opportunity for investigators to conceal misuse.
## Industry Reactions and Regulatory Calls
**John Scott-Railton**, a senior researcher at **Citizen Lab**, described **Paragon's** revelations as astonishing and the lack of mandatory logging as 'reckless.' He contends that **Paragon** exhibits less oversight, transparency, and contractual protection against abuses than even **NSO Group**.
> "Itβs exactly the opposite of the picture that Paragon has painted for itself for years. The CEO admitting that his customers wonβt tolerate oversight is refreshing honesty: Accountability is bad for business. And it signals to lawmakers and regulators that the spyware industry cannot be trusted to self-regulate."
US Senator **Ron Wyden** echoed these concerns, stating that surveillance tools without oversight and transparency are 'inevitably abused.' He called **Paragon's** refusal to audit its tool's usage a 'massive red flag.'
## Israeli Intelligence Roots and the US Market
**Paragon** was founded in 2019 by **Ehud Schneorson**, a former commander of the Israeli militaryβs signals intelligence group, **Unit 8200**, along with other **Unit 8200** veterans and former Israeli prime minister **Ehud Barak**. Initially struggling for customers, the company aimed to penetrate the lucrative US market. This ambition coincided with the US government's increased scrutiny of foreign spyware companies following the misuse of **NSO's Pegasus** and **Candiru's DevilsTongue** tools.
The recent revelations about **Paragon's** operational practices challenge its long-held image and intensify calls for greater transparency and accountability within the global offensive cyber industry, particularly as US companies become increasingly involved.