Paragon, a surveillance technology firm founded by former operatives of Israel’s Unit 8200, has been facing considerable scrutiny over its lack of transparency regarding customer usage of its products. CEO Boyd defends this absence of oversight, positing that it is essential to customer privacy. He asserts that potential buyers would shy away from purchasing Paragon’s offerings if they knew the company could access sensitive targeting information or logs related to their activities. “There’s a balancing act between privacy and security and being able to ensure that our customers are using these things correctly,” Boyd explained. “And I think we’ve landed on the best balance.”
This claimed balance is primarily maintained through a selective vetting process to screen customers, with Paragon opting to turn down requests from countries that may misuse its spyware. However, John Scott-Railton, a senior researcher at Citizen Lab, which monitors abuses of commercial espionage tools, has characterized Paragon’s revelations as shocking and its lack of mandatory logging as “reckless.” He contends that Paragon’s policies offer less oversight and transparency than those of competitors like the NSO Group.
Scott-Railton further criticized Paragon’s reliance on independent organizations like Citizen Lab to uncover misuse of its products while simultaneously employing methods to obscure its spyware from detection. “We only find a very, very, very small subset [of infections], and the total numbers are always larger,” he noted, highlighting that these companies invest heavily in strategies to evade discovery. Reflecting on the broader implications, U.S. Senator Ron Wyden asserted that surveillance tools operating without oversight are “inevitably abused,” stating, “The fact that Paragon refuses to audit the use of its tool is a massive red flag.”
Launched in 2019, Paragon was co-founded by Brigadier General Ehud Schneorson alongside other veterans of Israel’s intelligence community and former Prime Minister Ehud Barak. Within two years, despite developing its flagship product, Graphite, the company had reportedly not secured any clients. The landscape shifted dramatically when the U.S. government imposed sanctions on NSO Group and other spyware entities following reports of their products being misused against diverse targets, including government officials and journalists.
The U.S. Commerce Department designated NSO Group as a restricted entity in 2021, and a drastic reduction in the number of countries authorized to procure Israeli spyware followed, now limited to 37 nations, excluding key markets such as Saudi Arabia and the UAE. Over the past year, further protective measures from the Biden administration have effectively made it more challenging for the U.S. government to acquire foreign-made commercial spyware that might pose risks to national security.
In addressing the potential vulnerabilities posed by such surveillance technologies, which reflect tactics seen in the MITRE ATT&CK framework such as initial access, privilege escalation, and data exfiltration, it is crucial for business owners to evaluate the implications of tools lacking necessary oversight and logging capabilities. The events surrounding Paragon underscore the ongoing challenges in ensuring accountability within the surveillance industry and illustrate the need for heightened scrutiny in order to protect sensitive data and maintain trust.