Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
state-sponsored-espionagegovernment-diplomatic-threatendpoint-software-vulnerabilityidentity-impersonation-fraud

Paragon Graphite Spyware Scandal Deepens in Italy

Updated 29d agoFirst seen Apr 28, 202618 sources

Italian prosecutors are investigating a spyware scandal after WhatsApp and Apple alerted journalists, activists, and NGO workers that they had been targeted with mercenary spyware linked to Paragon Solutions’ Graphite platform. The campaign reportedly affected about 90 people worldwide, and public disclosures in Italy included journalist Francesco Cancellato, Fanpage journalist Ciro Pellegrino, and Mediterranea Saving Humans figures Luca Casarini and Beppe Caccia. Researchers at Citizen Lab later confirmed infections of Pellegrino and another European journalist, tying one case to a sophisticated zero-click iMessage exploit that Apple said was mitigated in iOS 18.3.1.

The case has intensified scrutiny of Italy’s intelligence services after a parliamentary committee said agencies AISI and AISE were Paragon customers, even as the government denied targeting legally protected subjects such as journalists. Paragon said it had offered help investigating the alleged surveillance and later cut ties with Italy, but prosecutors in Rome and Naples reportedly have not received the company’s cooperation through formal channels, raising questions about accountability and Israeli assistance in spyware investigations. The dispute echoes earlier battles over Israeli spyware vendors, including NSO Group’s Pegasus, which was previously used in WhatsApp-based attacks and became the subject of major litigation and international scrutiny.

Share:
Paragon Graphite Spyware Scandal Deepens in Italy
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

16 events from the most recent confirmed update back to the earliest known activity.

16 EVENTS
Apr 28, 20262mo ago

Report says Paragon did not answer Italian prosecutors' request

Despite previously saying it would help investigate, Paragon reportedly did not respond to a formal request for information sent by Italian prosecutors through the Israeli government. The reported lack of cooperation raised questions about Israeli assistance in the spyware inquiry.

Italian victims file complaints, prompting Rome and Naples probe

Victims in Italy filed criminal complaints over the spyware targeting, leading prosecutors in Rome and Naples to open a joint investigation. The inquiry focused on attacks linked to Paragon's Graphite platform and possible involvement of Italian intelligence services.

Mar 6, 20264mo ago

Italian prosecutors confirm 2024 spyware targeting of activists and journalist

Italian prosecutors confirmed that activists and a journalist in Italy had been targeted with spyware in 2024, adding official investigative validation to allegations surrounding the Paragon-linked surveillance scandal. The confirmation clarified that the attacks predated WhatsApp's January 2025 disruption and public victim notifications.

Italian activists and journalist targeted by spyware in 2024, prosecutors confirm | Italy | The Guardian
Dec 8, 20257mo ago

Citizen Lab publishes broader report on Paragon spyware operations

Citizen Lab published a new report examining Paragon's expanding spyware operations, marking a broader research disclosure beyond its earlier confirmation of individual Graphite infections. The publication indicated that scrutiny of Paragon had widened from the Italy-focused cases to the vendor's broader operational footprint.

Virtue or Vice? A First Look at Paragon’s Proliferating Spyware Operations - The Citizen Lab
Jun 13, 20251y ago

Amnesty reports new Italian journalist targeted with Graphite spyware

Amnesty International disclosed a new case of an Italian journalist targeted with Paragon's Graphite spyware, adding another victim to the Italy surveillance scandal. The report indicated the spyware use was broader than previously publicly documented and reinforced concerns about unlawful surveillance in Italy.

Italy new spyware case points to widespread unlawful use
Jun 12, 20251y ago

Apple says iMessage attack vector was mitigated in iOS 18.3.1

In response to Citizen Lab's findings, Apple said the exploit path used in one Paragon-linked infection had been mitigated in iOS 18.3.1. This provided a technical update on how at least one confirmed infection route had been addressed.

Citizen Lab confirms first public Paragon Graphite infections

Citizen Lab confirmed that two European journalists, including Italian journalist Ciro Pellegrino, were hacked with Paragon's Graphite spyware, marking the first publicly confirmed infections tied to the vendor. The researchers said the attacks likely involved the same Paragon customer and linked one infection to a zero-click iMessage exploit.

COPASIR says Italian intelligence used Paragon but denies targeting Cancellato

Italy's parliamentary intelligence oversight committee, COPASIR, confirmed that intelligence agencies AISI and AISE were Paragon customers. It also said it found no evidence that journalist Francesco Cancellato had been spied on and stated that legally protected subjects such as journalists were not targeted by Italian intelligence services.

Jun 6, 20251y ago

COPASIR says Italian intelligence rescinded Paragon contracts

Italy's parliamentary intelligence oversight committee reported that intelligence agencies AISE and AISI had contracts for Paragon's Graphite spyware and had since rescinded them. The committee disclosed this while reviewing agency contracts and spyware logs during its inquiry into surveillance of activists and journalist Francesco Cancellato.

Italian lawmakers say Italy used spyware to target phones of immigration activists, but not against journalist | TechCrunch
Feb 11, 20251y ago

Beppe Caccia publicly discloses WhatsApp spyware targeting

Mediterranea Saving Humans co-founder Beppe Caccia said he was among those notified by WhatsApp that they had been targeted with Paragon-linked spyware. His disclosure added another Italian civil society figure to the list of known targets.

Feb 6, 20251y ago

Paragon ends its contract with Italy

Paragon said it offered Italy assistance in investigating the alleged hacking of journalist Francesco Cancellato, but the government refused. The company then cut ties with Italy, according to later reporting.

Jan 31, 20251y ago

WhatsApp notifies Italian targets of Paragon-linked spyware attacks

Journalists and activists in Italy, including Francesco Cancellato, Luca Casarini, Husam El Gomati, and later Beppe Caccia, said they received WhatsApp notifications that they had been targeted in the campaign. These disclosures helped trigger public scrutiny and later criminal complaints in Italy.

WhatsApp disrupts Paragon-linked spyware campaign

WhatsApp disrupted a spyware campaign on January 31, 2025, after roughly 90 people worldwide were reportedly targeted. The campaign was linked to Paragon Solutions' Graphite platform, though the responsible government customer was not publicly identified.

Nov 13, 20242y ago

Apple notifies David Yambio of mercenary spyware targeting

Refugees in Libya co-founder David Yambio said Apple notified him in November 2024 that he had been targeted by a mercenary spyware attack. Reporting later noted it was unclear whether his case was connected to the Paragon-linked campaign.

Feb 1, 20242y ago

Father Mattia Ferrari says Meta warned him of government-linked spyware targeting

Italian priest Mattia Ferrari, affiliated with Mediterranea Saving Humans, said Meta notified him in February 2024 that he had been targeted by a sophisticated surveillance tool backed by unidentified government entities. His disclosure added another Italian civil society figure to the widening spyware scandal involving activists and journalists connected to migrant rescue work.

Italian priest close to pope told he was target of surveillance tool used by a government | Surveillance | The Guardian
May 10, 20197y ago

WhatsApp begins fixing Pegasus voice-call spyware flaw

WhatsApp disclosed a vulnerability that allowed NSO Group's Pegasus spyware to be installed via WhatsApp voice calls, including cases where targets did not answer. The company began deploying server-side mitigations on 2019-05-10 and released an updated app version on 2019-05-13, while notifying users and relevant organizations.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

14 LINKEDOpen in app
Malware
1 linked
Affected products
2 linked
WhatsappIphone
Organizations
11 linked
Paragon SolutionsThe GuardianTechCrunchNSO GroupIntellexaMeta PlatformsCitizen LabAppleFanpageWIRED ItalyMediterranea Saving Humans
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Paragon Graphite Spyware Scandal Deepens in Italy | Mallory