TL;DR: Leaked documents reveal Intellexa, the sanctioned spyware company behind Predator, had remote access to its government customers' surveillance systems. Staff could view stolen photos, messages, and data from hacked phones. The company also developed a zero-click attack called "Aladdin" that infects targets through malicious ads. Despite US sanctions in March 2024, Intellexa continues operating in Saudi Arabia, Kazakhstan, Angola, and Mongolia.

What changed (August 27, 2026): On February 26, 2026, an Athens misdemeanour court found Tal Dilian and three co-defendants guilty of illegally wiretapping 87 Greek victims, including ministers, military officials, and journalists. Each received an eight-year prison sentence, suspended pending appeal. The court agreed to share trial records to support potential further prosecutions, including possible espionage charges. Citizen Lab's John Scott-Railton called it "the first time that an executive at a mercenary spy company has been convicted and sentenced to prison."

What changed (September 14, 2026): Eight Greek Predator victims filed a civil lawsuit against Intellexa and 13 individuals on July 7-8, 2026, seeking approximately €7.6 million (about $8.7 million) in damages. The trial is scheduled for April 2027. Separately, the Committee to Protect Journalists published a special report on August 27, 2026 documenting how ad-delivered surveillance (the same Aladdin attack chain described above) is being used against journalists in Belgium, Germany, Egypt, Hungary, and El Salvador.

They Sold Spyware, Then Watched the Spying

When governments buy surveillance tools, they expect one thing: privacy. The target's data stays with the government. The vendor doesn't get to peek.

Intellexa broke that rule.

On December 4, 2025, Amnesty International published findings from leaked internal documents, sales materials, and training videos. The investigation, conducted with Haaretz, Inside Story, and Inside IT, exposed something the spyware industry claims never happens: vendor access to victim data.

Intellexa staff allegedly used TeamViewer (an off-the-shelf remote access tool) to connect directly to government customers' surveillance systems. Once connected, they could see everything: photos, messages, location data. All the intimate details stolen from hacked phones.

"These findings can only add to the concerns of potential surveillance victims," Amnesty stated. "Not only is their most sensitive data exposed to a government or other spyware customer, but their data risks being exposed to a foreign surveillance company."

The Training Video That Showed Too Much

One leaked video revealed a live demonstration of Predator infections against real targets. Not simulations. Real people.

The video showed detailed information from a Kazakhstan-based target: their IP address, the infection URL used to compromise their phone, and the software versions running on their device. This wasn't a controlled lab environment. Intellexa trainers were showing customers how to hack real humans.

A Memento Labs CEO, speaking to researchers, confirmed this level of access violates industry norms: "No [government] agency would accept it." Even NSO Group, maker of the infamous Pegasus spyware, claims it never accesses customer data.

Intellexa apparently didn't get that memo.

Aladdin: The Zero-Click Ad Attack

The leaks also revealed a new infection vector called "Aladdin." Here's how it works: Intellexa customers push malicious advertisements through ad networks. When a target views the ad (just views it, no clicking required) their phone gets compromised.

Zero-click. Zero interaction. You see an ad, you're hacked.

Google's Threat Intelligence Group noted that Intellexa has "solidified its position as one of, if not the most, prolific spyware vendors exploiting zero-day vulnerabilities against mobile browsers." The company burns through expensive zero-day exploits to keep Predator running, constantly finding new holes in iOS and Android.

In summer 2025, Amnesty's Security Lab documented an attack against a human rights lawyer in Pakistan's Balochistan province. The attack came through WhatsApp. Google sent spyware threat notifications to "several hundred accounts across various countries, including Pakistan, Kazakhstan, Angola, Egypt, Uzbekistan, Saudi Arabia and Tajikistan."

Sanctioned But Still Operating

In March 2024, the US Treasury sanctioned Intellexa founder Tal Dilian and his business partner Sara Aleksandra Fayssal Hamou. It marked the first time the US targeted a specific individual in the commercial spyware industry.

The sanctions cited misuse against Americans, including government officials and journalists.

Didn't matter. Researchers found evidence of Intellexa customers currently operating in Saudi Arabia, Kazakhstan, Angola, and Mongolia. Three former Intellexa executives are on trial in Greece, where dozens of Predator victims are located.

Dilian's lawyer issued a written response denying any crimes. Dilian himself called the journalists behind the investigation "useful idiots" in an orchestrated campaign against him. One source described Dilian as moving "like an elephant in a crystal shop" when it comes to discretion.

The elephant keeps stomping.

What You Can Do

If You're a Potential Target

Journalists, lawyers, activists, and dissidents are primary targets. Use Amnesty's Mobile Verification Toolkit to check your device for spyware indicators. Enable Lockdown Mode on iOS. Keep devices updated. Though Intellexa burns zero-days, patches eventually catch up.

Limit Your Attack Surface

The Aladdin attack uses ad networks. Use aggressive ad blockers. Avoid clicking suspicious links, but remember: zero-click attacks don't require interaction. Consider using a separate device for sensitive communications. Don't trust any single device completely.

Support Accountability Efforts

Organizations like Citizen Lab, Amnesty Tech, and EFF investigate spyware abuses. Their research led to these leaks and the US sanctions. Support their work. The more exposure, the harder it gets for these companies to operate.

The Mercenary Spyware Industry Won't Police Itself

Intellexa isn't unique. It's just the one that got caught with its hands in the cookie jar. The commercial spyware industry sells surveillance tools to governments with poor human rights records, then claims ignorance when those tools get used against journalists and activists.

The Intellexa leaks prove something worse: the vendors themselves may be watching. When you buy spyware, you might be sharing your victims with the company that sold it to you.

That's not a bug. That's leverage.

Update (August 27, 2026): First-ever spyware executive convictions in Athens

On February 26, 2026, an Athens misdemeanour court found four business executives linked to Intellexa guilty of "breaching the confidentiality of telephone communications" and illegally accessing information systems. The convicted defendants are Tal Dilian, founder of Intellexa and former commander of an elite Israeli intelligence unit; Sara Hamou, Dilian's ex-wife and the corporate offshoring specialist who helped establish Intellexa's Cyprus base; Felix Bitzios, an Intellexa executive; and Yiannis Lavranos, owner of the Greek security firm that purchased Intellexa's Predator spyware. Each was sentenced to eight years in prison, suspended pending appeal. Dilian announced on February 27, 2026 that he would appeal and called the verdict "fundamentally irreconcilable with the evidentiary record." Reuters reported on March 24, 2026 that he was still pursuing the appeal.

The "Predatorgate" case stems from a 2022 scandal in which Intellexa's Predator spyware targeted 87 confirmed victims. The list includes the current leader of Greece's main opposition party, a journalist covering Greek banking corruption, and the editor of a top newspaper. Greece's intelligence chief and a senior aide to the prime minister resigned during the original fallout. Dilian, Hamou, and Bitzios had been sanctioned by the US government in March and September 2024 (Dilian and Hamou specifically, on March 5, 2024); the Treasury lifted sanctions on Hamou in late 2025.

The court agreed to share trial records with judicial authorities to investigate potential additional offenses, including possible espionage charges. The Organized Crime and Corruption Reporting Project (OCCRP) reported the court also ordered further prosecutions. Predator remains in active use despite the sanctions and now the conviction: it was used in May 2024 to hack Angolan journalist Teixeira Cândido's phone, in summer 2025 against a human rights lawyer in Pakistan, and customers have included Sudan's Rapid Support Forces, Egyptian intelligence services, and the Vietnamese government.

Citizen Lab senior researcher John Scott-Railton called the verdict "the first time that an executive at a mercenary spy company has been convicted and sentenced to prison." Cândido, the hacked Angolan journalist, told ICIJ: "It feels like you're walking naked and being watched." Amnesty International framed the convictions as "a path towards accountability" and said the verdict matters because it treats the vendors themselves as culpable, not just the governments who pull the trigger. The Intellexa leaks documented above are now the evidentiary spine of a court record rather than only a press investigation.

Sources for this update: ICIJ. "Greek court convicts Intellexa founder Tal Dilian, three others in wiretapping scandal." February 26, 2026; Balkan Insight. "Greek Court Finds Four Executives Guilty in Predator Spyware Case." February 26, 2026; Reuters. "Intellexa founder says he plans to appeal Greek court ruling over wiretapping." March 24, 2026; Human Rights Watch. "Greek Court Finds Spyware Executives Guilty." March 2, 2026; OCCRP. "Greek Court Hands Down Maximum Sentences in 'Predator' Spyware Case, Orders More Prosecutions." February 2026; Amnesty International. "Greece 'Predatorgate' convictions is a path towards accountability." February 26, 2026.

Update (September 14, 2026): Greek victims sue Intellexa for €7.6M; CPJ maps ad-delivered surveillance

Five months after the Athens convictions, eight Greek Predator victims filed a civil lawsuit against Intellexa SA and 13 individuals tied to the company on July 7, 2026. The plaintiffs are seeking approximately €7.6 million ($8.7 million) in damages for what their attorney Zacharias Kesses described as "the moral damage suffered by the victims from the illegal violation of their privacy, the confidentiality of their communications and their personal data." Kesses called the lawsuit "the next institutional step towards full accountability of all those involved and redress for victims, both at national and European level." Civil trial is scheduled to start in April 2027.

The plaintiffs include financial journalist Thanasis Koukakis (whose phone Citizen Lab first confirmed was infected in late 2021), former Meta trust and safety manager Artemis Seaford, journalist Spyridon Sideris, two lawyers, a former director of the Hellenic Police's Forensic Laboratories, and a former head of a Greek intelligence agency. Dilian's defense is that Intellexa sold Predator only to government customers, including the Greek government and its national intelligence agency, and that the vendor plays no role in selecting targets. He has accused the Greek government and intelligence agency of a "conspiratorial criminal act" to hide their own wrongdoing. Dilian and his three co-defendants remain free while the criminal appeal is pending, and the new civil case will now run in parallel. Reported by The Record (Recorded Future News). "Greek victims file lawsuit against Intellexa over Predator spyware." July 8, 2026.

Separately, the Committee to Protect Journalists published a special report on August 27, 2026, by technology and human rights fellow Jonathan Rozen, titled "How mass surveillance from online advertising puts journalists at risk." The report maps six interconnected systems: software development kits (SDKs), real-time bidding (RTB) auctions, big-tech data brokers, advertising intelligence (ADINT) companies, and firms developing ad-delivered spyware, including Intellexa's Aladdin product. CPJ confirms that Aladdin uses JavaScript embedded in ads that, when opened, redirects the device to attacker-controlled infrastructure. Reporters Omer Benjakob and Jurre van Bergen told CPJ that confirmed cases of infection via this method had not yet been publicly reported.

The report profiles exiled Egyptian journalist Basma Mostafa in Berlin (whose "pattern of life" appeared in a free commercial data broker sample and was reported in Germany in April 2026), Hungarian investigative reporter Szabolcs Panyi (whose location data the report says was acquired by intelligence services using Pen Link's Webloc tool), and El Faro journalists in El Salvador (targeted by police using the same Webloc tool). CPJ also profiles Belgian journalist Nicolas Baudoux of L'Echo, German netzpolitik.org reporter Ingo Dachwitz, and former White House correspondent Byron Tau's account of an attempted tracking of a reporter who obtained embarrassing information about President Trump during his first term. The report extends the picture drawn above: the Aladdin attack chain the Intellexa leaks documented in December 2025 is now confirmed as a live operational pipeline against journalists in at least five countries.

Sources for this update: The Record. "Greek victims file lawsuit against Intellexa over Predator spyware." July 8, 2026; Reuters. "Greek wiretapping victims sue spyware firm Intellexa for damages." July 7, 2026; Committee to Protect Journalists. "How mass surveillance from online advertising puts journalists at risk." August 27, 2026; Harvard Kennedy School Carr-Ryan Center. "How mass surveillance from online advertising puts journalists at risk." August 27, 2026.

References

  1. TechCrunch - Sanctioned spyware maker Intellexa had direct access to government espionage victims (December 4, 2025)
  2. Amnesty International - "Intellexa Leaks" investigation provides further evidence of spyware threats to human rights (December 2025)
  3. Amnesty Security Lab - To Catch a Predator: Leak exposes internal operations of Intellexa's mercenary spyware (December 2025)
  4. The Hacker News - Intellexa Leaks Reveal Zero-Days and Ads-Based Vector for Predator Spyware Delivery (December 2025)
  5. Google Cloud Blog - Intellexa's Prolific Zero-Day Exploits Continue (December 2025)
  6. CyberScoop - Intellexa remotely accessed Predator spyware customer systems (December 2025)