/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

Sources: in 2021, the phone of a US and Greek national who worked on Meta's security and trust team was infected with Predator spyware from an Athens-based firm

New York Times Matina Stevis-Gridneff

Context & Ripple Effects

This report extends the documented reach of Predator beyond exiled Egyptians whose iPhones were compromised in 2021, as detailed in the earlier Citizen Lab findings. It also lands after researchers traced three Predator campaigns to exploits of Android vulnerabilities, showing the tool's use across a broader technical attack surface in Google's campaign analysis.

The significance is not just the individual target: a member of Meta's security and trust organization was reportedly affected, putting commercial spyware in closer proximity to the teams charged with detecting and disrupting abuse.

First-order effects

  • Meta must treat the reported 2021 compromise as an operational security incident involving a security-and-trust employee, including reviewing potential exposure around that person's communications and work accounts.
  • The report adds a high-profile alleged target to Predator's record, increasing attention on the Athens-based firm behind the deployment described by sources.

Second-order effects

  • Security teams at major platforms are likely to give greater weight to employee-targeting scenarios, not only cases involving journalists, dissidents, or political figures.
  • The finding reinforces pressure on mobile-security researchers and device vendors to identify and close exploit chains used by commercial spyware; prior reporting tied Predator campaigns to five Android vulnerabilities identified in Google's research.

Third-order effects

  • If spyware operators increasingly target people who investigate platform abuse, commercial surveillance becomes a resilience issue for technology companies as well as a civil-liberties issue for individual victims.
  • The pattern points toward a surveillance market in which public exposure of tools and vulnerabilities does not by itself end deployment; accountability will depend on whether technical defenses and oversight constrain suppliers and customers together.

The trend: Commercial spyware is broadening from a tool associated with political targeting into a persistent security risk for the researchers, platforms, and institutions that investigate it.

Discussion

  • @jsrailton John Scott-Railton on x
    BREAKING: #Predator spyware used on manager at @Meta's security & trust team. @ArtemisSeaford is first known 🇺🇸US national hacked w/Predator in the EU. We @citizenlab found infection. Mercenary spyware is spiraling out of control. 1/ By @MatinaStevis https://www.nytimes.com/... h…
  • @runasand Runa Sandvik on x
    A security policy manager at Meta was hacked with Predator, according to new reporting by @nytimes and forensics by @citizenlab. The phishing message sent to @ArtemisSeaford used a COVID vaccine appointment as context to trick her into clicking the link. https://www.nytimes.com/.…
  • @artemisseaford Artemis Seaford on x
    Anyone, anywhere can fall prey to spyware hacking. I should know - I was a #Predator target. This does not make it normal. We need our governments and international bodies to protect us. https://www.nytimes.com/...
  • @artemisseaford Artemis Seaford on x
    6/ I hope is this story will encourage other victims of spyware abuse to speak out. There are more of us out there, and our stories should be neither instrumentalized nor silenced. We deserve better. Ultimately, we need our governments and EU bodies to protect us.
  • @artemisseaford Artemis Seaford on x
    1/ The evidence suggests that my hacking with Predator was based on private information most likely obtained through state intelligence wiretapping. https://www.nytimes.com/...
  • @anupamchander Anupam Chander on x
    The DOJ is investigating TikTok/ByteDance for its employees in China tracking a leak to a journalist via IP addresses; this is an even more invasive effort against a journalist, now by a foreign government. https://twitter.com/...
  • @jsrailton John Scott-Railton on x
    4/ This #Predator case is further evidence that the mercenary spyware problem in the EU is out of control. And it's directly impacting US nationals working in on sensitive topics. Here's Artemis, in her own words.👇 https://twitter.com/...
  • @jsrailton John Scott-Railton on x
    3/ #Greek authorities in denial mode over #Predator. But @ArtemisSeaford's case may hard for them to get distance from: the message used to infect her may have been copied from a legit SMS scooped up by a traditional gov wiretap. https://twitter.com/...
  • @jsrailton John Scott-Railton on x
    2/ @ArtemisSeaford's #Predator spyware targeting was diabolical. She got an “appointment confirmation” text after making a COVID vaccine appointment. It contained her actual appointment details & appeared to come from the #Greek state vaccine agency. Most would have clicked. http…
  • @artemisseaford Artemis Seaford on x
    Journalism and civil society is why democracy survives. Grateful for the excellent technical work and amazing support of @citizenlab @jsrailton and the integrity of the work of @MatinaStevis and @nytimes in bringing out my #Predator hacking story. https://twitter.com/...
  • @evacide Eva on x
    The COVID appointment lure is really the cherry on this APT sundae. https://twitter.com/...
  • @citizenlab @citizenlab on x
    First known case of an American national being targeted with a #cyberespionage #predator tool in the EU. We @citizenlab discovered the infection👇🏽. https://www.nytimes.com/... https://twitter.com/...
  • @matinastevis Matina Stevis-Gridneff on x
    .@Meta Manager Was Hacked With Spyware, Wiretapped In Greece The full story of @ArtemisSeaford, the first known American national to be targeted with Predator in the EU while also being surveilled by the Greek national intelligence service. https://www.nytimes.com/...
  • @e_triantafillou Eliza Triantafillou on x
    ⚠️ A U.S. and Greek national who worked on Meta's security and trust team while based in Greece was placed under a yearlong wiretap by the Greek national intelligence service and hacked with a powerful cyberespionage tool ✍️ @MatinaStevis https://www.nytimes.com/...
  • @avischarf Avi Scharf on x
    Meta manager @ArtemisSeaford is the first known American national to be targeted with Predator, an Israeli spyware, in the EU. She was also being surveilled by the Greek national intelligence service By @MatinaStevis https://www.nytimes.com/...