Active Incident? 24/7 Response →
SleuthX

Read this first

Are you on a device or network the person can see?

  • If they might be able to see this device, use one they can’t access — a friend’s phone, a library or public computer, or a domestic-violence shelter’s safe device. If you continue here, your visit may be visible on a synced iCloud, Google account, or shared family plan.
  • If you think spyware or stalkerware is on this device, removing it can alert the person monitoring you and can destroy evidence. Make a safety plan — ideally with a domestic-violence advocate — before you remove anything, and use a device they can’t access in the meantime.
  • The Quick Exit button(top right) replaces this page with weather.com immediately — but it does noterase this visit from your history, and private/incognito mode doesn’t fully hide it either. To be safe, use a device the person can’t access.
  • If you’re in immediate danger, call 911. If you have a few quiet minutes, keep reading.

National Domestic Violence Hotline: 1-800-799-7233 · text START to 88788 · thehotline.org — 24/7, free, confidential.

988 Suicide & Crisis Lifeline: call or text 988 · 988lifeline.org — free, confidential crisis and emotional support, 24/7.

NNEDV Safety Net: techsafety.org — technology-safety help for survivors.

Spyware Explainer

What Is Pegasus Spyware (and Zero-Click Attacks)?

Pegasus is mercenary spyware sold to governments. The frightening part for journalists is the “zero-click” delivery — your phone can be compromised without you tapping anything. Here's what that means in plain language, and what it doesn't mean.

Pegasus is commercial spyware made by the NSO Group and sold to government clients. Once it is on a phone it can read messages, listen to calls, turn on the microphone and camera, and pull location — including content inside end-to-end encrypted apps, because it reads the device after the message is decrypted. The Pegasus Project, a collaboration of newsrooms coordinated by Forbidden Stories with technical analysis from Amnesty International’s Security Lab, documented its use against journalists, lawyers, and activists.

What “zero-click” means

Most phone malware needs you to do something — tap a link, open an attachment, install an app. A zero-clickexploit needs none of that. It abuses a flaw in how your phone silently processes an incoming message, image, or call, so the device is compromised before anything appears on your screen. There is nothing obvious to avoid clicking, which is exactly why ordinary “be careful what you open” advice is not enough against a targeted operator.

How likely is this for you?

Mercenary spyware is expensive and targeted. It is aimed at specific high-risk people — reporters on national-security, corruption, or human-rights beats, their sources, and their editors — not sprayed at the general public. If you cover those beats, the right response is a calm threat model, not panic. If you do not, the realistic risks to your reporting are far more ordinary (phishing, account takeover, a lost device). See how to threat-model your reporting to size the risk honestly.

The honest limits of any check

This matters more than anything else on this page: a clean result never means “your device is safe” — only “no known indicators of compromise were found.” Detection relies on published indicators for spyware that has already been studied. A new exploit chain, or one that cleans up after itself, can leave nothing for a check to find. Absence of evidence is not evidence of safety.

And if you suspect your phone is infected, do not factory-reset it or rip out a suspicious app first. Wiping the device destroys the very forensic traces that could confirm what happened, and acting on the device can tip off whoever is watching. Preserve first: stop using it for sensitive work, keep it powered and in the state it is in if you can, and get a methodical check. The companion guide, how a journalist checks a phone for spyware, walks through the safe order of operations.

If you need lab-grade confirmation

Self-checks are a screening step, not a verdict. When the stakes are high — a story, a source, or your own safety — a credentialed examiner can image the device without altering it, correlate against known indicators, and produce a court-ready record of what was and was not found. SleuthX offers that confirmation step; see newsroom device-compromise response. Free help from the named research labs below should usually be your first call.

Primary sources

  1. The Citizen Lab (University of Toronto), Research on mercenary spyware, including NSO Group's Pegasus. https://citizenlab.ca/
  2. Forbidden Stories, About the Pegasus Project — the journalism investigation into Pegasus. https://forbiddenstories.org/about-the-pegasus-project/
  3. Amnesty International Security Lab, Forensic methodology and indicators for detecting Pegasus. https://securitylab.amnesty.org/

Meet Your Practitioner

Quinnlan Varcoe

Founder & CEO

GIAC-certified · 15 industry certifications

With operational experience across Fortune 50 security programs and the defense industrial base, Quinnlan founded SleuthX in 2022 to provide clients with the caliber of expertise typically reserved for the largest enterprises. Her work in threat intelligence and digital forensics has earned the trust of 26,000+ cybersecurity professionals who follow her analysis.

“26,000 professionals follow my work because I say what others won't — and I can back it up technically.”

Fortune 50 BackgroundDefense IndustryThreat IntelligenceDigital PrivacyIncident Response
Quinnlan Varcoe, Founder & CEO

Certified Expertise

GIAC · AWS · Splunk · CompTIA

Transparent pricing

Trusted by partners across the practice

DAS Health
Exhibit A Cyber
Ally Security
KIRO Group
Black Mirage
Kalles Group
Gridware
CQR
Archstone Security
Cyvergence
Sentinel Cyber
Cloud Underground
Seron Security
Hexen
Koru Risk Management
DAS Health
Exhibit A Cyber
Ally Security
KIRO Group
Black Mirage
Kalles Group
Gridware
CQR
Archstone Security
Cyvergence
Sentinel Cyber
Cloud Underground
Seron Security
Hexen
Koru Risk Management