The suspended spyware is back in service: in between, the vendor changed owner
7 min read
On 23 July 2026 Senator Gary Peters (D-MI), the ranking member of the US Senate Homeland Security and Governmental Affairs Committee, wrote to Homeland Security Secretary Markwayne Mullin demanding answers about a $2 million Immigration and Customs Enforcement (ICE) contract: the one for Graphite, spyware capable of taking control of a phone — messages, photos, location — without the target clicking anything. He asked for contracts, privacy impact assessments, civil rights reviews and security policies, by 7 August. This is not the first time that contract has surfaced in an official record: it had already been suspended, for the same reasons Peters is now putting back on the table. In between, one thing happened, and it is the thing that matters for anyone assessing a critical vendor: the company that sells Graphite changed owners.
The facts, in order
- 27 September 2024: ICE signs a $2 million sole-source contract with Paragon Solutions, an Israeli cyberintelligence firm, for the use of Graphite.
- October 2024: the Biden administration suspends the contract with a stop-work order, to decide whether it complied with Executive Order 14093 (27 March 2023), which bars federal agencies from buying commercial spyware that poses a significant security risk to the United States or a risk of misuse by foreign governments. That review does not appear to have ever been publicly concluded.
- December 2024: Israeli media report that AE Industrial Partners, a Florida-based private equity firm, has acquired Paragon Solutions, folding it into REDLattice, a Virginia-based cyberintelligence integrator. Sources differ on the amount; they do not differ on the change of ownership — in July 2026 CBS describes Graphite as a tool “now owned by REDLattice”. On paper, the Israeli company becomes American.
- 31 January 2025: WhatsApp notifies roughly ninety users across several countries — journalists and civil society, including the Italian case we already reported — that they had been targeted by Graphite. Citizen Lab and Italian prosecutors later confirmed that Italian journalists and activists were among the targets.
- August 2025: the stop-work order is lifted and the $2 million contract goes active again. No new technical assessment accompanying the reversal appears to have been made public.
- 22 May 2026: the Department of Homeland Security tells NPR that ICE “has no relationship with Paragon Solutions, Inc. or with the company that acquired them” — a sentence that can remain literally true even as use of the tool, under the REDLattice name, continues.
- 23 July 2026: Peters writes the letter that reopens the case, calling the purchase “one of the most significant expansions of DHS and ICE’s surveillance ambitions to date” and noting that “misuse of Graphite is not hypothetical”. He asks whether the software has been deployed inside the United States, against whom, and under what legal authority; he records that his staff had requested briefings from DHS in December 2025 and from ICE in January 2026 and never heard back substantively. Peters does not allege that ICE has used Graphite against journalists or protesters: he asks whether it has been used, and against whom. A senior department official tells CBS that the technology serves “in support of investigations and law enforcement activities”, while respecting “civil liberties and privacy interests”. As a minority member, Peters has no power to compel a reply by the 7 August deadline he set.
Lesson 1: a vendor’s sovereignty is bought, not declared
A federal executive order bars agencies from buying commercial spyware that poses a national security risk or has been misused by foreign governments. The contract with Paragon, an Israeli company, was suspended precisely to decide whether it fell into that category. Eleven months later, the same spyware, plausibly with the same code, goes back into operation at the same agency. In the meantime, no known independent review found that the product itself had changed: the only thing on record that changed is the “owner” field in the corporate register. Whether that is what unblocked the contract we do not know — neither administration made its reasoning public — and we do not need to know in order to draw the lesson. For anyone assessing a critical vendor — in surveillance, AI, or infrastructure — the nationality of the capital is not a reliable proxy for actual control: what matters is who writes the code, who holds the keys, where the data sits and who can see it, not the registered address of whichever holding company owns it this month. It is the principle behind our approach to technological sovereignty: it is proven through direct control of the infrastructure, not through a change of corporate name.
Lesson 2: a ban has a political expiry date, not a technical one
The text of EO 14093 did not change between October 2024 and August 2025. What changed was who enforced it: one administration used it to suspend the contract, the next lifted the suspension with no new technical assessment on the public record — same rule, opposite outcome, and in between one known fact: a new company owner. Anyone who relies on an external ban, regulatory or contractual, as a security guarantee is building on ground that can shift with a change of administration, not a change in actual risk. The question to ask before excluding a vendor because it is “banned elsewhere,” or choosing one because it is “authorised,” is always the same: what would happen if only the interpretation changed, not the risk?
Lesson 3: a denial can be narrowly true and substantively misleading
In May 2026 the Department denies a “relationship” with Paragon Solutions Inc. or with whoever acquired it: a sentence built on a company’s name, not on the tool’s actual use. In July the same Department defends, in general terms, the use of “technology” for investigations. The two statements do not contradict each other on paper, and that is precisely the problem: a denial anchored to the corporate name, not the function, leaves the substance untouched and changes only the label. For anyone drafting or assessing third-party vendor clauses — “no relationship with company X” — the lesson is to always check operational continuity behind a change of corporate name, not stop at whatever name appears in a press statement.
What to do
- Verify beneficial ownership, not the declared registered address, of every critical vendor — and repeat the check at every change of corporate control.
- Never treat a regulatory ban or authorisation as final: map whether it rests on technical risk, political risk, or both, and what would make it lapse.
- In third-party clauses, define “relationship” in terms of product and infrastructure, not corporate name: a denial that is true on the name can be false on the substance.
- Distinguish the declared lawful use from the residual structural risk: the two can coexist, and treating them as alternatives leads to poor decisions on both fronts.
Organisations that want to verify — not merely declare — who really controls their data can do so in two ways, always both available: on-premises, within the client’s own perimeter, or through a dedicated CSIDIA cloud — an environment reserved for a single client, accessed via dedicated VPN, with a data centre in Italy staffed and secured directly by us. Either way, control remains verifiable by whoever uses the system, not granted by whoever sells it.
Do you need to assess a critical vendor without stopping at its registered address or its latest acquisition? Half an hour with one of our experts for an initial map of supply-chain risk.
Sources
- Senate Homeland Security and Governmental Affairs Committee (minority) — Peters Demands ICE Explain Purchase and Use of Powerful Spyware (23 July 2026)
- CBS News — Sen. Gary Peters wants ICE to explain why it bought spyware that can covertly take control of phones (24 July 2026)
- NPR — DHS says ICE has no relationship with Paragon spyware maker (22 May 2026)