Active Incident? 24/7 Response →
SleuthX

For Journalists

Your Phone Was Hacked? Get a Forensic Answer.

Suspected mercenary spyware or a targeted intrusion is a forensic question, not a symptom checklist. We confirm or rule out compromise against published indicators, preserve the evidence, and document it to a standard that holds up.

Suspicion is not confirmation — and a wipe destroys the answer

If you have a credible reason to think your device was targeted, two things matter immediately: do not act on folk symptoms alone, and do not wipe or reset the device. Battery drain and overheating are weak signals with a hundred ordinary causes. A threat notification from Apple or a platform like WhatsApp, or a specific reason to believe you are targeted because of your reporting, is a reason to get a forensic examination. The fastest way to lose the answer is to factory-reset the phone, which destroys the very artifacts an examination relies on.

Preserve, do not wipe

Forensic value lives in the device’s current state. The first move is preservation: stop changing the device and let it be imaged, with the evidence hash-verified at the moment of capture and a documented chain of custody, with collection aligned to ISO/IEC 27037. Imaging first is what makes every later conclusion defensible — in an insurance claim, a police report, or court. If the device poses an active risk, there are containment steps that do not destroy evidence; ask us before you take action.

How forensic confirmation works

Once the device is preserved, the examination follows a documented method:

The honest boundary, which MVT’s own authors state, is that the absence of indicators is not proof a device is clean. Our finding is “indicators of compromise found” or “no known indicators of compromise found” — never a guarantee. The 2025 confirmation of Paragon’s Graphite spyware on journalists’ devices, reported by Citizen Lab, is a reminder that this is a live, evolving threat and that careful method matters.

Honest attribution, and where it ends

A forensic examination can frequently establish that a device shows indicators consistent with a known spyware family — and that is often the finding that matters most. Naming the operator behind the attack is far harder and is often not possible from the device alone. Even Citizen Lab and Amnesty’s Security Lab, who do this at the highest level, are careful about attribution. We apply their published, peer-reviewed methods; we are not them, and we do not claim to be. We will tell you exactly what the evidence supports and where it stops, and we do not guarantee attribution.

Incident response and what comes after

Confirmation is the start of a response, not the end. Depending on the finding, the work includes containing further exposure, re-securing accounts the device could reach, and documenting the incident for your editor, your insurer, or law enforcement. Where a matter heads toward litigation, we provide cybersecurity expert-witness support on the methodology and findings.

What working with us means

Related guides

To harden a device before anything goes wrong, see digital security for journalists. To protect a source or intake channel, see protecting journalistic sources. The overview is on the For Journalists hub.

Plain terms

What we are — and what we are not

What we are

A digital forensics practice with an AI agent at the center. Credentialed examiners, documented chain of custody, explainable findings you can verify, and court-admissible reports under FRE 901/902. When field work is needed — backgrounds, locates, physical surveillance — we coordinate with licensed private investigators. Lawful, confidential, on your side.

What we are not

Spyware, stalkerware, or a way to secretly monitor another person. We do not “hack back,” promise guaranteed money recovery, or touch any account or device without its owner's lawful authorization — and we decline engagements that ask us to.

Meet Your Practitioner

Quinnlan Varcoe

Founder & CEO

With operational experience across Fortune 50 security programs and the defense industrial base, Quinnlan founded SleuthX in 2022 to provide clients with the caliber of expertise typically reserved for the largest enterprises. Her work in threat intelligence and digital forensics has earned the trust of 26,000+ cybersecurity professionals who follow her analysis.

“26,000 professionals follow my work because I say what others won't — and I can back it up technically.”

Fortune 50 BackgroundDefense IndustryThreat IntelligenceDigital PrivacyIncident Response
Quinnlan Varcoe, Founder & CEO

Certified Expertise

GIAC · AWS · Splunk · CompTIA

Frequently asked about device compromise

Quinnlan Varcoe, Founder & CEO

Schedule Your Session

Confirm it. Preserve it. Respond.

A direct, confidential conversation with Quinn, the founder and CEO who reviews every case. We coordinate with your media-law counsel and, for litigation, provide expert-witness support. NDA-protected. No sales process.

Transparent pricing

Trusted by partners across the practice

DAS Health
Exhibit A Cyber
Ally Security
KIRO Group
Black Mirage
Kalles Group
Gridware
CQR
Archstone Security
Cyvergence
Sentinel Cyber
Cloud Underground
Seron Security
Hexen
Koru Risk Management
DAS Health
Exhibit A Cyber
Ally Security
KIRO Group
Black Mirage
Kalles Group
Gridware
CQR
Archstone Security
Cyvergence
Sentinel Cyber
Cloud Underground
Seron Security
Hexen
Koru Risk Management