AI incident #1069 ·

Purported Graphite Spyware Linked to Paragon Solutions Allegedly Deployed Against Journalists and Civil Society Workers

Open on the AI Incident Database 33 news reports Synced from the AIID API · record last edited 31 Aug 2026

What happened

Researchers at Citizen Lab and Censys reportedly identified spyware infections involving Graphite, a tool attributed to Israeli firm Paragon Solutions. The spyware was allegedly deployed against civil society actors, including journalists and aid workers, through a zero-click WhatsApp exploit. WhatsApp notified over 90 targeted individuals. Evidence reportedly suggests deployments in multiple democratic countries.

Editor's notes (AI Incident Database)

For the full report by Citizen Lab, please visit this URL: https://citizenlab.ca/2025/03/a-first-look-at-paragons-proliferating-spyware-operations/. Timeline notes: WhatsApp reportedly notified over 90 individuals of targeting with Paragon spyware on January 31, 2025. Subsequent investigation by Citizen Lab and Censys, published on March 19, 2025, identified additional infrastructure and implicated law enforcement agencies in multiple democratic countries. This record uses January 31, 2025 as the incident date based on first confirmed exposure.

Only the incident metadata is stored here. The underlying news reports are on the AI Incident Database (CC BY-SA 4.0); use the links above to read them.

News reports (33)

Coverage catalogued by the AI Incident Database. Titles link to the original publisher; the text is not reproduced here.

  1. Owner of spyware used in alleged WhatsApp breach ends contract with Italy
    theguardian.com · Stephanie Kirchgaessner, Angela Giuffrida · AIID #5268
  2. Virtue or Vice? A First Look at Paragon’s Proliferating Spyware Operations
    citizenlab.ca · Bill Marczak, John Scott-Railton, Kate Robertson · AIID #5180
  3. Report on Paragon Spyware
    securityboulevard.com · Bruce Schneier · AIID #5252

Who was involved

Alleged deployer
York Regional Police Service (Ontario, Canada) Unidentified law enforcement or intelligence entity (Singapore) Unidentified law enforcement or intelligence entity (Israel) Unidentified law enforcement or intelligence entity (Denmark) Unidentified law enforcement or intelligence entity (Cyprus) Unidentified law enforcement or intelligence entity (Australia) Peel Regional Police (Ontario, Canada) Ontario Provincial Police Hamilton Police Service (Ontario, Canada) External Intelligence and Security Agency (Italy) AISE
On AIID: York Regional Police Service (Ontario, Canada), Unidentified law enforcement or intelligence entity (Singapore), Unidentified law enforcement or intelligence entity (Israel), Unidentified law enforcement or intelligence entity (Denmark), Unidentified law enforcement or intelligence entity (Cyprus), Unidentified law enforcement or intelligence entity (Australia), Peel Regional Police (Ontario, Canada), Ontario Provincial Police, Hamilton Police Service (Ontario, Canada), External Intelligence and Security Agency (Italy), AISE
Alleged harmed party
Refugees in Libya Privacy National security and intelligence stakeholders Mediterranea Saving Humans Luca Casarini Journalists Humanitarian workers Giuseppe "Beppe" Caccia General public of countries in which Graphite is being deployed Francesco Cancellato Fanpage.it David Yambio
On AIID: Refugees in Libya, Privacy, National security and intelligence stakeholders, Mediterranea Saving Humans, Luca Casarini, Journalists, Humanitarian workers, Giuseppe "Beppe" Caccia, General public of countries in which Graphite is being deployed, Francesco Cancellato, Fanpage.it, David Yambio

AI systems implicated

WhatsAppSurveillance technologyiOSGraphite (Paragon spyware)CloudflareAndroid

Classification (MIT AI Risk Repository taxonomy)

Causal entity
AI
Intent
Intentional
Timing
Post-deployment
Harm level
Sectors
Countries

Risk entries describing this failure mode

Entries from the MIT AI Risk Repository coded to subdomain 2.1.

  • Risks to privacy

    "General- purpose AI models or systems can ‘leak’ information about individuals whose data was used in training. For future models trained on sensitive personal data like health or financial data, this may lead to partic...

    International Scientific Report on the Safety of Advanced AI (Bengio2024)

  • Risks to privacy

    "General- purpose AI systems can cause or contribute to violations of user privacy. Violations can occur inadvertently during the training or usage of AI systems, for example through unauthorised processing of personal d...

    International AI Safety Report 2025 (Bengio2025)

  • Privacy Leakage

    "Privacy Leakage means the generated content includes sensitive personal information"

    Risk Taxonomy, Mitigation, and Assessment Benchmarks of Large Language Model Systems (Cui2024)

  • Private Training Data

    "As recent LLMs continue to incorporate licensed, created, and publicly available data sources in their corpora, the potential to mix private data in the training corpora is significantly increased. The misused private d...

    Risk Taxonomy, Mitigation, and Assessment Benchmarks of Large Language Model Systems (Cui2024)

  • Memorization in LLMs

    "Memorization in LLMs refers to the capability to recover the training data with contextual prefixes. According to [88]–[90], given a PII entity x, which is memorized by a model F. Using a prompt p could force the model...

    Risk Taxonomy, Mitigation, and Assessment Benchmarks of Large Language Model Systems (Cui2024)

  • Association in LLMs

    "Association in LLMs refers to the capability to associate various pieces of information related to a person. According to [68], [86], given a pair of PII entities (xi , xj ), which is associated by a model F. Using a pr...

    Risk Taxonomy, Mitigation, and Assessment Benchmarks of Large Language Model Systems (Cui2024)

  • Privacy Leakage

    "The model is trained with personal data in the corpus and unintentionally exposing them during the conversation."

    Risk Taxonomy, Mitigation, and Assessment Benchmarks of Large Language Model Systems (Cui2024)

  • Privacy and regulation violations

    "Some of the broken systems discussed above are also very invasive of people’s privacy, controlling, for instance, the length of someone’s last romantic relationship [51]. More recently, ChatGPT was banned in Italy over...

    Navigating the Landscape of AI Ethics and Responsibility (Cunha2023)

Incidents in the same risk subdomain

All incidents in this subdomain