Private spyware gives governments access to capabilities once associated with elite intelligence agencies. Depending on the product and method used, an operator may collect messages, contacts, photographs, location data, recordings, and other information from a targeted device.
Journalists, activists, dissidents, attorneys, and human rights defenders face particular danger because compromising one phone can expose entire networks of confidential sources. A surveillance operation aimed at one person may quietly map everyone who trusted her.
Commercial spyware can be used in lawful investigations. However, government agencies should still be able to explain what they purchased, which legal authority permits its use, who may be targeted, what safeguards protect political activity, and how misuse is detected. “National security” is not a magical phrase that turns unanswered questions into oversight.
This Resistance Survival Guide explains how to investigate government use of private spyware without making technical claims the evidence cannot support. It also explains how to protect potential victims, preserve evidence, follow procurement records, and separate a confirmed infection from speculation about who ordered it.
Understand the Different Surveillance Tools
Commercial spyware is privately developed surveillance software sold or licensed to government customers. Some products can remotely compromise a phone. Others help investigators extract information after authorities physically seize or obtain access to a device.
These methods should not be carelessly combined. Remote spyware, forensic extraction equipment, location tracking services, and ordinary search tools have different capabilities, legal authorities, contracts, and evidentiary traces.
Citizen Lab has documented Pegasus infections affecting journalists and civil society figures. It has also investigated government use of Cellebrite forensic extraction products against activists in Jordan, Kenya, and Russia. Those investigations demonstrate why researchers must identify the specific product and method instead of treating every suspicious battery problem as proof that an intelligence service has moved into the guest room.
Why Government Spyware Use Requires Scrutiny
Spyware can expose far more than one person’s private conversations. When used against a journalist, it may reveal confidential sources, unpublished reporting, legal advice, travel plans, and internal newsroom discussions. When used against an activist, it may identify organizers, donors, witnesses, protest participants, and vulnerable community members.
In the United States, Executive Order 14093 restricts federal operational use of commercial spyware that presents significant security risks or significant risks of improper foreign use. The order specifically addresses documented misuse involving journalists, activists, dissidents, political opponents, and human rights defenders. It is a risk based restriction, not a universal prohibition on every government acquisition or use of commercial spyware.
Procurement records therefore matter. In 2025, independent technology outlet 404 Media reported that Immigration and Customs Enforcement had reactivated a contract involving Paragon spyware. The outlet later sued for related records and reported receiving heavily redacted documents. A contract does not prove that a particular person was targeted. It does establish a trail worth following, which is why procurement paperwork occasionally becomes more exciting than the people hiding it intended.
Step by Step Guide
Step One: Define the Suspected Surveillance Program
Begin with a precise investigative question. Identify the agency, jurisdiction, suspected vendor, relevant office, approximate period, and type of surveillance involved.
Separate what is confirmed from what is alleged. A confirmed contract is not proof of deployment. A security notification may show attempted targeting without proving successful infection. A forensic finding may confirm compromise without identifying the government operator responsible.
Write a working statement such as: “This investigation examines whether Agency X acquired or used Product Y between 2024 and 2026, what legal authority governed its use, and whether safeguards protected journalists and political activists.”
Step Two: Build a Vendor and Product Map
Record the vendor’s legal name, parent company, subsidiaries, product names, former names, local distributors, resellers, consultants, and government contracting partners.
Search corporate registries, procurement databases, budget records, meeting materials, lobbying disclosures, court filings, export records, and vendor presentations. A spyware company may sell through a local subsidiary or technology integrator, allowing the recognizable product name to disappear from the contract.
Search capability descriptions as well as brand names. Contracts may refer to lawful access, mobile device exploitation, advanced collection, digital intelligence, forensic extraction, remote access, or investigative support. Bureaucracy rarely labels the folder “Questionable Spyware Purchases For Reporters To Find.”
Step Three: Follow the Procurement Trail
Search federal, state, and local purchasing systems for contracts, purchase orders, solicitations, amendments, invoices, renewals, training packages, maintenance agreements, and sole source justifications.
Record the contract number, award date, purchasing office, funding source, total value, performance period, contracting officer, vendor, and product description. Check whether the purchase moved through an emergency process or an existing contract vehicle.
Compare the original award with later modifications. A small evaluation contract can become a larger operational program through amendments that receive little public attention.
Step Four: Request the Complete Contract File
Submit a focused public records request for the solicitation, vendor proposal, statement of work, capability description, privacy review, legal memorandum, security assessment, purchase order, invoice, amendment, training material, acceptance record, and correspondence concerning approval.
Request records by contract number, vendor, product, office, and date range. Ask for attachments and final versions. If records are withheld, request the legal basis for each redaction and all reasonably segregable material.
Do not request every agency email containing the word surveillance. That approach creates an enormous haystack and gives the agency several years to admire it.
Step Five: Identify the Legal Authority
Determine which statute, warrant authority, court order, policy, regulation, executive order, or internal directive permits the government to use the product.
Ask whether investigators require a warrant, supervisory approval, prosecutor review, emergency certification, or judicial authorization. Identify any rules governing journalists, attorneys, elected officials, political organizations, protected speech, or confidential sources.
For federal commercial spyware use, examine whether the agency completed the risk determination, certification, internal controls, and oversight procedures required by Executive Order 14093. A purchase labeled lawful still requires someone to show their work.
Step Six: Find the Targeting and Approval Rules
Request policies describing who may be targeted, which crimes qualify, what evidence is required, who approves deployment, how long surveillance may continue, and when emergency use is permitted.
Search for special procedures covering members of the news media, political organizations, attorneys, minors, foreign nationals, and people engaged in demonstrations. Request templates for targeting requests, approval forms, renewal decisions, and after action reviews.
Policies alone do not prove compliance. However, they establish the standard against which actual cases can be tested.
Step Seven: Trace Training and Operational Support
Request training schedules, attendee lists, certification records, user manuals, vendor support tickets, travel expenses, webinar invitations, and communications with technical consultants.
Training records can identify which office operated the system and when the capability became usable. Support records may reveal deployment problems, upgrades, license limits, or interactions with the vendor.
Do not publish operational details that could expose an active victim or create a new security risk. Accountability reporting does not require handing a surveillance operator a complimentary troubleshooting guide.
Step Eight: Preserve Possible Device Evidence Safely
If a journalist or activist receives a threat notification or suspects a targeted compromise, advise her to contact a qualified digital security organization from a separate trusted device. Access Now operates a round the clock Digital Security Helpline for civil society, while Amnesty International’s Security Lab publishes guidance and may support eligible investigations.
Do not install random detection applications, erase the phone, reset accounts from the suspected device, or upload a full backup to an unfamiliar service. Those actions may destroy evidence or expose additional sensitive material.
Preserve screenshots of notifications, dates, times, unusual messages, account alerts, device details, and relevant correspondence. Follow the forensic expert’s instructions before changing the device.
Step Nine: Separate Targeting From Infection and Attribution
Use three distinct findings. Targeting means someone appears to have selected or attempted to reach the person. Infection means forensic evidence shows that the device was compromised. Attribution means credible evidence connects the activity to a particular operator, agency, or government.
Do not leap from infection to government identity. Citizen Lab’s investigation involving former European Parliament member Stelios Kouloglou confirmed repeated Pegasus infections but did not attribute them to a particular government.
A careful report may conclude that spyware was present while attribution remains unknown. Accuracy is more persuasive than dramatic certainty wearing a trench coat.
Step Ten: Reconstruct the Government Decision Chain
Identify every official who requested, reviewed, approved, purchased, operated, renewed, or audited the spyware.
Request approval memoranda, meeting notes, delegated authority documents, legal reviews, privacy assessments, audit logs, disciplinary records, and communications with senior officials. Compare formal authorization with the offices that actually used the system.
A signature on a contract identifies the buyer. It does not necessarily identify the person who selected the target or received the collected information.
Step Eleven: Trace the Collected Information
Determine what information the product could collect and what the agency was authorized to obtain. Then examine where that information was stored, who could access it, how long it was retained, and whether it was shared with other agencies or contractors.
Request data retention policies, access control records, dissemination rules, deletion schedules, audit logs, and agreements with partner agencies. Ask whether privileged, journalistic, or political information requires special handling.
A surveillance program without reliable access logs is essentially an unlocked filing cabinet with better branding.
Step Twelve: Test for Retaliatory or Political Patterns
Compare known or suspected targeting dates with major investigations, protests, lawsuits, elections, whistleblower disclosures, border crossings, arrests, and meetings with confidential sources.
Look for repeated targeting within the same newsroom, advocacy organization, legal team, or protest network. Examine whether surveillance began shortly after criticism of an agency or contact with a government opponent.
Timing can support an inference, but it does not prove motive. Label documented events, forensic findings, and interpretations separately.
Step Thirteen: Audit Oversight and Misuse Investigations
Request internal audits, inspector general reports, compliance reviews, user access logs, complaints, suspension records, misuse referrals, disciplinary actions, and notices sent to affected people.
Determine whether the agency can identify every deployment and the official who authorized it. Check whether independent reviewers examined target selection, minimization, retention, and dissemination.
Oversight that depends entirely on operators volunteering their own mistakes is not oversight. It is a suggestion box placed inside the surveillance van.
Step Fourteen: Publish Without Endangering Sources
Before publication, ask the affected people and qualified security experts what technical details could create additional risk. Remove personal identifiers, confidential source information, device backups, phone numbers, and unpublished indicators when disclosure could help an attacker.
Describe the evidence accurately. State whether the investigation found acquisition, attempted targeting, confirmed infection, or attributable government use. Give the agency and vendor a meaningful opportunity to respond.
Publish supporting contracts, policies, timelines, and methodology when safe. Readers should be able to see which conclusions come from documents and which remain informed inferences.
Red Flags That Deserve Immediate Attention
Warning signs include secret or misleading product descriptions, purchases routed through intermediaries, missing legal reviews, blanket redactions, emergency contracts without documented urgency, and systems operating without complete audit logs.
Other concerns include targeting rules that ignore protected journalism, contracts that let vendors access collected data, repeated use against peaceful activists, indefinite retention, and officials who cannot identify how many devices were targeted.
A threat notification should also be taken seriously. It is not automatic proof of infection, but it deserves expert review rather than a cheerful reboot followed by denial.
Turning Evidence Into Accountability
Send documented findings to inspectors general, legislative oversight committees, civil liberties organizations, independent journalists, public defenders, and attorneys representing affected people.
Ask the government to publish vendor names, contract values, legal standards, aggregate deployment statistics, protected activity safeguards, retention limits, misuse findings, and audit results.
Strong reforms include judicial authorization, heightened protection for journalists and political activity, independent technical audits, complete access logging, strict deletion requirements, notice to targets when legally possible, and contract termination when vendors facilitate abuse.
The objective is not to publish rumors about mysterious phone behavior. It is to document who purchased the capability, who approved its use, who was targeted, what was collected, and whether anyone bothered to supervise the people holding the digital skeleton key.
Closing RK Thoughts
Private spyware allows public agencies to purchase extraordinary surveillance power from companies that frequently operate behind confidentiality clauses, subsidiaries, resellers, and aggressively redacted contracts.
That secrecy is precisely why investigators must combine procurement records, legal authorities, forensic findings, internal policies, audit logs, and testimony from affected people. No single document will reveal the entire system.
Resistance Kitty does not assume every strange notification is a spy agency. She simply believes that when the government buys software capable of entering a journalist’s phone, “trust us” is not a privacy policy.
Follow the money. Preserve the evidence. Protect the targets. Make the government explain who received the password to democracy’s group chat.
Sources
- Executive Order 14093 on Commercial Spyware
- 404 Media Investigation of the ICE Paragon Contract
- 404 Media Report on Redacted ICE Spyware Records
- Citizen Lab Spyware Litigation Tracker
- Citizen Lab Investigation of Pegasus Targeting a European Parliament Member
- Citizen Lab Investigation of Journalists Targeted With Pegasus
- Citizen Lab Investigation of Cellebrite Use Against Jordanian Civil Society
- Amnesty International Security Lab Tools and Guides
- Amnesty International Investigation of Spyware Used Against Serbian Journalists and Activists
- Access Now Digital Security Helpline
- United States Commercial Spyware Visa Restriction Policy
- CISA Guidance on Tracking Technologies and Spyware
