How spyware from eSurv, which was helping police hack suspects' phones in Italy, was allegedly used by its employees to hack the phones of innocent Italians
police & prosecutors across Italy, an intelligence agency, the most powerful mafia organisation in Europe, a judge accused of corruption, & a secretive group called the “Black Team.” Ryan Gallagher / @rj_gallagher : I went to Italy to investigate a surveillance technology company that was helping police hack the phones of terrorists, but then allegedly went rogue & illegally spied on innocent people: https://www.bloomberg.com/...
Context & Ripple Effects
Ryan Gallagher's investigation lands at the start of an arc the related coverage keeps extending: eSurv built phone-hacking tools for Italian police and prosecutors, then allegedly let its own staff — including a secretive 'Black Team' — turn those tools on ordinary Italians. That insider-abuse pattern is exactly what later reporting on Italy's surveillance sector documents at scale, with the country becoming an unexpected spyware hub specializing in cheaper tools and running thousands of operations since 2021 ([[a:879253]]).
The story also foreshadows the vendor-trust problem now standard in European spyware coverage: Citizen Lab later found European journalists' iPhones hacked with Paragon spyware ([[a:886843]]), and even US sanctions on NSO Group haven't slowed government deployment of these tools. Italy's own oversight machinery is not immune either — police have since searched the country's data protection agency itself as part of a corruption probe ([[a:1161615]]).
First-order effects
- Innocent Italians whose phones were hacked had no legal process against them — the abuse came from inside the vendor police trusted, so victims' only recourse is through prosecutors investigating eSurv itself.
- Italian police and prosecutors who deployed eSurv tooling face a credibility problem: their lawful interception capability is now tied to allegations of illegal spying on citizens.
Second-order effects
- Government buyers of commercial spyware inherit a vendor-insider risk they cannot audit — the same capability sold for suspect investigations can be repurposed privately, pushing agencies toward stricter contractual controls or in-house tooling.
- Rival surveillance vendors now compete partly on trustworthiness claims, while investigative outlets and groups like Citizen Lab become de facto auditors of an industry that official regulators struggle to inspect.
Third-order effects
- If the pattern holds — cheap national toolmakers, insider abuse, and oversight bodies themselves under corruption probes — Europe faces pressure to regulate the spyware supply chain the way it regulates other dual-use exports, rather than treating each scandal as isolated.
- Italy's trajectory from eSurv to a full-fledged spyware hub suggests a structural split in the industry: premium vendors like NSO draw sanctions, while lower-cost national champions grow beneath the regulatory radar.
The trend: Commercial spyware is consolidating into a national-industrial ecosystem across Europe where insider abuse and weak oversight, not export controls, set the real limits on who gets surveilled.