US Immigration and Customs Enforcement Purchases Spyware Capable of Taking Over Phones, Senator Demands Disclosure of Surveillance Targets
United States Senator Gary Peters is demanding that U.S. Immigration and Customs Enforcement (ICE) disclose all information regarding the procurement and use of commercial spyware capable of infiltrating mobile phones without the owner’s knowledge. In a letter dated Thursday (23/7/2026), Peters questioned a direct appointment contract worth 2 million US dollars for Graphite technology developed by spyware company Paragon Solutions. The letter was addressed to Acting ICE Director David Venturella, rather than directly to Homeland Security Secretary Markwayne Mullin. Peters, a Democratic politician and senior member of the minority in the Senate Homeland Security and Governmental Affairs Committee, described the procurement as one of the most significant expansions of surveillance capabilities for ICE and the U.S. Department of Homeland Security (DHS). “Graphite is an extremely powerful and invasive cyber tool,” Peters wrote, as reported by American media. According to him, the device can silently breach phones, extracting messages, photos, files, location data, and other stored information, while also activating the microphone and camera without the device owner’s knowledge. Such capabilities distinguish Graphite from standard phone extraction devices that require officers to first hold or seize the device. Commercial spyware can exploit security vulnerabilities and access data directly from targeted phones, including conversations on encrypted applications. The Citizen Lab at the University of Toronto previously found forensic evidence that Graphite uses a zero-click attack via iMessage. In this type of attack, the victim does not need to click a link, open an attachment, or take any action for their device to be compromised. Apple stated that the vulnerability found in that case has been patched since the iOS 18.3.1 update. Peters is demanding ICE explain whether Graphite has ever been used within the United States, how many U.S. citizens and foreign nationals have been targeted, their locations when targeted, and the reasons for using the spyware in each case. He is also demanding an explanation of the legal basis used by ICE to operate the technology. Peters is asking ICE to reveal whether data obtained through Graphite has been shared with other units within ICE, government agencies, private companies, non-profit organisations, or systems outside the United States. Peters’ questions also touch on supply chain security. He is asking ICE to explain whether every Graphite system and software update is independently inspected to prevent infiltration, code manipulation, or hidden access by foreign parties.