Magnet Forensics Inc, a Toronto-based cybersecurity specialist, has filed a federal lawsuit accusing a former contractor of transferring sensitive information about a previously undisclosed iPhone security flaw to a competing firm. The action, lodged in the Northern District of Georgia on July 7, names Mario Del Gaudio and Paradigm Shift Technology SL as defendants, with Magnet contending that classified vulnerability details were posted publicly on the rival company's blog. The case represents a high-stakes dispute within the secretive world of offensive cyber tools sold primarily to government agencies and law enforcement for digital investigations.
Both Magnet Forensics and Paradigm Shift Technology operate in a niche but lucrative sector, developing and licensing so-called zero-day hacking capabilities to state customers worldwide. Zero-day vulnerabilities are software flaws previously unknown to cybersecurity professionals and vendors, providing a theoretical window of zero days for protection before exploitation. These tools are among the most prized assets in the cyber industry because they can bypass security measures that ordinary commercial software cannot penetrate, making them invaluable for investigative agencies seeking access to encrypted devices.
The specific vulnerability in question targeted Apple Inc's A12 and A13 processor chips used across multiple iPhone models. According to court filings, Magnet had developed a method allowing its government clients to penetrate locked iPhones and retrieve data through exploiting this previously unknown flaw. The technical breakthrough delivered substantial commercial value because it enabled law enforcement and intelligence agencies to access devices that would otherwise remain secure, potentially preserving evidence in criminal investigations that might otherwise be lost.
Del Gaudio served as an iOS exploit engineer at Magnet and spent months developing and refining the vulnerability while employed there. Magnet alleges that despite contractual obligations preventing such disclosure, Del Gaudio subsequently became involved with Paradigm Shift's research team. In June, Paradigm Shift published detailed technical research on the identical A12 and A13 vulnerability, making the information freely available to anyone searching online. The public disclosure fundamentally undermined the flaw's value to Magnet's customers, as Apple could now identify and patch the weakness.
The timing of events appears central to Magnet's legal strategy. Del Gaudio's employment at Magnet coincided precisely with the window during which the vulnerability was being weaponised for commercial use. His subsequent association with Paradigm Shift and that firm's June publication of the same vulnerability suggests, in Magnet's view, a deliberate transfer of proprietary knowledge. The company has characterised the fallout as causing "irreparable harm and continuing damage," language often used in intellectual property disputes to underline losses that money damages alone cannot adequately remedy.
Magnet Forensics itself represents significant capital and technical expertise concentrated in the hands of a relatively small player. The company serves more than 6,000 public and private sector customers across roughly 100 countries, according to its own records. In 2023, American private equity firm Thoma Bravo acquired Magnet Forensics for US$1.3 billion, signalling strong confidence in the sector's future growth and the company's competitive position. That acquisition values the firm's intellectual property and client relationships highly, making the loss of exclusive access to a zero-day vulnerability potentially costly.
Paradigm Shift Technology and Del Gaudio have not publicly responded to requests for comment, leaving their account of events undisclosed. The research remains published online despite Magnet's issuance of multiple cease-and-desist letters demanding removal. This persistent availability of the technical information intensifies the stakes for Magnet, as the vulnerability remains exposed and usable by any government, criminal, or other actor with the skills to implement it.
The case emerges against a backdrop of growing concern about the theft and illicit sale of offensive cyber tools. In 2025, a former government contractor employed by military defence firm L3Harris Technologies Inc pleaded guilty to stealing classified hacking tools and selling them to Russian brokers, ultimately receiving a prison sentence exceeding seven years. That incident highlighted how vulnerabilities and exploits can transition from legitimate government use into criminal and hostile-state hands, amplifying the security and foreign policy risks associated with such thefts.
For Malaysian readers and Southeast Asian technology stakeholders, this dispute carries several implications. The case demonstrates how intellectual property in the cyber domain remains contested and difficult to protect, even when contracts purport to restrict disclosure. It also illustrates the dual-use nature of cybersecurity technology, whereby the same tools developed for legitimate law enforcement can pose risks if disclosed or misused. Furthermore, the global nature of the cyber tools industry means vulnerabilities discovered and exploited in iPhones affect users everywhere, making international cooperation on cybersecurity governance increasingly necessary for protecting regional users and infrastructure.
