The Pegasus spyware scandal: a critical review of Citizen Lab's "CatalanGate"
Bibliographic record
Abstract
This document dissects the report “CatalanGate: Extensive Mercenary Spyware Operation against Catalans Using Pegasus and Candiru”, published on 18 April 2022, by Citizen Lab at the Munk School of Global Affairs and Public Policy, University of Toronto, and reveals a series of serious methodological and ethical issues that severely undermine its value as evidentiary basis for parliamentary committees and court trials. This critical review shows that Citizen Lab’s research design, fieldwork, and reporting of findings in the “CatalanGate” report clash with commonly accepted norms of academic research conduct and integrity. The variety and gravity of the pitfalls discovered suggest that Citizen Lab and the political organisations that collaborated with them in the elaboration of the report may have tried to purposefully induce a strong political bias to shape public opinion and achieve strong media impact. This critical review recommends the University of Toronto to launch an independent investigation on this report and to retract its publication. The CatalanGate report cannot be considered a rigorous academic work. It breaches most academic research conventions and does not respect the protocols and principles of digital forensic investigation. It appears to have been designed and conducted with the purpose of becoming a political instrument for Catalan nationalists, feeding evidence for lawsuits that both Apple and secessionist parties were planning, and attempting to justify ex-post the nullity of several trials that had taken place after the unilateral secession attempt in October 2017 —based on the pretended illegal monitoring of lawyers by the Spanish authorities at the time these trials took place—. As such, it could be considered as a key element in a disinformation campaign. It is beyond the scope of this review to assess whether Spain spied —legally or illegally— on some of the participants in the investigation or if Pegasus was the spyware of choice. This review shows, however, that the CatalanGate report does not meet the minimal requisites to be used as evidentiary basis for either legal procedures or parliamentary committees of enquiry. An independent investigation for research misconduct is expected in cases as serious as this one. Any parliamentary committee or court of justice investigating CatalanGate should request independent forensic experts —without connections to Citizen Lab or Amnesty Tech— to reproduce the analyses and assess their validity and reliability. It is important to rule out false positives as well as to identify any potential alterations or fabrications of evidence, such as manufactured positive results, taking advantage of the absence of a chain of custody of evidence in this investigation. The lack of checks on the actions of internet security and privacy watchdogs, such as Citizen Lab, and their potential “capture” by Big Tech corporations and partisan political groups should be a source of concern for the European Union. Citizen Lab is right to demand public accountability and transparency from European Member states, but it is also important that they also adhere to these same principles and that accusations against governments do not drive attention away from responsibilities and challenges incurred by Big Tech corporations regarding internet security.
Fetched live from OpenAlex and de-inverted. Abstracts are not stored in this database: the inverted indexes are 8.6 GB of the frame’s 9.3 GB of text, and the host has 13 GB free.
How this classification was reachedexpand
Full frame distilled prediction
Teacher imitationNot calibrated prevalence, not ground truth. Human validation pending. Learned from the 10,348 direct Codex labels and 10,348 direct Gemma labels. Candidate is the union of thresholded teacher heads; consensus is their intersection. These outputs are machine_predicted_unvalidated and are not human labels or direct frontier model labels.
Codex and Gemma teacher scores by category
| Category | Codex | Gemma |
|---|---|---|
| Metaresearch | 0.012 | 0.016 |
| Meta-epidemiology (narrow) | 0.001 | 0.000 |
| Meta-epidemiology (broad) | 0.002 | 0.000 |
| Bibliometrics | 0.001 | 0.001 |
| Science and technology studies | 0.001 | 0.028 |
| Scholarly communication | 0.000 | 0.000 |
| Open science | 0.002 | 0.002 |
| Research integrity | 0.001 | 0.001 |
| Insufficient payload (model declined to judge) | 0.001 | 0.000 |
Machine scores (provisional)
The two teacher heads of the student model, read on this work. A score orders the frame for review; it never asserts a category, and the validation status ships verbatim with every row.
Baseline scores from an immature model (maturity gate not passed, 7 training rounds). Scores rank; they never assert a category.
score_only:v0-immature-baseline · verbatim from the scoring run: score_only means the number may rank works, and no category label ships from itClassification
machine, unvalidatedMachine predicted; a candidate call from one teacher head, not a consensus.
How this classification was reached, model by model and score by score, is at the end of the page under "How this classification was reached".