Italian prosecutors are investigating a spyware scandal after WhatsApp and Apple alerted journalists, activists, and NGO workers that they had been targeted with mercenary spyware linked to Paragon Solutions’ Graphite platform. The campaign reportedly affected about 90 people worldwide, and public disclosures in Italy included journalist Francesco Cancellato, Fanpage journalist Ciro Pellegrino, and Mediterranea Saving Humans figures Luca Casarini and Beppe Caccia. Researchers at Citizen Lab later confirmed infections of Pellegrino and another European journalist, tying one case to a sophisticated zero-click iMessage exploit that Apple said was mitigated in iOS 18.3.1.
The case has intensified scrutiny of Italy’s intelligence services after a parliamentary committee said agencies AISI and AISE were Paragon customers, even as the government denied targeting legally protected subjects such as journalists. Paragon said it had offered help investigating the alleged surveillance and later cut ties with Italy, but prosecutors in Rome and Naples reportedly have not received the company’s cooperation through formal channels, raising questions about accountability and Israeli assistance in spyware investigations. The dispute echoes earlier battles over Israeli spyware vendors, including NSO Group’s Pegasus, which was previously used in WhatsApp-based attacks and became the subject of major litigation and international scrutiny.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
16 events from the most recent confirmed update back to the earliest known activity.
Despite previously saying it would help investigate, Paragon reportedly did not respond to a formal request for information sent by Italian prosecutors through the Israeli government. The reported lack of cooperation raised questions about Israeli assistance in the spyware inquiry.
Victims in Italy filed criminal complaints over the spyware targeting, leading prosecutors in Rome and Naples to open a joint investigation. The inquiry focused on attacks linked to Paragon's Graphite platform and possible involvement of Italian intelligence services.
Italian prosecutors confirmed that activists and a journalist in Italy had been targeted with spyware in 2024, adding official investigative validation to allegations surrounding the Paragon-linked surveillance scandal. The confirmation clarified that the attacks predated WhatsApp's January 2025 disruption and public victim notifications.
Citizen Lab published a new report examining Paragon's expanding spyware operations, marking a broader research disclosure beyond its earlier confirmation of individual Graphite infections. The publication indicated that scrutiny of Paragon had widened from the Italy-focused cases to the vendor's broader operational footprint.
Amnesty International disclosed a new case of an Italian journalist targeted with Paragon's Graphite spyware, adding another victim to the Italy surveillance scandal. The report indicated the spyware use was broader than previously publicly documented and reinforced concerns about unlawful surveillance in Italy.
In response to Citizen Lab's findings, Apple said the exploit path used in one Paragon-linked infection had been mitigated in iOS 18.3.1. This provided a technical update on how at least one confirmed infection route had been addressed.
Citizen Lab confirmed that two European journalists, including Italian journalist Ciro Pellegrino, were hacked with Paragon's Graphite spyware, marking the first publicly confirmed infections tied to the vendor. The researchers said the attacks likely involved the same Paragon customer and linked one infection to a zero-click iMessage exploit.
Italy's parliamentary intelligence oversight committee, COPASIR, confirmed that intelligence agencies AISI and AISE were Paragon customers. It also said it found no evidence that journalist Francesco Cancellato had been spied on and stated that legally protected subjects such as journalists were not targeted by Italian intelligence services.
Italy's parliamentary intelligence oversight committee reported that intelligence agencies AISE and AISI had contracts for Paragon's Graphite spyware and had since rescinded them. The committee disclosed this while reviewing agency contracts and spyware logs during its inquiry into surveillance of activists and journalist Francesco Cancellato.
Mediterranea Saving Humans co-founder Beppe Caccia said he was among those notified by WhatsApp that they had been targeted with Paragon-linked spyware. His disclosure added another Italian civil society figure to the list of known targets.
Paragon said it offered Italy assistance in investigating the alleged hacking of journalist Francesco Cancellato, but the government refused. The company then cut ties with Italy, according to later reporting.
Journalists and activists in Italy, including Francesco Cancellato, Luca Casarini, Husam El Gomati, and later Beppe Caccia, said they received WhatsApp notifications that they had been targeted in the campaign. These disclosures helped trigger public scrutiny and later criminal complaints in Italy.
WhatsApp disrupted a spyware campaign on January 31, 2025, after roughly 90 people worldwide were reportedly targeted. The campaign was linked to Paragon Solutions' Graphite platform, though the responsible government customer was not publicly identified.
Refugees in Libya co-founder David Yambio said Apple notified him in November 2024 that he had been targeted by a mercenary spyware attack. Reporting later noted it was unclear whether his case was connected to the Paragon-linked campaign.
Italian priest Mattia Ferrari, affiliated with Mediterranea Saving Humans, said Meta notified him in February 2024 that he had been targeted by a sophisticated surveillance tool backed by unidentified government entities. His disclosure added another Italian civil society figure to the widening spyware scandal involving activists and journalists connected to migrant rescue work.
WhatsApp disclosed a vulnerability that allowed NSO Group's Pegasus spyware to be installed via WhatsApp voice calls, including cases where targets did not answer. The company began deploying server-side mitigations on 2019-05-10 and released an updated app version on 2019-05-13, while notifying users and relevant organizations.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
18 references tracked. Mallory keeps watching after this page renders.
techcrunch.com
Open sourcetheguardian.com
Open sourcecitizenlab.ca
Open sourcecitizenlab.ca
Open sourcetechcrunch.com
Open sourcetechcrunch.com
Open sourceft.com
Open sourcedocumenti.camera.it
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.