Rather than see Paragon’s lack of access to logs as an accountability problem, however, Boyd describes it as a selling point: No one would buy their products if the company could see a customer’s sensitive targeting information or logs that contain it.
“There’s a balancing act between privacy and security and being able to ensure that our customers are using these things correctly,” Boyd says. “And I think we’ve landed on the best balance.”
That balance is achieved mostly through careful vetting of customers, he says, and rejecting any country that might be prone to abusing the spyware.
John Scott-Railton, senior researcher at Citizen Lab, which has tracked government misuse of commercial spyware for years, calls the revelations astonishing and the lack of mandatory logging “reckless.”
“What Paragon is saying in several substantial ways means [it has] less oversight, less transparency, less contractual protection against abuses than NSO Group,” he says. “It’s exactly the opposite of the picture that Paragon has painted for itself for years. The CEO admitting that his customers won’t tolerate oversight is refreshing honesty: Accountability is bad for business. And it signals to lawmakers and regulators that the spyware industry cannot be trusted to self-regulate.”
Scott-Railton also finds it ironic that Paragon relies on Citizen Lab and others to uncover customer misuse when Paragon actively works to hide its spyware on infected devices and prevent discovery—which inherently includes potential misuse.
“We only find a very, very, very small subset [of infections], and the total numbers are always larger,” Scott-Railton says. “These companies spend millions trying to hide from us.”
US senator Ron Wyden tells WIRED that surveillance tools that lack oversight and transparency are “inevitably abused.”
“It’s easy to claim your powerful hacking tool isn’t being misused if you go out of your way to ensure you don’t know how customers use it,” Wyden says. “The fact that Paragon refuses to audit use of its tool, or even attempt to match the work of a small team of researchers at the Citizen Lab is a massive red flag.”
Israeli Intelligence Roots
Paragon was launched in 2019 by Israeli Brigadier General Ehud Schneorson, former commander of the Israeli military’s signals intelligence group, Unit 8200. He cofounded it with three other 8200 veterans and former Israeli Prime Minister Ehud Barak. Two years later, the company reportedly had no customers but was developing Graphite and hoping to conquer the lucrative US market. But then the US government began cracking down on foreign spyware companies after NSO’s Pegasus and Candiru’s DevilsTongue tools were misused by their customers against government workers, journalists, dissidents, activists, and academics.
The US Commerce Department sanctioned both companies in 2021, and the Israeli government drastically cut the number of countries to which Israeli firms could sell spyware—from 102 countries to 37, excluding Saudi Arabia, the UAE, Morocco and Mexico. Over a year later, the Biden administration and Congress imposed guardrails making it difficult for the US government to purchase foreign-made commercial spyware if it posed a national security risk or could be misused by foreign governments.






