HomeIntelligenceBrief
BREACH BRIEF🟠 High ThreatIntel

U.S. ICE Deploys Graphite Spyware for Immigration Enforcement Surveillance

ICE has openly acknowledged the use of Graphite's Israeli‑origin spyware to monitor individuals in immigration investigations. The revelation underscores third‑party risk concerns for government contractors and highlights the need for rigorous vendor vetting and privacy controls.

LiveThreat™ Intelligence · 📅 April 23, 2026· 📰 schneier.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
3 recommended
📰
Source
schneier.com

U.S. ICE Deploys Graphite Spyware for Immigration Enforcement Surveillance

What Happened – The U.S. Immigration and Customs Enforcement (ICE) agency publicly confirmed that it employs surveillance software developed by the Israeli firm Graphite. The tool, classified as “spyware,” is used to monitor individuals under immigration investigations.

Why It Matters for TPRM

  • Government agencies are sourcing high‑risk surveillance tools from foreign vendors, raising supply‑chain and data‑sovereignty concerns.
  • Use of such software can expose partner organizations to legal and reputational risk if data is collected without proper safeguards.
  • The disclosure highlights the need for continuous vetting of third‑party surveillance and intelligence products.

Who Is Affected – Federal law‑enforcement bodies, contractors that provide services to ICE, and any third‑party data processors linked to immigration case management.

Recommended Actions

  • Review contracts and data‑processing agreements with ICE‑related vendors for clauses on surveillance tool usage.
  • Conduct a risk assessment of any third‑party solutions that could be integrated with Graphite’s spyware.
  • Verify that appropriate privacy impact assessments (PIAs) and export‑control compliance are in place.

Technical Notes – The spyware is a proprietary product from Graphite, reportedly capable of remote device access, keystroke logging, and location tracking. No specific CVEs were disclosed. Source: Schneier on Security

📰 Original Source
https://www.schneier.com/blog/archives/2026/04/ice-uses-graphite-spyware.html

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Monitor Your Vendor Risk with LiveThreat™

Get automated breach alerts, security scorecards, and intelligence briefs when your vendors are compromised.