A Citizen Lab report finds that two European journalists had their iPhones hacked with Paragon spyware; Apple fixed the zero-day used in the spyware in February
Act Now To Prevent Attacks Markus Kasanmascheff / WinBuzzer : Apple Confirms iPhone Flaw Was Used to Spy on Journalists Kevin Poireault / Infosecurity : European Journalists Targeted by Paragon Spyware, Citizen Lab Confirms Bill Toulas / BleepingComputer : Graphite spyware used in Apple iOS zero-click attacks on journalists Yadullah Abidi / The Mac Observer : Zero-Tap iMessage Hack Let Hackers Slip Into iPhones Undetected Pierluigi Paganini / Security Affairs : Paragon Graphite Spyware used a zero-day exploit to hack at least two journalists' iPhones Bluesky: @evacide : If you have an iPhone, make sure you always have the latest security update. — If you are concerned that you might be targeted by government spyware, enable Lockdown Mode. [embedded post] @eunews.social : Spyware from a U.S.-backed Israeli company was used to target the phones of at least three prominent journalists in Europe, two of whom are editors at an investigative news site in Italy, according to digital researchers at Citizen Lab, citing new forensic evidence of the attacks. Nathan Patin / @nathanpatin : Now Citizen Lab has forensically confirmed 2/3 European journalists were targeted w/ Paragon spyware citizenlab.ca/2025/06/firs... [embedded post] @citizenlab.ca : NEW REPORT: Our forensic analysis confirms ✅ two more European journalists targeted with Paragon's Graphite spyware. — Read it here: citizenlab.ca/2025/06/firs... Lorenzo Franceschi-Bicchierai / @lorenzofb : As always, worth reading Citizen Lab's whole report here: citizenlab.ca/2025/06/firs... Sean Lyngaas / @snlyngaas : More zero-click spyware found on journalists' phones in Europe. One of the victims, Italian journalist Piro Pellegrino, went on the record in this analysis from @citizenlab.ca: citizenlab.ca/2025/06/firs... @natynettle : New bombshell report from Citizen Lab confirming with high confidence that Italian Fanpage.it journalist Ciro Pellegrino + anonymous European journalist were targeted with Paragon's Graphite mercenary spyware. — This scandal is not going away... citizenlab.ca/2025/06/firs... Mastodon: Zack Whittaker / @zackwhittaker@mastodon.social : And for more on _that_ story about the two journalists whose phones were hacked, @lorenzofb also has you covered. — From earlier today: https://techcrunch.com/... Lorenzo Franceschi-Bicchierai / @lorenzofb@infosec … : UPDATE: COPASIR, the Italian parliament committee that investigated the Paragon scandal referred to a section in its report that says it could expand its inquiry, including into “the alleged mobile device intrusions disclosed by two other journalists in recent weeks.” — Obviously one of those two journalists is Pellegrino. … X: Hannah Neumann / @hneumannmep : Our debate @Europarl_EN on Monday about spyware abuse is just on time. How much longer can @EU_Commission hide behind member states assuring that they are fully on top of things - while systematically violating fundamental rights? Thanks once more @citizenlab for exposing it: John Scott-Railton / @jsrailton : 8/ I think our latest report will deepen Italy vs. Paragon tensions. Paragon doesn't want to be stuck w/unexplained abuses against journalists. I think they want to be able to it on a customer & wash hands... But when your customer is a government... John Scott-Railton / @jsrailton : 🚨NEW INVESTIGATION: We just forensically unmasked #Paragon's Apple spyware. Zero-click targets: Journalists. In 🇪🇺Europe. Like 🇮🇹Italian reporter @ciropellegrino. Reopen's #Italy's spyware scandal. Follows our @citizenlab investigation of their Android spyware. 1/ [image] LinkedIn: Lorenzo Franceschi-Bicchierai : NEW: Researchers found forensic evidence of Paragon's spyware on the iPhones of two journalists. — One is Ciro Pellegrino, who works for Fanpage. … Ronald Deibert : We The Citizen Lab have a new report out today. Yet more journalists' phones hacked in Europe — attributed to mercenary spyware vendor Paragon with high confidence. … Forums: r/cybersecurity : “There's no link to click, attachment to download, file to open or mistake to make.” For curiosity sake, how are journalists supposed to protect themselves from this? r/apple : Apple fixes new iPhone zero-day bug used in Paragon spyware hacks BeauHD / Slashdot : Researchers Confirm Two Journalists Were Hacked With Paragon Spyware See also Mediagazer
Context & Ripple Effects
The finding extends a recent pattern around Paragon: WhatsApp said it had disrupted a campaign targeting journalists and civil-society members earlier this year. Citizen Lab’s forensic confirmation now ties that pattern to compromised iPhones and a specific exploit path.
It also fits a longer record of commercial spyware using zero-click iPhone attacks, including Citizen Lab’s documentation of NSO zero-click exploits and its reporting on QuaDream’s targeting of journalists and public-interest figures. The important distinction is that Apple had already closed the identified route in February.
First-order effects
- Apple’s February update removes the disclosed zero-day route used in these intrusions, while the two confirmed targets must treat their devices and communications as potentially exposed.
- Citizen Lab’s attribution puts Paragon’s Graphite product at the center of a documented case involving European journalists, increasing immediate scrutiny of the vendor and its customers.
Second-order effects
- News organizations, civil-society groups, and other high-risk iPhone users have a clearer reason to prioritize Apple’s security updates and incident-response procedures for suspected device compromise.
- The case adds to pressure on commercial-spyware vendors to account for how their tools are deployed, following the earlier WhatsApp disruption of a Paragon-linked targeting campaign.
Third-order effects
- If repeated forensic findings continue to connect mercenary spyware products to journalists, the market’s principal constraint is likely to shift from vendors’ technical claims toward customer oversight, disclosure, and legal accountability.
- Platform vendors will remain a critical defensive layer: rapid patches can close known exploit chains, but recurring zero-click attacks show why device security and rights protections must operate together.
The trend: Commercial spyware is becoming an increasingly visible governance problem as forensic investigations repeatedly link zero-click mobile exploits to targeting of journalists and civil society.