Table of Contents
WhatsApp’s Paragon warning puts mercenary spyware back in focus
WhatsApp has confirmed that nearly 100 journalists and civil society members were targeted by spyware linked to Paragon Solutions, an Israeli hacking software company. Meta, WhatsApp’s parent company, says it has “high confidence” that 90 users were targeted and “possibly compromised.” That language is careful, but the underlying message is not: a communications platform used by people whose work can put them at risk was targeted by commercial surveillance technology.
The affected group matters as much as the technical details. Journalists, activists, researchers and other civil society figures often hold sensitive conversations, maintain confidential sources and work across borders. Access to one phone can reveal far more than a single account. It can expose contacts, calendars, photos, location history and the social map around a person. Even when a messaging service uses encryption, a compromised device can give an attacker visibility before a message is encrypted or after it is displayed.
That is why the alleged use of Paragon’s spyware, known as Graphite, is so serious. The software is described as allowing hackers to fully access a phone, including encrypted chats on WhatsApp and Signal. Encryption remains essential for protecting messages in transit, but it cannot fully protect a device once spyware has gained control of it. The distinction is often lost in public discussion: an encrypted app can be functioning as designed while a phone itself has become the point of failure.
What is known about the alleged attack
Security researchers describe the operation as zero-click, meaning victims did not need to interact with malicious links to be infected. In practical terms, zero-click attacks are especially troubling because they remove the ordinary warning signs users are taught to watch for. No suspicious link needs to be opened, no attachment necessarily has to be consciously downloaded, and no obvious mistake by the target is required.
At the same time, security experts believe the infection method involved sending malicious PDF files through group chats. Those two descriptions should be read together with some caution. The public account establishes that PDFs sent in group chats were part of the suspected infection path, while the zero-click characterization points to an attack that did not depend on a target actively engaging with malicious content. What remains clear is that group messaging can be an attractive delivery channel: it reaches people in a setting that appears familiar and trusted, rather than through an unsolicited message from an obvious stranger.
WhatsApp worked with Citizen Lab, a cybersecurity research group, to analyze the attacks. That collaboration is significant because spyware incidents are difficult to investigate from outside the targeted device. In many cases, the target may never know an attempt was made. Notifications from a platform can therefore be one of the few moments when a person learns that their phone, accounts or professional network may have drawn the attention of a surveillance operation.
WhatsApp has begun notifying affected users and says it has taken legal action. The company sent a cease-and-desist letter to Paragon while exploring further legal steps. Notification is not a complete remedy for a possible compromise, but it gives targets a chance to reassess the security of their devices and communications. It also turns a largely invisible technical incident into a public accountability question for the companies that develop and sell such tools.
The unresolved question: who ordered it?
It is still unclear which government or entity ordered the attacks. Paragon’s spyware is sold to government agencies, but WhatsApp has not identified the specific clients involved. That absence of attribution is central to the case. Spyware vendors often present themselves as suppliers rather than operators, while the public consequences are borne by the people whose devices are targeted and the institutions trying to protect them.
Paragon was founded by former Israeli Prime Minister Ehud Barak and has 35 government customers, all described as “democratic.” The company’s claimed customer standards are now part of the scrutiny surrounding the incident. Reports suggest Paragon refuses to work with countries previously accused of spyware abuse, including India, Mexico, Greece, Poland, and Hungary. Yet the WhatsApp allegations illustrate the limits of judging surveillance practices solely by a vendor’s stated sales policies. A company can describe its customer base in reassuring terms while questions remain about how tools are deployed, against whom and with what oversight.
Paragon has remained silent, declining to comment on the allegations. That silence leaves a large gap between WhatsApp’s account of the targeting and the company’s public explanation of its technology, customers or safeguards. For people concerned about surveillance, that gap is not a public-relations issue. It is the difference between broad assurances and verifiable accountability.
The episode also arrives amid recent scrutiny of Paragon after a report revealed that U.S. Immigration and Customs Enforcement (ICE) had signed a $2 million contract with the company. The deal was paused for review because of U.S. government restrictions on spyware usage. The pause does not answer the questions raised by the WhatsApp case, but it shows how quickly the commercial spyware market can become entangled with policy, procurement and human-rights concerns.
WhatsApp’s fight with spyware vendors is not new
This case comes only weeks after WhatsApp won a major lawsuit against NSO Group, another Israeli spyware company. In 2019, WhatsApp sued NSO after discovering that its Pegasus spyware had infected 1,400 users. A U.S. judge ruled that NSO violated federal hacking laws and WhatsApp’s terms of service.
The comparison matters because it shows that WhatsApp is not treating spyware as a routine spam or fraud problem. The company is pursuing the companies behind the tools, not only attempting to block individual attacks. That approach can raise the cost of operating in a market where vendors have frequently argued that responsibility lies with government customers. Legal action does not eliminate spyware, but it can force disclosure, create consequences and challenge the idea that commercial surveillance firms should remain insulated from the conduct enabled by their products.
Meta is now pushing back against Paragon and warning that spyware companies must be held accountable. WhatsApp has assured users that it will continue strengthening security measures to prevent future attacks. That promise should be judged over time, because the pressure on messaging platforms is relentless: attackers look for weaknesses not only in messages, but in file handling, calls, notifications and the operating systems beneath the apps.
For ordinary users, the most practical advice remains basic even when the alleged attack is sophisticated: stay vigilant, avoid suspicious files and update apps regularly. Those habits cannot guarantee protection against a zero-click exploit, particularly for a targeted journalist or activist. They do reduce exposure to more common threats and ensure that security fixes reach a device as quickly as possible.
For readers following WhatsApp’s wider role in consumer technology, see ChatGPT Now Accessible via Phone Calls and WhatsApp, published on December 19, 2024, by SquaredTech.
Stay Updated: Tech News

