Part II · Chapter 16
The Mercenary Market and the Forensic Answer
The same surveillance capability sells at every price point — millions of dollars aimed at a journalist, thirty dollars a month aimed at a wife — and it is the first of the surveillance layers built to leave traces.
Lay a state intelligence operation and a jealous partner’s phone app side by side, and the capability diagram is identical: read everything the target writes, see everywhere they go, listen without their knowledge, and remain invisible while doing it. The commercial market that supplies that capability sells it at every price point at once.
At the top of that market sits Pegasus, developed by the Israeli firm NSO Group and documented by Citizen Lab and Amnesty International’s Security Lab.1 It is zero-click spyware, requiring no link to open and no user error. It grants whoever deploys it access to every message across WhatsApp, Signal, Telegram, and iMessage; real-time location; silent camera and microphone activation; a target’s full photo library, browsing history, and contact network; and every keystroke typed, including messages composed and deleted before ever being sent. NSO markets it against crime and terrorism; the documented targets tell a different story: at least a hundred eighty journalists across twenty countries were selected for potential targeting between 2016 and 2021, per the Pegasus Project’s investigation across seventeen media organizations;2 Jamal Khashoggi’s own inner circle was infected months before his murder, including his wife’s phone while she was detained by UAE authorities;3 the Emirati activist Ahmed Mansoor became, in 2016, the case that first exposed the tool’s iPhone zero-days to researchers, who called it “The Million Dollar Dissident”;4 a Moroccan human-rights lawyer was repeatedly sent malicious links designed to install the software while he defended protesters;5 and at least twenty-five Mexican journalists were selected for targeting over a two-year span, including Cecilio Pineda, whose phone was selected for targeting weeks before he was killed in 2017.6 NSO’s defense — that it sells only to governments, only for law enforcement, and bears no responsibility for how customers use the product — sits uneasily against a roster of journalists, human-rights lawyers, and dissidents rather than the criminals and terrorists the license supposedly requires.
Pegasus is not alone, and the wider roster shows how routine this capability has become. Germany and the UK’s Gamma Group sold FinFisher spyware that surfaced in emails targeting Bahraini activists during the 2011 Arab Spring crackdown, and a contract for the tool, worth roughly two hundred eighty-seven thousand euros, was found by dissidents who searched Egypt’s secret police offices after Mubarak’s fall that same year.7 North Macedonia’s Cytrox produced Predator, zero-click spyware exposed by Citizen Lab and Meta in late 2021, documented in use against an Egyptian opposition politician, an exiled journalist, a sitting member of the European Parliament, and a Greek financial journalist — part of a wider 2022 Greek spyware scandal that ultimately touched more than ninety phones.8 Paragon’s Graphite spyware, contracted to the Italian government, was confirmed by Citizen Lab’s forensic analysis to have targeted journalists; Italy’s own government admitted in June 2025 to using the tool against at least two journalists and two co-founders of a migration-rescue organization, under a migration-control justification, and as of 2026, per press reporting, Paragon had not cooperated with the resulting Italian prosecutorial investigation despite canceling its Italian contracts.9 The pattern across these vendors is consistent: tools costing anywhere from a hundred thousand to several million dollars per target, sold by private contractors rather than governments themselves specifically to manufacture deniability, in a regulatory vacuum where no international law prohibits the sale, and documented, repeatedly, in use against exactly the people the marketing material says the tool is not for.
At the opposite end of the price scale sits consumer stalkerware — mSpy, FlexiSPY, SpyBubble, and similar products, running fifteen to two hundred dollars a month, offering location tracking, message interception, call recording, and browsing history to anyone willing to gain five minutes of physical access to a target’s phone.10 They are advertised openly (on ordinary websites, YouTube, Reddit) under the same euphemisms that give them legal cover, “parental monitoring,” “employee monitoring,” normalized by the language this book has already examined: it’s just to keep them safe. A Kaspersky survey of more than twenty-one thousand people across twenty-one countries, in September 2021, found that thirty percent saw no problem secretly monitoring a partner.11 Scoping reviews of the technology-facilitated-abuse literature put the share of intimate-partner-violence cases involving some form of this technology at twelve to thirty percent, disproportionately deployed against women, and associated with mental-health outcomes (anxiety, depression, complex trauma) measurably more severe than abuse without a technological component.12 The market is no cottage industry: estimates put stalkerware revenue at five hundred million to a billion dollars annually, at very high margins, because development cost is minimal and scaling nearly free.13
Neither market ever required its target to become suspicious — of the phone in her hand, or of the person who put it there.
Alongside surveillance sits a related, newer mechanism: media that is not surveillance at all, but fabrication. A 2019 landscape study by the research group Sensity found that ninety-six percent of the deepfake video then circulating online was pornographic, and ninety percent of that targeted women, mostly public figures, with the four leading deepfake-pornography sites accumulating more than a hundred thirty-four million views targeting hundreds of named women.14 This is not a marginal side-use of synthetic media. It is, by the only real landscape data available, the technology’s primary documented application — and its coercive uses extend directly from that base: a threat to release fabricated intimate images functions as leverage in exactly the way a real image would; a fabricated video of a target “confessing” to something she never said or did functions as narrative reversal with fabricated evidence attached; and the psychological harm of simply knowing such material could exist, whether or not it ever surfaces, produces a chilling effect on its own. The United States addressed the most acute version of this in May 2025, when the TAKE IT DOWN Act became federal law, requiring platforms to remove non-consensual intimate imagery — expressly including AI-generated deepfakes — within forty-eight hours of a victim’s request, backed by FTC enforcement and criminal penalties running up to two years.15 A companion bill, the DEFIANCE Act, would create a federal civil remedy letting victims sue creators of non-consensual sexual deepfakes directly; it passed the Senate in 2024 but had not become law as of 2026, pending rather than settled law.16 The forensic problem underneath both efforts is a timing asymmetry: the harm from a released fabrication is immediate, while proving the fabrication and getting it removed takes time platforms have historically been slow to supply.
A related mechanism operates at even larger scale, requiring no single target at all: coordinated networks of fake or compromised accounts, deployed to manufacture the appearance of organic consensus. The Senate Select Committee on Intelligence’s bipartisan 2019 report on Russia’s use of social media found that the Internet Research Agency’s activity across Facebook, Instagram, Twitter, and YouTube disproportionately targeted Black Americans more than any other group, and — tellingly — increased rather than decreased after Election Day. That timing suggests the goal was sustained polarization and eroded institutional trust rather than any single electoral outcome.17 Research by King, Pan, and Roberts at Harvard, analyzing leaked internal emails from a single Chinese county’s propaganda department, estimated that the Chinese government fabricates roughly four hundred forty-eight million social-media posts a year. The great majority are written not by paid contractors, contrary to the popular “fifty cents per post” myth, but by ordinary government employees as an addition to their regular duties, in coordinated bursts timed to distract from unfolding crises rather than to argue with critics.18 Both programs perform the same function at individual scale: manufacture apparent consensus, isolate a target inside an apparent majority, and produce a chilling effect that silences dissent without anyone needing to silence any single voice.
It would be a mistake to file synthetic media as a new entry in the grammar this book has been mapping. It is not a new move; it is the oldest move here — manufacturing a believable account — with its cost, its skill floor, and its production time collapsed toward zero. The keystone named in the introduction, deciding the story in advance and then building the evidence to fit it, once required either resources or craft: a forged document, a staged photograph, a witness willing to lie. Synthetic media removes that constraint. In March 2019, criminals used a cloned voice of a German parent company’s chief executive to convince the head of its UK subsidiary to wire two hundred twenty thousand euros to a fraudulent account, in what is widely cited as the first reported case of AI voice-mimicry used for fraud.19 Five years later the technique had scaled from a phone call to an entire boardroom: in January 2024 a finance employee at the engineering firm Arup, in Hong Kong, made fifteen transfers totaling roughly twenty-five million US dollars after joining a video conference on which the chief financial officer and every colleague he recognized were AI-generated deepfakes.20 His initial, correct suspicion of a phishing email was overridden by the evidence of his own eyes and ears — precisely the faculty synthetic media is built to turn against its target.
The reading this book draws from the two cases is offered as synthesis, not documented fact: what AI changes is not the mechanism but the economics of the mechanism, and the specific casualty is the category of media a person used to be able to treat as self-authenticating. A familiar voice on the phone, a recognized face on a call, once carried their own proof; they no longer do. That loss cuts in an unexpected direction. It raises the value of the exact counter-discipline the rest of this book keeps arriving at — the contemporaneous, independently corroborated, provenance-bearing record — because that is the one form of evidence a fabrication assembled after the fact cannot retroactively manufacture. As synthetic media makes the artifact less trustworthy, it makes the timeline matter more, not less: when a record was made, and whether it can be shown to predate the thing it documents, becomes the question no forgery can answer for itself.
What makes this layer different from the mechanisms examined earlier is that it is, for once, built specifically to leave traces. Amnesty International’s Mobile Verification Toolkit, released alongside the 2021 Pegasus Project as an open-source tool, examines a device’s system files, app cache, and network logs for the specific indicators known spyware campaigns leave behind, with a caveat in its own documentation: a clean scan does not prove a device was never targeted, only that no known indicator was found.21 Broader digital forensics extends the same principle: full-disk imaging capable of recovering files a perpetrator believed deleted. None of this makes detection easy, and a well-resourced state actor’s tools remain considerably harder to catch than consumer stalkerware. But it offers what none of the interpersonal chapters could as cleanly: a perpetrator who believes himself invisible is not, to a sufficiently rigorous examination of the device itself. It has to be conceded plainly, though: reconstructing the operation and sending the device to a forensic lab presumes an expertise and a budget most ordinary victims do not have — the forensic answer is real, but access to it is itself gated by money, and the victim’s side of the reconstruction starts already behind. The method and its undoing are the same skill read from two directions — the tradecraft that plants the spyware and the forensics that recovers it working on the identical file.
Notes
NSO Group’s Pegasus spyware — documented by The Citizen Lab and Amnesty International’s Security Lab. Amnesty International, “The Pegasus Project,” July 2021, https://www.amnesty.org/en/latest/press-release/2021/07/the-pegasus-project/↑
At least 180 journalists across 20 countries selected as potential Pegasus targets between 2016 and June 2021, per the Pegasus Project investigation (Forbidden Stories + 80 journalists at 17 media organizations, working with Amnesty International’s Security Lab). https://www.amnesty.org/en/latest/press-release/2021/07/the-pegasus-project/↑
Citizen Lab forensic analysis found Pegasus on the phone of Omar Abdulaziz, a close confidant of Jamal Khashoggi, months before Khashoggi’s murder, and (per Washington Post forensics) on the phone of his wife Hanan Elatr while she was detained by UAE authorities in April 2018. Citizen Lab, December 2021, https://citizenlab.ca/2021/12/the-washington-post-a-uae-agency-put-pegasus-spyware-on-phone-of-jamal-khashoggis-wife-months-before-his-murder-new-forensics-show/↑
UAE activist Ahmed Mansoor’s 2016 case exposed iPhone zero-days to Citizen Lab researchers, who dubbed it “The Million Dollar Dissident.” https://citizenlab.ca/research/million-dollar-dissident-iphone-zero-day-nso-group-uae/↑
Moroccan human-rights lawyer Abdessadak El Bouchattaoui was repeatedly sent malicious links/redirects designed to install Pegasus while representing defendants from the 2017 Hirak Rif protests. https://cyberscoop.com/morocco-spyware-nso-group-pegasus/↑
At least 25 Mexican journalists were selected for Pegasus targeting over a two-year period, including Cecilio Pineda, whose phone was selected for targeting weeks before his 2017 killing — Pegasus Project investigation.↑
FinFisher/FinSpy (Gamma Group, Germany/UK) code was found embedded in emails sent to Bahraini activists during the 2011 Arab Spring crackdown (analysis by University of Toronto/Citizen Lab researchers); a €287,000 FinFisher/Gamma International contract was found by dissidents who searched Egypt’s secret police offices after Mubarak’s 2011 overthrow. University of Toronto Citizen Lab research (Marquis-Boire et al., 2012); https://wikileaks.org/spyfiles4/↑
Cytrox’s Predator spyware, zero-click Android/iOS spyware, was exposed by Citizen Lab and Meta in late 2021, documented in use against Egyptian opposition politician Ayman Nour, an exiled journalist, EU lawmaker Nikos Androulakis, and a Greek financial journalist — part of the wider 2022 Greek spyware scandal affecting 92+ phones. https://citizenlab.ca/research/pegasus-vs-predator-dissidents-doubly-infected-iphone-reveals-cytrox-mercenary-spyware/; https://balkaninsight.com/2022/08/23/how-many-greek-spyware-scandal-just-getting-started-says-targeted-reporter/↑
Citizen Lab’s first forensic confirmation of Paragon’s Graphite spyware found journalists among the targets; Italy’s government confirmed in June 2025 it used Graphite against journalists Francesco Cancellato and Ciro Pellegrino and Mediterranea Saving Humans co-founders Luca Casarini and Giuseppe Caccia, under a migration-control justification. As of 2026, Paragon has not cooperated with the Italian prosecutors’ investigation despite canceling its Italian government contracts. https://citizenlab.ca/research/first-forensic-confirmation-of-paragons-ios-mercenary-spyware-finds-journalists-targeted/; https://www.amnesty.org/en/latest/news/2025/06/italy-new-case-of-journalist-targeted-with-graphite-spyware-confirms-widespread-use-of-unlawful-surveillance/; https://techcrunch.com/2026/04/28/paragon-is-not-collaborating-with-italian-authorities-probing-spyware-attacks-report-says/↑
Consumer stalkerware products mSpy ($30–70/mo), FlexiSPY ($100–200/mo), and SpyBubble ($15–50/mo), and their advertised feature sets (location, messages, calls, browsing, and, for FlexiSPY, mic activation and call recording), from the vendors’ own advertised pricing and feature listings.↑
Kaspersky/Sapio Research global survey of 21,000+ participants across 21 countries, September 2021: 30% said they see no problem secretly monitoring a partner. https://www.kaspersky.com/about/press-releases/30-of-people-see-no-problem-in-secretly-monitoring-their-partner-finds-new-research-on-stalkerware↑
Rogers, M., Fisher, C., Ali, P., Allmark, P., & Fontes, L., “Technology-Facilitated Abuse in Intimate Relationships: A Scoping Review,” Trauma, Violence, & Abuse (2023); Cuomo, D. & Dolci, N., “New tools, old abuse: Technology-enabled coercive control (TECC),” Geoforum 126 (2021): 224–232 — scoping-review literature estimating 12–30% of intimate-partner-violence cases involve technology-facilitated abuse, disproportionately against women, with more severe mental-health outcomes.↑
Estimated stalkerware market size of $500M–$1B annually, an aggregate industry estimate not attributable to a single named study.↑
Sensity (formerly Deeptrace), 2019 landscape study of online deepfakes: 96% were pornographic, nearly all of them targeting women (many of them public figures), and the top four dedicated deepfake-porn sites had together accumulated more than 134 million views. https://www.siliconrepublic.com/enterprise/deepfakes-non-consensual-porn-research-deeptrace↑
TAKE IT DOWN Act, signed into US federal law May 19, 2025 — requires platforms to remove non-consensual intimate imagery (including AI-generated deepfakes) within 48 hours of a victim’s request, backed by FTC enforcement and criminal penalties up to two years. TAKE IT DOWN Act, signed into US federal law on May 19, 2025 (public law).↑
DEFIANCE Act — passed the Senate in 2024 but stalled in the House and had not become law as of 2026; would create a federal civil remedy allowing victims to sue creators of non-consensual sexual deepfakes. https://www.durbin.senate.gov/imo/media/doc/DEFIANCE%20Act%20one%20pager%20051324.pdf↑
Senate Select Committee on Intelligence, bipartisan report “Russia’s Use of Social Media” (2019): Internet Research Agency activity across Facebook, Instagram, Twitter, and YouTube disproportionately targeted Black Americans, and activity increased after Election Day (Instagram +238%, YouTube +84%, Facebook +59%, Twitter +52%). https://www.intelligence.senate.gov/2019/10/08/press-senate-intel-committee-releases-bipartisan-report-russia-e2-80-99s-use-social-media/↑
King, G., Pan, J., & Roberts, M.E., analysis of a leaked 2014 email cache from a single Chinese county’s propaganda department, estimating the Chinese government fabricates roughly 448 million social-media posts per year, mostly by ordinary government employees rather than paid contractors, posted in bursts timed to distract from crises. https://gking.harvard.edu/50c/↑
In March 2019, criminals used AI-based voice-cloning software to impersonate the chief executive of a German parent company and convinced the head of its UK energy-firm subsidiary to transfer €220,000 (about $243,000) to a fraudulent account; it is widely cited as the first reported case of AI voice-mimicry used for fraud. Catherine Stupp, “Fraudsters Used AI to Mimic CEO’s Voice in Unusual Cybercrime Case,” Wall Street Journal, August 30, 2019; summarized at https://www.trendmicro.com/vinfo/us/security/news/cyber-attacks/unusual-ceo-fraud-via-deepfake-audio-steals-us-243-000-from-u-k-company.↑
A finance employee at the engineering firm Arup’s Hong Kong office made fifteen transfers totaling roughly HK$200 million (about US$25 million) to five bank accounts in January 2024 after joining a video call on which the company’s UK-based chief financial officer and other colleagues were all AI-generated deepfakes; Hong Kong police disclosed the case in February 2024, and Arup confirmed it was the victim in May 2024. Heather Chen and Kathleen Magramo, “Finance worker pays out $25 million after video call with deepfake ‘chief financial officer,’” CNN, May 16, 2024, https://www.cnn.com/2024/05/16/tech/arup-deepfake-scam-loss-hong-kong-intl-hnk.↑
Amnesty International’s Mobile Verification Toolkit (MVT), released alongside the 2021 Pegasus Project as an open-source tool, examines a device’s system files, app cache, and network logs for known spyware indicators, with the caveat that a clean scan does not prove a device was never targeted. https://securitylab.amnesty.org/get-help/; https://mvt-docs.readthedocs.io/↑
From The Machinery of Compliance by Willow Whitman · edition 1.0.2, · free under CC BY-NC-ND 4.0 · corrections