Exposé

Zero-Click Spyware Crossed the Border, and It's Reading Chats

A tool built in Israel to break into phones without a tap is now American-owned — and ICE has confirmed it is using spyware to read encrypted messages inside the United States.

Here is what a zero-click attack asks of you: nothing. You do not click a link. You do not enter a password. You do not fail a phishing test, because there is no test. A message lands on WhatsApp or Signal — you may never even see it — and by the time your screen wakes up, the software is already inside, reading the encrypted threads you believed only you and one other person could see. The tool that does this is called Graphite. It was built in Israel. And this spring, a U.S. agency confirmed it is using spyware like it — on this side of the border.

The tool, and who owns it now

Graphite is made by Paragon Solutions, an Israeli-founded company, and it belongs to a class of "mercenary" spyware that turns a phone into a live microphone and an open file drawer. In early 2025, WhatsApp disclosed that roughly 90 of its users — journalists and members of civil society across several countries — had been targeted with Paragon's tool, according to reporting by Reuters and the company's own statements. Researchers at the Citizen Lab at the University of Toronto later confirmed specific journalists and humanitarian aid workers in Italy whose phones were infected through WhatsApp messages, as NPR reported. Italy ended its contract with Paragon in 2025.

Here is the part that should make you sit up straight. That tool no longer answers to a foreign startup. In late 2024, Paragon was purchased by AE Industrial Partners, an American private-investment firm, and merged with a U.S. cybersecurity company, RedLattice, according to Reuters reporting cited by NPR. The border this story crosses is a supply chain: an exploit with Israeli military-intelligence roots, bought with American capital, aimed at the encrypted apps hundreds of millions of Americans open every day.

Why this reaches you

Follow the tool to its customer. In a letter dated April 1, 2026, ICE's acting director, Todd Lyons, told members of Congress that the agency's Homeland Security Investigations unit is using spyware to intercept encrypted messages — framed around disrupting fentanyl traffickers and foreign terrorist organizations, NPR reported. It was the first time ICE acknowledged using this category of tool. The agency had signed a $2 million contract with Paragon at the end of the Biden administration; that contract was paused, then revived by the Trump administration, which lifted the stop-work order in September 2025.

What the letter did not say is the whole problem. It did not say who can be targeted. It did not say whether a warrant is required. It did not rule out using the tool against people inside the United States. Representative Summer Lee, who co-signed the original inquiry, told NPR the response made one thing clear: "They are moving forward with invasive spyware technology inside the United States." Lawyers at the Electronic Frontier Foundation and the Electronic Privacy Information Center told NPR that the content on your phone is protected by the Fourth Amendment — and that they have no visibility into whether agents are seeking warrants first. When the intrusion is zero-click, the only thing standing between you and the inside of your phone is a rule nobody outside the agency can confirm is being followed.

The market you are funding

Here is the connection most coverage misses. This is not one contract. It is a market — and the United States just became one of its largest customers and, now, an owner. The U.K.'s National Cyber Security Centre estimated this year that around 100 countries have access to spyware and cyber-intrusion tools, NPR reported: the same class of capability that keeps surfacing on the phones of journalists and dissidents. Every government that buys in helps fund the research that finds the next zero-click flaw in the messaging app in your pocket. The vulnerability that lets an agency read a trafficker's Signal thread is the same vulnerability that lets a hostile intelligence service read yours. As EPIC's Maria Villegas Bravo put it to NPR, paying for these tools bolsters a market that "weakens American critical infrastructure, including our telecommunications networks."

And the guardrails are coming down at the same moment the buying ramps up. In December 2025, the Treasury Department quietly removed three figures tied to Intellexa — maker of the Predator spyware — from a U.S. sanctions list; one of them was convicted in Greece in February 2026 in connection with Predator abuses, according to NPR's account of BBC reporting. NSO Group, the Israeli maker of Pegasus, remains on the Commerce Department's blacklist and has spent close to $8 million lobbying Washington since 2020, hiring a long roster of consultants and, late last year, a former Trump ambassador as chairman, NPR reported. The pattern rhymes: sanction the industry, then unwind the sanctions; blacklist the vendor, then let American money buy the company.

What to actually do about it

I am not going to tell you to throw your phone in a lake. Zero-click means there is nothing for you to fall for, so the usual advice — do not click, do not reuse passwords — mostly misses the threat. What limits exposure is boring and real. Update your operating system the day patches ship, because a zero-click chain gets burned once it is found and fixed. Turn on your phone's hardened setting — Lockdown Mode on iPhone, Advanced Protection on Android — if you are a journalist, an organizer, or anyone with reason to think you are a target. Reboot regularly; some implants do not survive a restart. None of this makes you immune. It raises the cost of coming after you, which for most people is the entire game.

But the real fix is not on your lock screen. It is whether Congress forces this industry into daylight — warrants, targeting rules, an honest accounting of which agencies hold which tools — before the next capability crosses the border quietly, picks up an American owner, and starts reading the one app you assumed was safe.