By Quinn Varcoe, Founder & CEO, SleuthX
Suspicion is not confirmation — and a wipe destroys the answer
If you have a credible reason to think your device was targeted, two things matter immediately: do not act on folk symptoms alone, and do not wipe or reset the device.
Battery drain and overheating are weak signals with a hundred ordinary causes.
A threat notification from Apple or a platform like WhatsApp, or a specific reason to believe you are targeted because of your reporting, is a reason to get a forensic examination.
The fastest way to lose the answer is to factory-reset the phone, which destroys the very artifacts an examination relies on.
Preserve, do not wipe
Forensic value lives in the device’s current state.
The first move is preservation: stop changing the device and let it be imaged, with the evidence hash-verified at the moment of capture and a documented chain of custody, with collection aligned to ISO/IEC 27037.
Imaging first is what makes every later conclusion defensible — in an insurance claim, a police report, or court.
If the device poses an active risk, there are containment steps that do not destroy evidence; ask us before you take action.
How forensic confirmation works
Once the device is preserved, the examination follows a documented method:
- Acquisition — a forensically sound copy of the device, hash-verified at capture, the kind of record that can be self-authenticated under Federal Rule of Evidence 902(14).
- Indicator analysis— for mobile spyware, the open standard is the Mobile Verification Toolkit (MVT), run against published indicator sets such as Amnesty International’s Pegasus IOCs.
- Artifact correlation — cross-checking sign-ins, configuration profiles, and other on-device evidence against the indicators.
- Documented findings — a plain-language report of what is and is not present, written to support admissibility.
The honest boundary, which MVT’s own authors state, is that the absence of indicators is not proof a device is clean.
Our finding is “indicators of compromise found” or “no known indicators of compromise found” — never a guarantee.
The 2025 confirmation of Paragon’s Graphite spyware on journalists’ devices, reported by Citizen Lab, is a reminder that this is a live, evolving threat and that careful method matters.
- A direct line to Quinn, the founder — not a sales pipeline.
- Worked in-house by the examiner who scoped it.
- Explainable findings you can verify, with the methodology shown.
Honest attribution, and where it ends
A forensic examination can frequently establish that a device shows indicators consistent with a known spyware family — and that is often the finding that matters most.
Naming the operator behind the attack is far harder and is often not possible from the device alone.
Even Citizen Lab and Amnesty’s Security Lab, who do this at the highest level, are careful about attribution.
We apply their published, peer-reviewed methods; we are not them, and we do not claim to be.
We will tell you exactly what the evidence supports and where it stops, and we do not guarantee attribution.
When a guide hands you to a professional
The free resources say it themselves: self-help has a ceiling.
The nonprofit guides that cover suspected spyware route readers past that ceiling to a professional examination when they are not eligible for a lab’s own casework or the situation needs more than a checklist.
Reporters Without Borders’ Digital Security Lab is explicit about the boundary of what a free lab provides — it “cannot offer incident response” (rsf.org, as of July 2026).
None of those organizations endorses or refers cases to any private practice, including ours.
What follows is simply what the professional engagement looks like when you arrange one.
A professional forensic spyware examination— the engagement we run in our own casework — is consensual and scoped in writing: your device, your authorization, a documented chain of custody from acquisition onward.
The examination is MVT-aware — the same open toolkit and published indicator sets the guides reference — correlated with artifacts a self-check cannot reach.
The output is written findings in plain language, prepared to support admissibility and, where a matter heads to litigation, prepared to testify about.
For a small newsroom without an in-house security team, the examination is usually one piece of newsroom incident response:
- containing further exposure
- re-securing what the device could reach
- and documenting the incident for editors, insurers, or counsel
Large outlets keep that capability on staff; most local and independent newsrooms cannot, and the free labs do not fill that gap.
That is the work this page describes.
Incident response and what comes after
Confirmation is the start of a response, not the end.
Depending on the finding, the work includes containing further exposure, re-securing accounts the device could reach, and documenting the incident for your editor, your insurer, or law enforcement.
Where a matter heads toward litigation, we provide cybersecurity expert-witness support on the methodology and findings.
What working with us means
- Written scope before any work. You see a written scope — deliverables, timeline, and price — and approve it before we begin. You are never billed for work you did not authorize.
- We commit to findings, not outcomes. We tell you up front what the evidence can and cannot establish. Recovery, attribution, and prosecution are decided by banks, platforms, insurers, and courts — we produce the record they act on, and we put that distinction in writing.
- Every case is investigated, not just scanned. A credentialed examiner reviews every case before findings leave the practice. You get a documented investigation to court-admissible standards — not a single automated scan and a one-line answer.
- We will tell you if you do not need us. If a free or simpler step — a police report, an IC3 filing, a platform's own recovery flow — would resolve your situation, we point you there first.
Related guides
To harden a device before anything goes wrong, see digital security for journalists.
To protect a source or intake channel, see protecting journalistic sources.
The overview is on the For Journalists hub.

















