Sources: in 2021 the phone of a US and Greek national who worked on Meta's security and trust team was infected with Predator spyware, from an Athens-based firm
Artemis Seaford, a dual U.S.-Greek national, was targeted with a cyberespionage tool while also under a wiretap by the Greek spy agency … Tweets: @jsrailton , @runasand , @citizenlab , @matinastevis , @e_triantafillou , and @avischarf Tweets: John Scott-Railton / @jsrailton : BREAKING: #Predator spyware used on manager at @Meta's security & trust team. @ArtemisSeaford is first known 🇺🇸US national hacked w/Predator in the EU. We @citizenlab found infection. Mercenary spyware is spiraling out of control. 1/ By @MatinaStevis https://www.nytimes.com/... https://twitter.com/... Runa Sandvik / @runasand : A security policy manager at Meta was hacked with Predator, according to new reporting by @nytimes and forensics by @citizenlab. The phishing message sent to @ArtemisSeaford used a COVID vaccine appointment as context to trick her into clicking the link. https://www.nytimes.com/... https://twitter.com/... @citizenlab : First known case of an American national being targeted with a #cyberespionage #predator tool in the EU. We @citizenlab discovered the infection👇🏽. https://www.nytimes.com/... https://twitter.com/... Matina Stevis-Gridneff / @matinastevis : .@Meta Manager Was Hacked With Spyware, Wiretapped In Greece The full story of @ArtemisSeaford, the first known American national to be targeted with Predator in the EU while also being surveilled by the Greek national intelligence service. https://www.nytimes.com/... Eliza Triantafillou / @e_triantafillou : ⚠️ A U.S. and Greek national who worked on Meta's security and trust team while based in Greece was placed under a yearlong wiretap by the Greek national intelligence service and hacked with a powerful cyberespionage tool ✍️ @MatinaStevis https://www.nytimes.com/... Avi Scharf / @avischarf : Meta manager @ArtemisSeaford is the first known American national to be targeted with Predator, an Israeli spyware, in the EU. She was also being surveilled by the Greek national intelligence service By @MatinaStevis https://www.nytimes.com/...
Context & Ripple Effects
Artemis Seaford, a dual U.S.-Greek national who worked on Meta's security and trust team, was hit twice over: Citizen Lab confirmed her 2021 infection with Predator spyware from an Athens-based firm, while Greece's intelligence service simultaneously kept her under a yearlong wiretap. She is the first known U.S. national hacked with Predator inside the EU.
The case lands amid a documented surge in government spyware despite U.S. sanctions on the NSO Group — an investigation into booming government spyware use that included the DEA's secret deployment of Graphite — and follows Citizen Lab and Microsoft's exposure of Tel Aviv-based QuaDream, which hacked journalists and politicians on iOS 14 iPhones.
First-order effects
- Seaford becomes the first publicly known U.S. national targeted with Predator in Europe, and Citizen Lab's attribution drags a previously low-profile Athens vendor into the mercenary-spyware spotlight alongside NSO and QuaDream.
- A Meta security-and-trust insider being compromised shows that even personnel whose job is platform integrity are within reach of state-grade commercial tools.
Second-order effects
- Greece faces acute political exposure: its own intelligence service wiretapped the same person its domestic spyware vendor attacked, forcing scrutiny of both EYP oversight and the Athens firm's export clients.
- Washington now has a direct constituency — an American citizen — giving U.S. officials a concrete case to press Athens and EU counterparts on mercenary-spyware controls, much as the NSO sanctions debate did earlier.
Third-order effects
- If the pattern holds, the market is fragmenting rather than shrinking: sanctions on one vendor (NSO) simply shift demand to new national suppliers like the Athens firm, QuaDream, and Paragon, each discovered after the fact by researchers.
- Targeting is broadening from journalists and opposition figures toward corporate security staff and dual nationals — people who sit at the junction of companies and governments — which pushes EU and U.S. regulators toward licensing regimes rather than single-vendor bans.
The trend: Commercial spyware is proliferating past sanctioned vendors into new national suppliers, with researcher attribution — not regulation — currently the main brake on its spread.