6 min read

The Containment Problem: How the Surveillance Industry Escaped Its Own Market- 193

The Containment Problem: How the Surveillance Industry Escaped Its Own Market- 193

June 17, 2026

The commercial surveillance industry—once defined by a model of exclusivity, high costs, and state-level procurement—has experienced a definitive structural collapse. This report examines the three primary fronts of this collapse, tracing how the proliferation of sophisticated spyware, the failure of international regulatory frameworks, and the leakage of state-grade exploit frameworks into criminal hands have fundamentally altered the global security landscape. By analyzing these trends, we can better understand how tools previously restricted to accountable state actors are now fueling a broader, more pervasive environment of digital risk that extends far beyond traditional surveillance targets.

The commercial surveillance industry was built on a promise of exclusivity. Pegasus cost millions of dollars per deployment. Predator required government-level procurement. The tools were sophisticated, expensive, and ostensibly subject to export controls designed to keep them in the hands of accountable state actors pursuing legitimate security objectives. Whatever the reality of how those tools were used, the architecture was one of scarcity: only certain buyers could afford entry, which meant the technology's reach was theoretically bounded. That model has now collapsed across three fronts simultaneously, and the documents released across a single spring fortnight in 2026 collectively describe the collapse in enough detail to make the structural argument unavoidable.

The first front is simple proliferation. The UK National Cyber Security Centre, in findings presented at the CYBERUK conference in Glasgow, put the number of governments with access to commercial spyware capable of infiltrating phones and computers at one hundred, up from eighty in 2023. More than half the world's sovereign governments. NCSC director Richard Horne noted that the victimology of this surveillance has expanded beyond the traditional profile of at-risk individuals — journalists, dissidents, activists — to include bankers and wealthy businesspeople, a detail that carries its own diagnostic weight. When the customer base widens enough, vendors find new use cases to sell. A parallel study presented to Ukraine's parliament by the Economic Security Council placed the commercial cyberespionage market above $55 billion in 2025, with projections reaching $168.7 billion by 2033, and found that twenty-one of the world's thirty-one largest producers operate entirely outside international control mechanisms — companies in Israel, India, and Russia among them. The Pall Mall Process, the diplomatic framework designed to bring some order to this market, remains aspirational. Ukraine itself sought accession to that process precisely because its direct experience of digital surveillance and interference gave it a stake in making the framework real rather than ornamental.

The second front is geographic diffusion through regulatory failure. A Human Rights Watch report published in May, built on trade records obtained through freedom-of-information requests across the European Union, found that companies in Bulgaria, Poland, Finland, Denmark, Estonia, and the Czech Republic collectively sold surveillance technology to more than two dozen nations with documented histories of human rights abuses. Bulgaria alone exported to more than twenty countries, including the United Arab Emirates and Azerbaijan. France, Greece, Spain, Germany, and Italy — among the bloc's largest known exporters of surveillance technology — declined to provide their records at all. The European Commission's 2021 updated export control regime, which expanded the definition of covered products and required exporting states to consider recipients' human rights records, has not functioned as a binding constraint. Human Rights Watch noted that all but two of the commercial surveillance vendors identified in Google's 2024 Buying Spying report are EU-based — making Europe simultaneously the industry's primary geographic center of gravity and the jurisdiction most visibly failing to govern it.

The third front is the one that fully dissolves the original exclusivity model: the tools are now leaking, and when they leak, they land in criminal hands equipped to repurpose them at mass scale. DarkSword and Coruna, two zero-click iOS exploit frameworks discovered by researchers in early 2026, both bear the code quality signature of state-affiliated development — uniformly engineered exploit chains, detailed English-language inline comments explaining each component's function, six-vulnerability and twenty-three-vulnerability chains respectively that required the kind of sustained, well-resourced research effort associated with intelligence contractor work rather than criminal shops. Kaspersky's Global Research and Analysis Team confirmed that Coruna is a direct evolution of the Operation Triangulation framework, the sophisticated campaign that targeted Kaspersky's own employees. One current theory is that an insider at the developing firm sold Coruna to criminal actors; however it happened, the tool has since been used to drain cryptocurrency wallets from an estimated 42,000 devices in China alone. DarkSword's original operators compounded the problem by leaving its full source code on the infected websites they controlled, effectively open-sourcing a precision intelligence weapon to any criminal group with the competence to read it. The UK NCSC's report on the DarkSword leak made the systemic point explicit: tightly guarded government hacking tools can and do escape containment, and when they do, they expose not a narrow set of targeted individuals but potentially millions of ordinary users. Google's zero-day attribution data for 2025 frames the broader picture: of ninety zero-days tracked that year, eighteen were attributed to commercial surveillance vendors, primarily targeting mobile devices and browsers. The vendors who built tools for governments are the same vendors whose products now drive a significant share of overall zero-day exploitation volume, regardless of who is ultimately pulling the trigger.

leakage funnel — showing how a tool moves from state-affiliated developer to commercial vendor to government client to criminal actor to mass-infection victim, the trajectory that DarkSword/Coruna illustrates

What Citizen Lab's April 2026 research adds to this picture is invisible infrastructure. The researchers documented two separate surveillance campaigns exploiting known weaknesses in SS7, the aging signaling protocol that underpins most 3G voice and text routing and that lacks both authentication and encryption, and in Diameter, the nominally more secure protocol for 4G and 5G networks that many operators have deployed without implementing its available protections. The campaigns, observed targeting telecoms in at least seventeen countries across Europe, Africa, and Asia, relied on a centralized command-and-control platform with what the researchers described as deep integration into the global signaling ecosystem, providing multiple routing options to covertly reach target networks. A single high-profile executive in the Middle East was tracked across multiple operator networks and multiple country jurisdictions over a period of years — the kind of persistent, multi-hop surveillance that requires not just a tool but an industrial platform. Citizen Lab researcher Gary Miller was direct about the scale: the unauthorized traffic flowing through the mobile signaling environment is massive, generated overwhelmingly by third-party actors, and the telecoms themselves have not addressed it. The infrastructure of targeted political surveillance has, in other words, been quietly embedded in the signaling fabric of the global mobile network, using the same trusted interconnections that route ordinary calls and text messages, and the operators whose networks carry this traffic are frequently unaware it is happening.

market growth chart — $55B (2025) to $168.7B (2033) bar or curve, with the proliferation count (80→100 countries) overlaid, making the scale argument visual

Taken together, these findings describe a market that has long since outgrown its original governance model without any replacement governance model emerging to take its position. The cost of entry has fallen, the number of buyers has more than doubled in three years, the tools routinely escape into criminal ecosystems, the regulatory frameworks in the jurisdiction that hosts most of the industry's vendors are not enforced, and the infrastructure these vendors depend on has burrowed into the world's telecom networks in ways that individual operators cannot detect and international bodies have not required them to address. What was sold as a controlled, precision instrument of state security has become a sprawling, poorly contained industry whose second and third-order effects are now visible not only in the phones of journalists and dissidents but in the cryptocurrency wallets of ordinary users in China, Saudi Arabia, Turkey, and Malaysia. The containment argument was always partly a legal fiction; it is now a demonstrable one.