Active Incident? 24/7 Response →
SleuthX

For Journalists

Your Phone Was Hacked? Get a Forensic Answer.

Suspected mercenary spyware or a targeted intrusion is a forensic question, not a symptom checklist. We confirm or rule out compromise against published indicators, preserve the evidence, and document it to a standard that holds up.

By Quinn Varcoe, Founder & CEO, SleuthX

Suspicion is not confirmation — and a wipe destroys the answer

If you have a credible reason to think your device was targeted, two things matter immediately: do not act on folk symptoms alone, and do not wipe or reset the device.

Battery drain and overheating are weak signals with a hundred ordinary causes.

A threat notification from Apple or a platform like WhatsApp, or a specific reason to believe you are targeted because of your reporting, is a reason to get a forensic examination.

The fastest way to lose the answer is to factory-reset the phone, which destroys the very artifacts an examination relies on.

Preserve, do not wipe

Forensic value lives in the device’s current state.

The first move is preservation: stop changing the device and let it be imaged, with the evidence hash-verified at the moment of capture and a documented chain of custody, with collection aligned to ISO/IEC 27037.

Imaging first is what makes every later conclusion defensible — in an insurance claim, a police report, or court.

If the device poses an active risk, there are containment steps that do not destroy evidence; ask us before you take action.

How forensic confirmation works

Once the device is preserved, the examination follows a documented method:

The honest boundary, which MVT’s own authors state, is that the absence of indicators is not proof a device is clean.

Our finding is “indicators of compromise found” or “no known indicators of compromise found” — never a guarantee.

The 2025 confirmation of Paragon’s Graphite spyware on journalists’ devices, reported by Citizen Lab, is a reminder that this is a live, evolving threat and that careful method matters.

Honest attribution, and where it ends

A forensic examination can frequently establish that a device shows indicators consistent with a known spyware family — and that is often the finding that matters most.

Naming the operator behind the attack is far harder and is often not possible from the device alone.

Even Citizen Lab and Amnesty’s Security Lab, who do this at the highest level, are careful about attribution.

We apply their published, peer-reviewed methods; we are not them, and we do not claim to be.

We will tell you exactly what the evidence supports and where it stops, and we do not guarantee attribution.

When a guide hands you to a professional

The free resources say it themselves: self-help has a ceiling.

The nonprofit guides that cover suspected spyware route readers past that ceiling to a professional examination when they are not eligible for a lab’s own casework or the situation needs more than a checklist.

Reporters Without Borders’ Digital Security Lab is explicit about the boundary of what a free lab provides — it “cannot offer incident response” (rsf.org, as of July 2026).

None of those organizations endorses or refers cases to any private practice, including ours.

What follows is simply what the professional engagement looks like when you arrange one.

A professional forensic spyware examination— the engagement we run in our own casework — is consensual and scoped in writing: your device, your authorization, a documented chain of custody from acquisition onward.

The examination is MVT-aware — the same open toolkit and published indicator sets the guides reference — correlated with artifacts a self-check cannot reach.

The output is written findings in plain language, prepared to support admissibility and, where a matter heads to litigation, prepared to testify about.

For a small newsroom without an in-house security team, the examination is usually one piece of newsroom incident response:

Large outlets keep that capability on staff; most local and independent newsrooms cannot, and the free labs do not fill that gap.

That is the work this page describes.

Incident response and what comes after

Confirmation is the start of a response, not the end.

Depending on the finding, the work includes containing further exposure, re-securing accounts the device could reach, and documenting the incident for your editor, your insurer, or law enforcement.

Where a matter heads toward litigation, we provide cybersecurity expert-witness support on the methodology and findings.

What working with us means

Related guides

To harden a device before anything goes wrong, see digital security for journalists.

To protect a source or intake channel, see protecting journalistic sources.

The overview is on the For Journalists hub.

Plain terms

What we are — and what we are not

What we are

A digital forensics practice with an AI agent at the center. Credentialed examiners, documented chain of custody, explainable findings you can verify, and court-admissible reports under FRE 901/902. When field work is needed — backgrounds, locates, physical surveillance — we coordinate with licensed private investigators. Lawful, confidential, on your side.

What we are not

Spyware, stalkerware, or a way to secretly monitor another person. We do not “hack back,” promise guaranteed money recovery, or touch any account or device without its owner's lawful authorization — and we decline engagements that ask us to.

Meet Your Practitioner

Quinnlan Varcoe

Founder & CEO

GIAC-certified · 9 industry certifications

With operational experience across Fortune 50 security programs and the defense industrial base, Quinnlan founded SleuthX in 2022 to provide clients with the caliber of expertise typically reserved for the largest enterprises. Her work in threat intelligence and digital forensics has earned the trust of 26,000+ cybersecurity professionals who follow her analysis.

“26,000 professionals follow my work because I say what others won't — and I can back it up technically.”

Fortune 50 BackgroundDefense IndustryThreat IntelligenceDigital PrivacyIncident Response
Quinnlan Varcoe, Founder & CEO

Certified Expertise

GIAC

Frequently asked about device compromise

How do I know if my phone was actually hacked?
Be skeptical of folk symptoms. Battery drain, heat, and data spikes are weak signals — they have a hundred mundane causes and are not evidence of spyware. The signals that warrant a real examination are different: a threat notification from Apple or a platform like WhatsApp, a credible reason to believe you are targeted because of your reporting, or specific anomalies a forensic look surfaces. The only way to move from suspicion to a defensible answer is a forensic examination, not a symptom checklist.
What does the forensic confirmation actually involve?
At a high level: we make a forensically sound acquisition of the device, then analyze it for indicators of compromise. For mobile spyware, the open standard is the Mobile Verification Toolkit, run against published indicator sets such as Amnesty International's STIX2 IOCs, and correlated with other artifacts on the device. The output is a documented finding of what is and is not present. We are candid about the limit MVT's own authors state: the absence of indicators is not proof a device is clean.
Should I factory-reset or wipe the device first?
No — preserve, do not wipe. A reset destroys exactly the artifacts an examination depends on. If you suspect compromise, the right first move is to preserve: stop changing the device, and let it be imaged first, with the evidence hash-verified at capture and a documented chain of custody (collection aligned to ISO/IEC 27037). If the device is an active danger, talk to us about containment that does not destroy evidence. Capturing the image before anything else is what keeps a later report defensible.
Can you tell me who targeted me?
We can often establish that a device shows indicators consistent with a known spyware family, and that is frequently the finding that matters. Naming the specific operator behind an attack is much harder and often not possible from the device alone — even Citizen Lab and Amnesty, who do this work at the highest level, are careful about attribution. We will tell you what the evidence supports with high confidence and where it stops. We do not guarantee attribution.
Are you Citizen Lab or Amnesty's Security Lab?
No. We are a private forensic practice that applies the same published, peer-reviewed methods those organizations have documented — MVT, the Pegasus forensic methodology, public indicator sets — to your case, with a named, credentialed examiner who can stand behind the work. We cite them as the standard, not as partners or affiliates. Where a matter heads toward litigation, we also provide expert-witness support; see our cybersecurity expert witness work.
Quinnlan Varcoe, Founder & CEO
Quinnlan Varcoe
GIAC-certified · Founder & CEO

Schedule Your Session

Confirm it. Preserve it. Respond.

A direct, confidential conversation with Quinn, the founder and CEO who reviews every case. We coordinate with your media-law counsel and, for litigation, provide expert-witness support. NDA-protected. No sales process.

Free, confidential · NDA-protected · no obligation.

  1. 1. Book a 15-minute call — we scope your situation, no charge.
  2. 2. You get a written scope — deliverables, timeline, and price — before any work begins.
  3. 3. Approve it and we start; most engagements begin within 48 hours.

Transparent pricing

Trusted by partners across the practice

DAS Health
Exhibit A Cyber
Ally Security
KIRO Group
Black Mirage
Kalles Group
Gridware
CQR
Archstone Security
Cyvergence
Sentinel Cyber
Cloud Underground
Seron Security
Hexen
Koru Risk Management
DAS Health
Exhibit A Cyber
Ally Security
KIRO Group
Black Mirage
Kalles Group
Gridware
CQR
Archstone Security
Cyvergence
Sentinel Cyber
Cloud Underground
Seron Security
Hexen
Koru Risk Management