Imagine a journalist investigating corruption, an activist documenting human rights abuses, or a civil society organization exposing government wrongdoing. The technology they once thought belonged only to the realm of law enforcement can now be used to watch, track, and intimidate them.
Commercial spyware, developed by private companies and sold to governments as a tool for fighting crime, has been repurposed into a powerful instrument of digital surveillance.
Today, a compromised phone is not just a technical incident. It can expose confidential sources, communications, contacts, movements, professional networks, and sensitive information potentially putting entire communities at risk. Despite this, all conversations around spyware often begin and end with one question:
Was the device infected?
Detection is important, but it is only the beginning. Accountability however, requires asking what happens after the infection is detected.
Spyware investigations usually begin with technical evidence. Forensic analysis can reveal traces of exploitation, suspicious processes, malicious infrastructure, or other indicators of compromise that surveillance targets.
Preserving this evidence is critical. When someone suspects that their phone has been compromised, actions that can seem helpful such as factory-resetting the device, deleting suspicious messages, uninstalling applications, or immediately updating the operating system can change or destroy forensic evidence. However, the priority should be to preserve the device, document what happened, and seek trusted forensic assistance.
But forensic analysis should not stop at confirming an infection.
Behind every compromised device is a person and a context. A journalist investigating corruption. An activist organizing around a politically sensitive issue. A human rights defender documenting a violation.
Understanding spyware requires connecting technical evidence with the circumstances surrounding the targeting.
One compromised phone can be one piece of a larger puzzle; a much larger surveillance operation. When evidence is documented responsibly across cases, researchers can begin identifying common infrastructure, recurring indicators, targeting patterns, and affected communities.
This allows investigations to move from isolated incidents toward documenting systematic surveillance; and it matters because responsibility cannot automatically stop with whoever operated the spyware.
Commercial spyware exists within an ecosystem such as companies that develop surveillance technologies can facilitate their sale, governments or other customers purchase them, and operators eventually deploy them.
A journalist can become afraid of communicating with sources. An activist can stop organizing. Colleagues, family members, or vulnerable communities can be exposed through information stored on a compromised device.
Spyware therefore creates collective risk, one compromised journalist can potentially expose an entire network of confidential sources, and one targeted activist can expose colleagues who were never directly targeted themselves.
Documenting these consequences is essential for understanding the true impact of surveillance.
Journalists and lawyers play a particularly important role in this matter. They themselves can be targets, but they also are important to exposing the surveillance industry as a whole.
Collaboration between journalists, lawyers, forensic researchers, civil society organizations, and other accountability actors can transform technical evidence into questions of public interest.
Who purchased the technology? Which institutions had access to it? Were journalists or activists targeted? What safeguards existed? Did the vendor know about patterns of abuse?
These questions move investigations beyond malware and toward the systems enabling surveillance.
Finally, a recurring challenge remains: spyware is discovered, investigated, reported, and eventually replaced in the news cycle by another case.
Without mechanisms that translate evidence into consequences, documentation risks becoming an archive of abuses rather than a pathway toward accountability.
Technical investigations should therefore connect to broader action. Evidence can support investigative journalism, legal action, regulatory investigations, stronger export controls, transparency, advocacy, and efforts to establish safeguards around the sale and use of intrusive surveillance technologies.
No single organization can accomplish this alone. Accountability requires mutual collaboration between forensic researchers, journalists, activists, lawyers, policymakers, technology companies, and affected communities.
The goal of spyware investigations should therefore extend beyond detecting infections, each investigated case can contribute to a broader accountability chain:
Forensic evidence → documentation → investigation → public scrutiny → advocacy → accountability.
Success should not only be measured by how many compromised devices are identified. It should also be measured by whether affected communities are better protected, whether abuses are documented credibly, whether regional evidence reaches broader accountability mechanisms, and whether governments and companies responsible for surveillance face meaningful scrutiny.
Spyware accountability may begin with a device. It should not end there.
The post What should happen after we detect a spyware infection on a device? appeared first on SMEX.
