Sources: in 2021, the phone of a US and Greek national who worked on Meta's security and trust team was infected with Predator spyware from an Athens-based firm
New York TimesMatina Stevis-Gridneff
Context & Ripple Effects
This report extends the documented reach of Predator beyond exiled Egyptians whose iPhones were compromised in 2021, as detailed in the earlier Citizen Lab findings. It also lands after researchers traced three Predator campaigns to exploits of Android vulnerabilities, showing the tool's use across a broader technical attack surface in Google's campaign analysis.
The significance is not just the individual target: a member of Meta's security and trust organization was reportedly affected, putting commercial spyware in closer proximity to the teams charged with detecting and disrupting abuse.
First-order effects
Meta must treat the reported 2021 compromise as an operational security incident involving a security-and-trust employee, including reviewing potential exposure around that person's communications and work accounts.
The report adds a high-profile alleged target to Predator's record, increasing attention on the Athens-based firm behind the deployment described by sources.
Second-order effects
Security teams at major platforms are likely to give greater weight to employee-targeting scenarios, not only cases involving journalists, dissidents, or political figures.
The finding reinforces pressure on mobile-security researchers and device vendors to identify and close exploit chains used by commercial spyware; prior reporting tied Predator campaigns to five Android vulnerabilities identified in Google's research.
Third-order effects
If spyware operators increasingly target people who investigate platform abuse, commercial surveillance becomes a resilience issue for technology companies as well as a civil-liberties issue for individual victims.
The pattern points toward a surveillance market in which public exposure of tools and vulnerabilities does not by itself end deployment; accountability will depend on whether technical defenses and oversight constrain suppliers and customers together.
The trend: Commercial spyware is broadening from a tool associated with political targeting into a persistent security risk for the researchers, platforms, and institutions that investigate it.
BREAKING: #Predator spyware used on manager at @Meta's security & trust team. @ArtemisSeaford is first known 🇺🇸US national hacked w/Predator in the EU. We @citizenlab found infection. Mercenary spyware is spiraling out of control. 1/ By @MatinaStevis https://www.nytimes.com/... h…
A security policy manager at Meta was hacked with Predator, according to new reporting by @nytimes and forensics by @citizenlab. The phishing message sent to @ArtemisSeaford used a COVID vaccine appointment as context to trick her into clicking the link. https://www.nytimes.com/.…
Anyone, anywhere can fall prey to spyware hacking. I should know - I was a #Predator target. This does not make it normal. We need our governments and international bodies to protect us. https://www.nytimes.com/...
6/ I hope is this story will encourage other victims of spyware abuse to speak out. There are more of us out there, and our stories should be neither instrumentalized nor silenced. We deserve better. Ultimately, we need our governments and EU bodies to protect us.
1/ The evidence suggests that my hacking with Predator was based on private information most likely obtained through state intelligence wiretapping. https://www.nytimes.com/...
The DOJ is investigating TikTok/ByteDance for its employees in China tracking a leak to a journalist via IP addresses; this is an even more invasive effort against a journalist, now by a foreign government. https://twitter.com/...
4/ This #Predator case is further evidence that the mercenary spyware problem in the EU is out of control. And it's directly impacting US nationals working in on sensitive topics. Here's Artemis, in her own words.👇 https://twitter.com/...
3/ #Greek authorities in denial mode over #Predator. But @ArtemisSeaford's case may hard for them to get distance from: the message used to infect her may have been copied from a legit SMS scooped up by a traditional gov wiretap. https://twitter.com/...
2/ @ArtemisSeaford's #Predator spyware targeting was diabolical. She got an “appointment confirmation” text after making a COVID vaccine appointment. It contained her actual appointment details & appeared to come from the #Greek state vaccine agency. Most would have clicked. http…
Journalism and civil society is why democracy survives. Grateful for the excellent technical work and amazing support of @citizenlab @jsrailton and the integrity of the work of @MatinaStevis and @nytimes in bringing out my #Predator hacking story. https://twitter.com/...
First known case of an American national being targeted with a #cyberespionage #predator tool in the EU. We @citizenlab discovered the infection👇🏽. https://www.nytimes.com/... https://twitter.com/...
.@Meta Manager Was Hacked With Spyware, Wiretapped In Greece The full story of @ArtemisSeaford, the first known American national to be targeted with Predator in the EU while also being surveilled by the Greek national intelligence service. https://www.nytimes.com/...
⚠️ A U.S. and Greek national who worked on Meta's security and trust team while based in Greece was placed under a yearlong wiretap by the Greek national intelligence service and hacked with a powerful cyberespionage tool ✍️ @MatinaStevis https://www.nytimes.com/...
Meta manager @ArtemisSeaford is the first known American national to be targeted with Predator, an Israeli spyware, in the EU. She was also being surveilled by the Greek national intelligence service By @MatinaStevis https://www.nytimes.com/...