A Warning from the Buyer: Egypt Flags Israeli Spyware It Paid Millions to Use

Egypt’s telecom regulator warns of sophisticated spyware while technical investigations document the state’s use of foreign surveillance tools, raising questions about privacy, accountability and national security.
Picture of Hisham Aref

Hisham Aref

On December 9, 2025, Egypt’s National Telecom Regulatory Authority (NTRA), through its National Computer and Network Emergency Readiness Team (EG-CERT), issued an urgent warning about sophisticated hacking attempts targeting smartphone users in more than 150 countries, including Egypt. It said the attacks exploited previously unknown vulnerabilities—zero-days—and used malicious links and messages appearing to come from trusted sources.

The warning coincided with Google and Apple reports concerning sophisticated commercial spyware, including Predator, associated with Intellexa, described in the investigation as an Israeli spyware company subject to US sanctions for threatening global cybersecurity.

Intellexa is one of the best-known “mercenary spyware” companies, a term civil society and industry researchers use for private entities that develop spyware and sell it to governments.

The irony is that Egyptian authorities had previously worked with the same company between 2019 and 2021, using tools such as Predator to monitor activists, politicians and human rights defenders, according to technical investigations by Amnesty International and other organizations.

Leaked marketing brochure describing Intellexa’s spyware capabilities. Amnesty International.
Leaked marketing brochure describing Intellexa’s spyware capabilities. Amnesty International.

A subsequent investigation by Amnesty International, in collaboration with Inside Story, Haaretz and WAV Research Collective, found evidence that Intellexa could remotely access customers’ Predator systems, including systems physically located in government clients’ offices. It could therefore access data belonging to people targeted by governments.

Leaked internal documents underscored this particularly serious finding: Intellexa’s remote access extended even to systems at government premises, potentially exposing the information of people subjected to targeted surveillance.

Screenshot of a leaked document showing “Aladdin,” a zero-click infection system using a malicious advertisement and a public IP address. Amnesty International.
Screenshot of a leaked document showing “Aladdin,” a zero-click infection system using a malicious advertisement and a public IP address. Amnesty International.

The leaked files, covering much of the company’s recent history, provided additional technical and digital forensic evidence linking Predator—Intellexa’s flagship spyware—to specific surveillance abuses previously detected in Greece and Egypt.

Screenshot from a leaked internal training video showing Elasticsearch logs and information from a live Predator system. Amnesty International.
Screenshot from a leaked internal training video showing Elasticsearch logs and information from a live Predator system. Amnesty International.

Mahmoud Shalaby, Amnesty International’s researcher on Egypt and Libya, says the organization has documented commercial spyware and digital attacks against human rights defenders, journalists and political activists in Egypt in recent years.

He cites Egypt-linked campaigns using the Intellexa alliance’s Predator and digital forensic evidence from 2020 and 2021 involving opposition figures and journalists.

The 2021 Pegasus Project also found Egyptian activists’ and journalists’ phone numbers among potential targeting lists. Shalaby adds that Amnesty discovered a 2019 cyberattack against hundreds of people, including defenders working with Egyptian civil society organizations. They received emails attempting to access their accounts through a form of phishing known as OAuth phishing.

Shalaby describes these unlawful practices as broad violations of privacy. He says the Egyptian government has used them to stifle public life and create self-censorship by tracking and intimidating defenders, journalists and anyone potentially involved in the public sphere.

Who is watching Egyptians?

Egypt has faced growing rights criticism in recent years over expanding digital and legal surveillance affecting privacy and freedom of expression through phones, the internet and social media, as well as the blocking of news websites.

Nevertheless, parliament approved Criminal Procedure Law amendments last year permitting prosecutors, with a reasoned authorization from a district judge, to monitor wired and wireless communications, social media accounts, email, text, voice and video messages on phones and technical devices; seize media containing them; or record private conversations. The provision concerns felonies or misdemeanors punishable by more than three months’ imprisonment and allows a renewable maximum period of 30 days.

A review of surveillance systems obtained by Egyptian authorities since 2013 reveals systematic expansion in purchases of interception and digital spying technologies from US, French, Italian and Israeli companies.

Systems including ProxySG, Vortex, Cortex, Remote Control System, Pegasus and Cerebro went beyond observing public content. They provided capabilities to compromise personal devices, activate cameras and microphones, intercept encrypted communications and analyze behavior at scale.

How communications are monitored in Egypt: imported digital surveillance systems
System Company / country Use in Egypt Assessment in the Arabic graphic Source
ProxySG Blue Coat (United States) Imported in 2013 to monitor web traffic and track content Fully accurate Access Now
Vortex Ercom (France) Interception of calls, SMS, internet and location since 2014 Accurate SMEX
Cortex Ercom (France) Storage and processing of intercepted data Accurate SMEX
Remote Control System (RCS) Not directly specified; probably Hacking Team (Italy) Not explicitly mentioned in reports about Egypt; used for remote control of devices Accurate Access Now
Pegasus NSO Group (Israel) Zero-click phone compromise; camera and microphone activation; interception of encrypted communications Accurate and documented since 2018 Access Now
Cerebro Nexa / Amesys (France) Comprehensive DPI surveillance covering calls, email, social media and search; transferred from the UAE to Egypt in 2017 Accurate Access Now
Source: reports and unofficial sources, as identified in the Arabic graphic. Assessments reproduce the source graphic’s wording.

Digital surveillance means observing and tracking citizens’ digital activities—calls, emails, instant messages or internet browsing—to collect and analyze information about users’ behavior. Digital monitoring and control encompass technical and legal processes regulating content, observing traffic and analyzing patterns, including network management, interception and database analysis tools.

An information technology specialist who requested anonymity told Zawia3 that tracking citizens involves collecting detailed information about individual behavior: websites visited, people contacted and search terms used.

The potential legal problem, the specialist says, lies in the absence of clear legislation governing the relationship between the state and private companies operating these systems, placing personal data collection and behavioral monitoring in a legal gray area. Potential violations include infringements of privacy and telecommunications law, particularly without clear statutory authority or independent oversight safeguarding citizens’ rights.

Operation depends on hardware, software and personnel. Hardware stores and transmits data; software analyzes and classifies it; specialist staff operate networks and databases. Software may be local or imported, sometimes from companies indirectly linked to foreign states with possible political or security implications. This does not necessarily mean a direct national security threat exists, he cautions.

Collected information includes metadata such as telephone numbers, IP addresses and call times; communications content where a legal basis exists; and browsing and application use. The investigation shows that systems presented as infrastructure or digital transformation projects enable extensive aggregation and analysis of citizens’ information.

The system is a chain of technical operations: collection, analysis and potential tracking of an individual’s digital behavior, involving hardware, software and specialist operators. Without a clear legislative framework, these tools may be misused or remain in a gray area affecting privacy rights.

How do companies operate in Egypt?

Official, published contract information shows private companies such as Raya Information Technology and GTS acting as technical partners to public entities including Misr for Central Clearing and Telecom Egypt in network modernization and data center projects, forming the backbone of Egypt’s digital infrastructure in cooperation with foreign companies.

These companies are not accused here of directly conducting surveillance. Rather, their announced contracts, technologies and position within state digital infrastructure indicate a pivotal enabling role in surveillance systems without independent legislative oversight.

Canadian company Sandvine was among the principal foreign suppliers of deep packet inspection (DPI) equipment and technology to Egyptian internet providers, enabling authorities to monitor behavior and block websites.

According to reports by Qurium, Citizen Lab and the Association for Freedom of Thought and Expression, the company’s technology was used to train Egyptian employees in monitoring communications and directing internet traffic, while allowing access to sensitive information about citizens’ digital activity.

Software used to block independent media was detected in Egyptian networks, including traffic analysis and DPI. Reports cited in the investigation say at least 424 websites were blocked in 2017, rising to more than 500 by 2019.

Blocking continued through subsequent years and covered dozens of additional sites through 2025, bringing the total cited in the report to 600. These include 126 news websites and television channels, proxy and VPN services, and rights and political websites.

Amnesty International’s Security Lab reported on September 25, 2020 that German-made FinSpy had been used against activists and rights defenders through a fake Adobe Flash update. The campaign, known as NilePhish, targeted operating systems including Windows, macOS, Linux and Android.

On February 29, 2024, the US Commerce Department imposed restrictions on Sandvine by adding it to the Entity List, accusing it of selling internet monitoring and website blocking tools to the Egyptian government.

Rights groups welcomed the move, but it also raised questions about why this Canadian company was singled out while European and US firms continued supplying similar technologies.

In September 2024, Sandvine announced it would leave 56 countries it described as “non-democratic,” specifically naming Egypt and promising to end business there by March 2025. It presented the move as a comprehensive reform to prevent abuse, alongside announcements of its CEO’s departure, appointment of a human rights director and donations from future profits to internet freedom organizations.

Observers regarded these measures as responses to an economic crisis and mounting political pressure rather than a genuine ethical transformation. Withdrawal does not dismantle existing systems, they argue, but leaves a gap other suppliers can fill.

Documents and reports indicate Sandvine sales in Egypt exceeded USD 30 million since 2019, involving state bodies including NTRA and the Defense Ministry and major operators such as Vodafone Egypt and Telecom Egypt.

One of its largest deals was a 2020 contract worth more than USD 10 million with Telecom Egypt, according to Bloomberg. The relationship went beyond equipment sales to operation, support and training, including preparing local staff to use network surveillance technologies.

Although the company does not publish contract details or customer governments’ names, its official website describes professional services extending beyond equipment supply: installation, configuration, operation and end-user training, as well as resident support engineers for telecommunications operators and government clients.

Excerpt from the contract model published on Sandvine’s official website.
Excerpt from the contract model published on Sandvine’s official website.

Published support and service terms show that training in the operation of surveillance and network management products forms an integral part of commercial contracts.

This model corresponds to independent technical reporting, including Qurium Media Foundation investigations documenting Sandvine equipment in Egyptian internet provider networks used to systematically block media and rights websites through DPI. Qurium says observed blocking patterns indicate advanced network configuration, implying training and direct technical support rather than random use of tools.

Citizen Lab analyses at the University of Toronto similarly concluded that Egypt’s surveillance and censorship infrastructure relied on centrally configured network-level systems, suggesting direct technical cooperation between suppliers and operators.

Technical findings in Masaar and OONI reports identified Sandvine’s PacketLogic devices in Egyptian networks for traffic analysis, connection rerouting, redirection and website blocking.

The Canadian company’s name is also associated with attempts to target opposition politicians’ phones, including former parliamentarian Ahmed El Tantawy during the presidential election period in late 2023.

A technical investigation found a series of attacks against El Tantawy using Predator, which can record calls, activate cameras and microphones and monitor encrypted messages.

The picture extends beyond one company. Egyptian authorities imported US company Blue Coat Systems’ ProxySG through local agent Systems Engineering of Egypt (SEE Egypt), in a procurement process that also included offers from Gamma Group and Narus, according to a technical report. SEE Egypt is a major systems integrator with longstanding contracts with key state ministries.

Other tools include France’s Vortex and Cortex for interception, Italy’s Hacking Team Remote Control System for remote compromise and surveillance, and Israel’s Pegasus for smartphone spying.

Authorities also used Amesys/Nexa Technologies’ Cerebro for DPI-based communications surveillance, alongside projects such as a public opinion measurement system monitoring social media activity.

Observers say these tools enabled broad spying on calls, messages and correspondence; recording activity around devices; monitoring files and applications; and remotely activating microphones and cameras.

ProxySG gives operators capabilities to monitor internet traffic collectively, track users and approximate locations, filter content and block sites and applications, intercept messaging applications such as WhatsApp, Viber and Skype, and link behavioral analysis to identities.

Technical investigations and rights reports identified its use in Egypt after detecting false SSL certificates and widespread interception, particularly after 2013. The investigation argues that this reflects infrastructure-wide surveillance rather than isolated actions or individual court orders.

Authorities also turned to more intrusive tools targeting devices themselves, including Hacking Team’s Remote Control System (RCS).

In 2015, leaked internal company documents revealed contracts with Egyptian authorities providing comprehensive spyware able to compromise computers and phones, monitor calls, texts, email and chat, activate cameras and microphones, log keystrokes, copy files and identify location.

Leaked material illustrating the spyware’s capabilities.
Leaked material illustrating the spyware’s capabilities.

The leaks revealed a deal with Egypt’s Defense Ministry worth EUR 598,000 and another worth EUR 58,000 with Egyptian company GNSE Group. Saudi General Intelligence’s contract was estimated at EUR 600,000, and the UAE Interior Ministry’s at EUR 634,000.

RCS targets multiple operating systems, including Windows, Linux, macOS, Android, iOS and BlackBerry, marking a shift from network monitoring to direct control of personal devices.

The investigation describes growing reliance on Pegasus, one of the world’s most dangerous spyware products, developed by Israel’s NSO Group. It cites technical reports dating from 2018 concerning use by the Egyptian government through malicious links or zero-click attacks exploiting unknown vulnerabilities, allowing compromise without the user’s knowledge.

NSO Group, also known as Q Cyber Technologies, was established in Israel in 2010 and develops and sells surveillance software to governments and intelligence services. Its June 2021 Transparency and Responsibility Report listed 60 customers in 40 countries: intelligence agencies accounted for 51%, law enforcement for 38% and military bodies for 11%.

NSO and Pegasus have been associated with extensive use by Arab governments against journalists, activists, rights defenders and politicians inside and outside their borders. The company gained international prominence in 2016 when Citizen Lab exposed targeting of Emirati human rights defender Ahmed Mansoor.

Subsequent rights reports documented Pegasus targeting in Palestine, Egypt, Jordan and other Arab countries. NSO also faced litigation in several jurisdictions, including US cases brought by WhatsApp and Meta, judicial investigations in France, and actions by Apple and rights organizations concerning compromise of journalists’ and defenders’ devices.

The surveillance landscape includes government projects as well as imported tools. Egypt’s Interior Ministry announced its public opinion measurement system in 2013 as a “social media security risks monitoring project.” It could monitor Facebook, Twitter, YouTube and Instagram, analyze text and keywords and measure opinion trends, with scope to add platforms.

Systems Engineering of Egypt won the project over Britain’s Gamma Group and Israel’s Narus.

The hidden cost: millions in the shadows

Although digital surveillance contracts are not disclosed in detail, public budgets show substantial increases in information systems development and cybersecurity allocations in recent years without identifying beneficiaries or technologies. Surveillance technology companies’ investor reports list government revenues in the Middle East and North Africa without naming countries, overlapping with independent findings identifying these systems in Egyptian networks.

Surveillance contracts typically appear under broad budget headings such as telecommunications infrastructure development, securing national networks or supporting digital transformation rather than their actual names. These lines do not disclose contracted companies or services. The absence of a final total does not prevent estimates of the scale.

Global market prices suggest DPI and network surveillance systems deployed in a country with tens of millions of internet users require investments of millions, sometimes tens of millions, of dollars.

Internal documents reviewed by Bloomberg show Sandvine sold advanced surveillance technology in Egypt worth more than USD 30 million since 2019, including a single Telecom Egypt deal exceeding USD 10 million. Separately, the investigation cites Hacking Team’s 2015 leaks as showing approximately EUR 137,500 spent on its spyware in Egypt.

Egypt’s 2025/26 budget allocated about EGP 13 billion for public investment in communications and information technology, including about EGP 9 billion directly budget-funded for telecommunications infrastructure, cybersecurity and localization of IT and artificial intelligence.

How can surveillance software become a vulnerability?

A security researcher who requested anonymity told Zawia3 that advanced surveillance and spyware threaten not only privacy and activists but Egyptian national security itself. Exploiting unknown zero-day vulnerabilities can provide full access to smartphones without users’ knowledge or consent.

Once compromised, phones can transmit highly sensitive calls, messages, locations, photographs and files, and activate cameras and microphones at any time, the researcher says. This creates exposure for officials, military personnel, diplomats, journalists and employees of vital institutions, placing the state’s broader information security at risk of invisible compromise.

The risks multiply when the tools are associated with foreign companies, particularly Israeli firms such as NSO and Intellexa, operating in a politically and strategically complex relationship with Egypt.

Mostafa Fouad, executive director of HuMENA, told Zawia3 that Egyptian authorities’ tools fall into two tracks.

The first operates at internet provider network level, enabling website blocking, disruption of circumvention tools and sometimes direct interference in browsing traffic. The second targets devices themselves, phones or computers, and is more dangerous for individuals because it compromises their equipment directly.

Fouad cites Citizen Lab’s documentation of Ahmed El Tantawy’s targeting with Predator in 2023. Initial malicious links were followed by network injection into non-HTTPS connections on Vodafone Egypt’s network.

HuMENA is not a digital forensics laboratory and has a referral program with specialist partners rather than a “digital clinic,” Fouad explains. Its ongoing work on civic space nevertheless allows it to follow public evidence and specialist reporting and relate these to real-world effects.

This monitoring shows that blocking has been widespread and sustained since 2017. Techniques have become more complex, extending beyond individual URLs to alternative domains and multiple blocking layers across providers.

Fouad also sees a clear shift from mass blocking to individual targeting. El Tantawy’s case is an explicit example of commercial spyware used against a political figure, raising concerns that the approach could expand to journalists, defenders and opponents.

Complete details of government suppliers are not available as published contracts, Fouad says, but specific names appear in technical and rights documentation and official decisions outside Egypt.

Examples include Sandvine and Cytrox, Predator’s developer associated with the Intellexa group.

For Italian suppliers, Fouad recalls reporting after the 2015 leaks about a contract associated with Egypt’s Defense Ministry and Hacking Team, involving local intermediary GNSE Group and an invoice dating from 2012.

European rights reports and Italian organizations’ statements in 2016–17 also described a license granted to Italy’s Area SpA to export a communications and network surveillance system to Egypt’s Technical Research Department (TRD) through a local intermediary. The license was suspended, with Italian authorities then moving to cancel or revoke it under rights pressure.

Fouad describes these programs as grave violations of citizens’ rights and international human rights standards. They form an integrated system on two parallel levels: widespread, systematic information blocking and direct technical interference reaching into individual privacy.

Blocking hundreds of websites, including independent media, rights organizations and circumvention tools such as VPNs, undermines the digital public sphere and substantially restricts access to information, expression and circulation of opinions beyond narrow or exceptional legal justifications, he says.

Traffic manipulation or hijacking unencrypted HTTP connections goes beyond administration or regulation. It directly interferes in users’ communications and fundamentally affects their security and integrity.

Targeted tools such as Predator and FinSpy represent the most severe intrusion: compromising an individual’s device violates privacy, confidentiality of correspondence and personal life, while intimidating journalists, defenders and political opponents.

Fouad says these practices directly contradict Egypt’s international obligations to protect privacy and expression and its constitutional communications confidentiality safeguards, particularly without transparency, independent oversight or effective, testable avenues of appeal.

On national security, Fouad identifies a dangerous paradox: tools of digital control create structural weaknesses within telecommunications infrastructure.

Equipment capable of manipulating traffic or redirecting users necessarily creates a “control point” that can be exploited, compromised or abused, Fouad says.

Citizen Lab’s documentation of Predator network injection on a local network shows a capability that could theoretically have wider collective effects through poor management, counter-intrusion or leakage of the tools, Fouad says. Reliance on foreign suppliers and sensitive technology supply chains adds risks of leaks, backdoors or use by multiple parties outside meaningful accountability.

He concludes that policies presented as “protection” can weaken communications security, deepen digital infrastructure vulnerabilities and undermine trust in the entire digital public sphere.

The warning and the contradiction

NTRA’s December 2025 warning officially acknowledged the scale of the threat from a defensive perspective. It warned Egyptians of sophisticated smartphone attacks and explicitly described spyware exploiting unknown vulnerabilities—the same description used in Google and Apple reporting on Intellexa and Predator.

The state warning citizens about this software’s dangers also operates within a telecommunications environment that, according to documented reports, has used surveillance tools from similar foreign companies. The contradiction highlights the risk that supposedly “security” technologies become a strategic vulnerability allowing outside powers into Egypt’s digital space.

Although purchases are justified by security considerations, technological dependence raises fundamental questions about digital sovereignty. Can a state protect national security using tools whose technical architecture it does not fully control? Can surveillance shift from domestic control to a potential channel for foreign intrusion?

Search