· via Hacker News – Front Page (native)
ICE Holds $2 Million Contract With Paragon, Maker of Zero-Click Graphite Spyware
Military.com reports ICE holds a $2 million contract with Paragon, whose Graphite spyware has silently compromised the phones of European journalists and activists with no action from the target.

ICE signs a $2 million deal with Paragon
U.S. Immigration and Customs Enforcement holds a $2 million contract with Paragon Solutions, the maker of Graphite, a commercial spyware product capable of compromising a smartphone without the owner tapping a link, opening an attachment or installing anything, according to a Military.com report that gained traction on Hacker News. The deal puts a tool already tied to surveillance of journalists and immigration campaigners in Europe into the hands of a U.S. federal agency, with little public detail on how it may be used.
What Graphite is built to do
Graphite belongs to the same class of mercenary spyware as NSO Group's better-known Pegasus: privately developed intrusion software sold to government intelligence and law enforcement buyers. The two products come from separate companies, but Military.com notes a difference in ambition. Paragon reportedly designed Graphite primarily to extract data from messaging applications rather than to seize full control of a device.
That focus has a direct consequence for encrypted services. End-to-end encryption shields a message while it travels between devices; it cannot stop software running inside one of those devices from reading the message after the app decrypts it. Graphite can therefore collect readable content from apps such as WhatsApp and Signal without breaking their encryption at all.
How the zero-click attack works
No mistake by the target is required. Phones automatically parse incoming messages and files before displaying them, and an attacker can send specially crafted data that abuses a hidden flaw in that processing step. When the phone inspects the data, the flaw lets it execute commands and hide spyware inside legitimate applications, which then relay messages and other private material to the operator while the owner sees nothing.
Researchers have confirmed Graphite attacks delivered through WhatsApp and iMessage, although the complete method remains secret. Citizen Lab helped WhatsApp identify and block an active Graphite zero-click exploit in late 2024, and in January 2025 WhatsApp notified roughly 90 users — journalists and civil society figures across more than 20 countries — that Paragon's spyware had targeted their accounts.
Confirmed victims in Italy, and a first on iOS
Forensic examinations of devices belonging to warning recipients produced hard evidence. According to Military.com, researchers found Graphite components planted inside WhatsApp and other apps on the phones of Italian immigration activists Luca Casarini and Giuseppe Caccia, and Italian journalist Francesco Cancellato also received a WhatsApp alert.
In March 2026, prosecutors in Rome and Naples independently confirmed spyware traces on the phones of all three men, each dated to the early hours of December 14, 2024. Investigators traced the operations against Casarini and Caccia to the Paragon server used by Italy's domestic intelligence agency, but found no matching record for Cancellato, leaving whoever infected his phone unidentified.
A separate investigation delivered the first forensic confirmation that Graphite can compromise Apple devices: an unnamed European journalist's iPhone was successfully infected in January and February 2025 through a previously unknown iMessage flaw that would have been invisible to the target. The same iMessage account was tied to an operation against Italian journalist Ciro Pellegrino, and Apple closed the vulnerability in iOS 18.3.1.
Italy's parliamentary intelligence committee later acknowledged that Italian agencies had used Graphite against Casarini, Caccia and other activists, describing the surveillance as legally authorised and connected to immigration and national security. It concluded Italian intelligence had not targeted Cancellato.
A dispute over auditing
Paragon and Italian officials give conflicting accounts of the aftermath. The company says it terminated its Italian contracts after authorities declined an offer to examine whether Graphite had been used unlawfully against Cancellato. Italian officials call the termination mutual, arguing that letting a foreign private company inspect intelligence records would have exposed classified information.
Why it matters
The ICE contract means a capability with a documented record of reaching journalists and activists is now available to a U.S. immigration enforcement agency, and the public record says almost nothing about the rules governing its use. The Italian cases show how such tools, once sold to state agencies, extend beyond criminal or espionage targets to civil society figures. They also underline that end-to-end encryption is not endpoint security: transport-level protection did nothing for users whose devices were compromised from within. For most people, prompt patching remains the practical defence — the iOS 18.3.1 update closed a flaw that otherwise left targets with no visible sign of intrusion and no click to avoid.
- #spyware
- #surveillance
- #mobile-security
- #encryption
- #ice