An investigation details the Intellexa Alliance, a shady group of European companies that marketed and sold spyware like Predator to authoritarian regimes
The Intellexa Alliance is the name of the shady group of European companies that supplies dictators and despots with cyberweapons.
It also follows the U.S. decision to place Intellexa and Cytrox under an export prohibition on access to U.S. technology, making the alliance’s sales channels and corporate structure central to enforcement scrutiny.
First-order effects
The report places the Intellexa Alliance and Predator under sharper public and regulatory scrutiny by tying a network of European companies to sales into authoritarian states.
For the alliance’s constituent firms, the allegations raise immediate due-diligence and reputational pressure around customers, intermediaries, and the technology used to support spyware deployments.
Second-order effects
Export-control authorities and technology suppliers have stronger reason to examine whether corporate affiliates or intermediaries can circumvent restrictions aimed at a named spyware vendor.
Rival surveillance vendors and government buyers face a less defensible distinction between a formally regulated supplier and the wider corporate network that markets or enables its tools.
Third-order effects
If investigations, sanctions, and prosecutions continue to reach founders and connected firms—as in the Treasury sanctions targeting Intellexa-linked individuals and later Greek case—the commercial-spyware sector may be treated less as a collection of isolated vendors and more as an accountable supply chain.
That would shift compliance toward tracing ownership, technical dependencies, and end users, rather than relying principally on restrictions directed at a single product or company.
The trend: Commercial spyware oversight is moving from vendor-by-vendor restrictions toward scrutiny of the cross-border corporate networks that sell, support, and finance surveillance capabilities.
V proud that @amnestytech today publishes The Predator Files: Caught in the Net. The story is a complicated one but worth the effort because spyware like Predator is a fundamental threat to human rights. A few key pieces in this story: https://securitylab.amnesty.org/ ...
@AmnestyTech ... The same attacker account also targeted the President of Taiwan (@iingwen) and in the same reply sent the attack link United States Senator @SenJohnHoeven as he was tagged in the initial post. US Congressman Michael McCaul was also similarly targeted with a Preda…
First, worth reading our post on what Intellexa's surveillance products actually do. @amestytech's technologists have made the explanations as accessible as possible. Includes recommendations for mitigations to help protect potential civil society targets https://securitylab.amne…
The Head of the Security Lab, @donnchac provides an excellent summary of the research findings in our main report. So much effort went into the research and how the evidence was presented - with support from experts across the Amnesty movement. https://x.com/...
🚨 The #PredatorFiles spyware scandal continues. New investigation from @Amnesty Security Lab in collaboration with @EICnetwork reveals brazen targeting of civil society, politicians and officials around the world with “EU-regulated” spyware. 🧵 1/ https://securitylab.amnesty.org/ …
Latest report from @amnesty in collaboration with @EICnetwork reveals brazen targeting of civil society, politicians and officials around the world with “EU-regulated” spyware. https://www.amnesty.org/...
@AmnestyTech Internal Intellexa alliance records obtained by @MediapartEN and @DerSpiegel and shared with @EICnetwork helped uncover the full story of spyware sales, exports and shipments which enabled these reckless Predator attacks targeting civil society. [image]
“If the press found out about the Predator contract with Egypt, “we're dead,” the Frenchman said in June 2021. Ironically, that conversation was intercepted by the French federal police force.” #predatorfiles https://www.spiegel.de/...
@AmnestyTech ... The Predator spyware operator recklessly sent public Twitter replies with containing infection links for “EU-regulated” Predator to senior EU political figures including the @EU_Commission and EU Parliament President Roberta Metsola (@EP_President) [image]
@AmnestyTech ... Amnesty also discovered that Berlin-based journalist Khoa Lê Trung, editor-in-chief @thoibao_de was also targeted. He has receive threats for his work critical of the Viet Nam government and needs police protection. EU spyware adds to threats he faces [image]
Predator spyware targets uncovered in @AmnestyTech's extensive 50-page report include the accounts of Vietnamese journalists and opposition groups, as well as academics, European political leaders and EU institutions, United Nations officials and diplomats.
The Intellexa Alliance is the name of the shady group of European companies that supplies dictators and despots with cyberweapons. The mass spyware attacks have also been lucrative for German investors. https://www.spiegel.de/...
We told the story together with our partners @EICnetwork who focused on the business and exports side of the scandal. Each publication took a slightly different focus but this Der Spiegel piece in English is a good starting point: https://www.spiegel.de/...