Monday, August 3, 2026

Policy & Regulation

U.K. cyber agency: 100 countries now have access to spyware

The U.K. National Cyber Security Centre reports that 100 countries now have access to commercial spyware, potentially lowering the barrier for foreign actors to target critical infrastructure.

U.K. cyber agency: 100 countries now have access to spyware

More than half of the world’s governments have access to commercial spyware that can break into computers and phones to steal sensitive information, according to U.K. intelligence. The U.K. National Cyber Security Centre (NCSC)—the British government organization responsible for cyber security—plans to reveal its findings Wednesday, according to Politico. The report suggests that the barrier to access this type of surveillance technology has fallen, potentially making it easier for foreign governments and hackers to target U.K. citizens, companies, and critical infrastructure with spyware. This represents an increase in the number of countries with access to these hacking tools to 100, up from the 80 countries U.K. intelligence estimated in 2023.

Commercial spyware, developed by private companies like NSO Group (the developer of Pegasus spyware) and Paragon (the developer of Graphite spyware), often relies on exploiting security flaws in phone and computer software to break into devices and steal data. While governments have claimed they only use spyware against criminal and terror suspects, security researchers and human rights defenders have warned that governments have misused spyware to target their critics and political adversaries, including journalists. U.K. intelligence now says that the victimology has “expanded” to include bankers and wealthy businesspeople.

Richard Horne, who runs the NCSC, said in a speech at the CYBERUK conference in Glasgow—a cyber security conference—that British companies are “failing to grasp the reality of today’s world.” Horne stated that the majority of nationally significant cyberattacks targeting the United Kingdom has originated from foreign adversarial governments, rather than cybercriminals. The U.K. also continues to experience China-linked intrusions aimed at stealing sensitive data, spying on high-profile individuals, and setting the groundwork for potentially disruptive hacks.

The spyware threat is not just from governments, but also cybercriminals with access to these tools. Earlier this year, a hacking toolkit dubbed DarkSword leaked online, containing several exploits capable of hacking into modern iPhones and iPads manufactured by Apple. The leak showed that even tightly guarded hacking tools developed by and for governments can leak and proliferate out of control, putting people at risk from hacks.

Why it matters

The proliferation of commercial spyware to 100 countries marks a significant shift in the global threat landscape, moving beyond state-level actors to a broader range of targets, including private sector leaders.