23.09.26
Argomenti correlati
An IrpiMedia investigation reveals the key role Israel played in the rapid rise of Dataflow Security, an Italian company capable of developing what is considered the holy grail of cyberweapons: code that exploits vulnerabilities in computers and smartphones to spy on a target.
Founded in 2019 by Luca Todesco, a hacker prodigy who was just 22 at the time, Dataflow quickly became one of the most highly regarded players in a multimillion-euro market whose main customers include governments, intelligence agencies and spyware developers.
The company carved out an important position in Israel’s offensive cyber industry, a sector of strategic importance to the country. The scale of those ties is captured by one name: Eyal Tsir Cohen, a former senior Mossad official. IrpiMedia has found that since December 31, 2025, Tsir Cohen has headed two Dataflow-controlled companies in Israel: DF Security Israel Ltd and Random Research Ltd.
Just nine months earlier, Prime Minister Benjamin Netanyahu had shortlisted Tsir Cohen to lead Shin Bet, Israel’s domestic intelligence agency. Kan.org, the website of Israel’s public broadcaster, described him as «the candidate who supports the military occupation of Gaza», citing his support for suspending humanitarian aid and increasing military pressure on the Strip.
The investigation in a nutshell
- Dataflow Security, founded in 2019 in Bassano del Grappa by hacker Luca Todesco, develops exploits to break into computers and smartphones. Over three years, it generated almost €63 million in revenue, mostly outside the EU
- The company has forged close ties with Israel. Since December 31, 2025, its two Israeli subsidiaries have been led by Eyal Tsir Cohen, a former senior Mossad official who was shortlisted to lead Shin Bet in 2025
- Among its ranks are former members of Israeli military and intelligence units, as well as former employees of NSO Group, an Israeli spyware giant that has faced accusations over abuses carried out with its software
- Dataflow presents itself as an “ethical” supplier and says it operates only in democratic environments. But experts say that, once an exploit is sold, its developer loses almost all control over how it is used
- Italy’s export system is also opaque: Uama says it does not issue new licenses for exports to Israel, but has not clarified what happened to those already granted. It also denied IrpiMedia specific data on Dataflow and aggregated national figures
His candidacy also drew public backing from Amir Avivi, a former brigadier general and chairman of the Israel Defense and Security Forum. The Zionist organization says it represents 55,000 serving and former members of Israel’s security apparatus and advocates full Israeli military control over the West Bank. According to Avivi, Tsir Cohen was himself a member. But Tsir Cohen did not become head of Shin Bet. Instead, he joined the company founded in Bassano del Grappa, in Italy’s Veneto region.
Dataflow says it «operates in fully democratic environments», and this investigation has not documented abuses involving its products — abuses that are extremely difficult to detect in this industry. Yet its subsidiaries’ ties to senior figures in Israeli intelligence raise questions about their independence.
Experts interviewed by IrpiMedia describe particularly close ties between Israel’s state security apparatus and private companies developing offensive technologies. The relationship is all the more controversial given Israeli authorities’ extensive use of these tools to surveil the Palestinian population.
The cyber industry’s role in controlling the occupied territories and conducting military operations in Gaza has been documented from different perspectives. It is examined in Antony Loewenstein’s investigative book The Palestine Laboratory and in a report by United Nations special rapporteur Francesca Albanese.
More recently, the documentary Naza featured testimony from Israeli soldiers and intelligence officers about the systems used to identify and strike targets in the Gaza Strip. Once these capabilities are sold, industry experts say, their developers lose almost all control over how they are used. They have no effective means of preventing abuse.
Vulnerabilities and zero-days: what are they?
Zero days are software vulnerabilities discovered by a researcher but still unknown to the maker of a device. The manufacturer therefore cannot fix them. The tool used to take advantage of a vulnerability is known as an exploit. It is software that allows an attacker to remotely take control of a target device, whether a smartphone, computer or voice assistant. Some exploits require the victim to take an action, even unknowingly.
This might mean opening an attachment or clicking a link. So-called zero-click exploits require no action at all from the target. Simply receiving a message can be enough to compromise a phone, without the target noticing. This ability to keep an attack hidden is particularly valuable in surveillance operations.
Zero-click exploits are among the most sought-after and expensive products on the market. Those that leave few traces are especially valuable. According to two IrpiMedia sources in the industry, a single zero-click exploit for an iPhone can be worth between two and three million dollars. Attacking a device today may require more than one exploit.
«Exploit developers and brokers [exploits are pieces of code used to break into devices, ed.] help fuel spyware abuses, but the industry remains a black box. Even when we find spyware on someone’s phone, we rarely know who sold the exploit code used to infect the device», says John Scott-Railton, a researcher with the Citizen Lab, a University of Toronto research group that has documented spyware on the phones of journalists and activists around the world in recent years.
«After an exploit sale, a supplier typically has no control over what happens next. It hands the code over to the client and does not see how it is used. If Dataflow claims to be different from the rest of the industry, it should prove it by opening up its business practices to external audit and oversight», Scott-Railton adds.
The Italian hacker prodigy the 007s like
Dataflow’s headquarters are in an unremarkable building in the historic center of Bassano del Grappa, a short walk from the banks of the Brenta River. Only a small paper label next to the intercom signals the company’s presence. But the modest entrance hides a fast-growing international business.
Dataflow now has five subsidiaries abroad: the two already mentioned in Israel, one in Spain and two in the United States. Over the past three years, the company generated almost 63 million euros in revenue. About 63 percent came from outside the European Union, while just 11 percent came from Italy.
Dataflow’s subsidiaries
The company now has five subsidiaries abroad: two in Israel, one in Spain and two in the United States
Its international reach also shows in a network of advisers with links to European and American security agencies. They include Rob Bertholee, a former head of the Dutch intelligence service, and Ralph Goff, a CIA veteran. Another is Robin Louise Fontes, former deputy commanding general for operations at US Army Cyber Command, the branch of the US military responsible for cyber operations.
Public records reviewed by IrpiMedia reveal the company’s latest international deal. On April 20, 2026, US defense and engineering giant Parsons Government Services awarded Dataflow a $122,500 software subcontract. The work was part of a research project funded by the US Air Force.
On paper, Dataflow started small: 2,500 euros in capital and a single shareholder, Luca Todesco. But IrpiMedia’s reconstruction shows that the Italy-Israel axis was present almost from the beginning and grew stronger as the business expanded.
Dataflow’s technical brain remains in Italy. Todesco, known in hacker circles by the online handle qwertyoruiop, specializes in finding software vulnerabilities and developing code to exploit them. He has focused particularly on Apple products, considered among the hardest to breach.
The enfant prodige first drew attention in 2016, when he posted a video on X, then known as Twitter. It showed him bypassing restrictions on the newest iPhone and installing unauthorized software. A year later, the international edition of Forbes included the then 19-year-old in its European technology “30 Under 30” list. It called him «one of the best-known iPhone hackers in the world».
Dataflow built its business on those skills. Todesco had already begun monetizing them in Timișoara, Romania. Documents obtained by IrpiMedia show that he served as director of four software development and consulting companies. Between 2017 and 2022, they recorded combined net profits of about 6.32 million euros.
Sostienici e partecipa a MyIrpi
Regala l’adesione a MyIrpi+
e ricevi in omaggio la nostra T-shirt IrpiMedia.
Diventa una fonte.
Con IrpiLeaks puoi comunicare con noi in sicurezza.
As “breaking into” Apple systems became more complex, the work began to require a team. Todesco turned the operation into a more structured laboratory. «That is how Dataflow was born», he said at PoC 2024, an annual cybersecurity conference in Seoul, South Korea.
The Italy-Israel axis
Eleven months after Dataflow was founded, an Israeli investor entered the picture. Ofer Cohen — no relation to Tsir Cohen — acquired a 22.62 percent stake in 2020. He has remained the company’s second-largest shareholder after Todesco.
His background is very different from that of the young hacker. On LinkedIn, Cohen lists previous service in Mamram, the Israeli military unit that manages IT and communications systems. He later became a serial entrepreneur in the cyber sector. It may be no coincidence that Dataflow’s official website gives 2020, rather than 2019, as the year the company was founded.
Cohen is listed as Dataflow Security US’s point of contact and “managing partner” on Sam.gov, the federal database used by companies seeking US government contracts. In 2023, he also established Dataflow’s two Israeli subsidiaries, DF Security Israel and Random Research. Both are based in Herzliya, one of the surveillance industry’s key hubs.
But company records reviewed by IrpiMedia reveal a difference between the two subsidiaries. Random Research has two shareholders who do not appear in DF Security’s ownership structure.
One is Ofer Cohen himself. Unlike Todesco, he holds a direct personal stake in Random Research, in addition to his indirect interest through the Italian parent company. The other shareholder appeared only weeks after Tsir Cohen was appointed director. The shareholder’s identity is concealed behind a trustee: Sagi Ra’anan, a partner at the Israeli law firm Herzog Fox & Neeman who specializes in national security, export controls, defense trade and international sanctions.
Other minority shareholders also have intelligence backgrounds. According to his LinkedIn profile, Bar Avraham Matityahu spent more than six years in Unit 8200, the technology unit of Israeli military intelligence. Itay Rotem says he worked as a developer for the same unit.
Dataflow has also recruited from the spyware industry, particularly from NSO Group. The Israeli giant has faced accusations over abuses carried out with its spyware, which has been found on the phones of journalists and activists around the world.
IrpiMedia identified at least six former NSO employees now working for Dataflow. They include Korin Shapira Sharir, who worked on branding for both companies, and Itzik Kauffman. Kauffman became head of a research and development team at Dataflow after spending three and a half years at NSO.
«Dataflow has become an indispensable cog in Israel’s offensive cyber research and development machine, working side by side with local authorities», an industry source based in Israel told IrpiMedia on condition of anonymity.
According to the source, Dataflow’s strength is its business model. «Unlike companies that offer complete, ready-to-use surveillance platforms, Dataflow focuses primarily on developing one component of those platforms — the part that launches the attack», the source explains. «It is a strategy that sets it apart from larger operators, which attract greater media scrutiny, and makes it appealing to clients and employees alike».
The ethical promise
The market for software vulnerabilities has changed profoundly in the past decade. Secret deals between hacker groups, companies and governments have given way to a more organized and less secretive industry. But it has vulnerabilities of its own.
«When handling tools this dangerous and sensitive, a direct approach to risk analysis and management is essential. Each case requires an assessment not only of what the vulnerabilities can do, but also of the geopolitical context and the destination countries. It is a necessary approach, but one that is neither widely adopted nor rewarded in this industry», says IrpiMedia Andrea Zapparoli Manzoni, former chief executive of Crowdfense, a Dubai-based platform connecting offensive-technology researchers with clients.
In this market, Dataflow presents itself as an “ethical” supplier, a reputation that matters greatly to Todesco. Two sources familiar with the company’s activities told IrpiMedia that its ambition is to «become the new NSO». Both spoke on condition of anonymity.
Until three months ago, Todesco ran a Mastodon parody channel dedicated to NSO Group. He repeatedly used it to condemn abuses and discuss suppliers’ responsibilities. The channel became inaccessible in mid-June 2026, after IrpiMedia contacted Dataflow about the nature of its business. By then, IrpiMedia had already saved screenshots.
In February 2025, Todesco commented on reports that spyware company Paragon had ended its relationship with the Italian government. Paragon’s software had been found on the phones of journalists and activists. «This is how the industry should respond to misuse», he wrote.
«We detest abuse (…), but personally, from those on the defensive side, I have seen nothing but mockery, obstructionism or demonization. It does not have to be this way», he said in 2024. He added: «We have long operated on the basis of a strict allowlist and are aggressively removing almost all private companies from our client base».
Those claims, however, cannot be independently verified. Italy’s Unit for the Authorization of Armament Materials, known as Uama, issues export licenses for cyber-intrusion technologies. Between January and April, the Foreign Ministry body repeatedly rejected IrpiMedia’s freedom-of-information requests asking how many licenses had been granted to Dataflow and for which countries.
Dataflow’s operations in Israel also raise concerns, given its close ties to the intelligence apparatus. Companies working in offensive technology in Israel, such as Dataflow, «may be private, but they operate under the control of the Israeli Ministry of Defense», says IrpiMedia Israeli human rights lawyer Eitay Mack. Journalist Antony Loewenstein adds that «many of these companies are independent in name, but in practice they are very close to the state».
This dynamic predates October 7, 2023, when Hamas launched its attack on Israel. But «it has become even more apparent since then. The Israeli state began recruiting private companies to address military and technological challenges», Loewenstein tells IrpiMedia.
Cyberweapons: the black hole of Italian exports
Italy does not issue new licenses to export cyber-intrusion technologies to Israel, Uama told IrpiMedia by email. The Foreign Ministry unit authorizes exports of military equipment and dual-use goods, including the technologies in question.
But the authority did not clarify what happens to previously issued licenses that remain valid. It did not say whether they can still be used, or whether they have been suspended, revoked or restricted. This is one of several blind spots in an industry where public transparency is even more limited than in the conventional arms trade.
Italy publishes at least partial information on conventional weapons exports, including destination countries, categories, values and the companies involved. There is no equivalent disclosure for cyber-surveillance products. Even national totals are withheld. The only available figures are aggregated at the European level and cannot be cross-referenced to identify where Italian technologies are sent.
In response to IrpiMedia’s freedom-of-information requests, Uama withheld both information specifically concerning Dataflow and aggregated national data. It said that «the very nature of the requested data — even when aggregated — is such that selective redaction cannot eliminate the risk of harm».
According to Uama, the combination of product, year, destination and economic value could still reveal the identity of specific operators. The authority also argued that disclosure would expose foreign-policy assessments. It would «jeopardize […] the confidentiality and delicate balances through which relations between states must be conducted, undermining mutual trust in the international context», Uama said.
IrpiMedia asked Dataflow to clarify its relationship with Israeli intelligence and the country’s broader cyber-surveillance ecosystem. It also asked how the company selects clients and what technical safeguards it uses to prevent abuse. Dataflow did not address those questions.
«While we share the spirit of inquiry behind your work, we are bound by contractual, regulatory and confidentiality obligations that prevent us from responding in detail. Much of this information can be shared, within the limits imposed by law, only with the end users of our products or with the competent authorities», the company says in a statement provided to IrpiMedia.
«We exclude — the company adds — anyone unable to provide solid assurances that they operate in fully democratic environments and in full respect of fundamental rights. We work only with entities that use our products to protect the public, and all contracts include specific restrictions to that effect. Whenever suspicions of improper use have emerged, the relationship has been terminated immediately, regardless of the size of the contract or the client’s profile».
However, two former offensive-technology salespeople told IrpiMedia that there is currently no reliable way to prevent these tools from being misused once they have been purchased. «You sell the technology to someone who needs it, then one of their partners needs it, and suddenly it ends up somewhere else and you have no way of controlling it», says Adriel Desautels.
Desautels founded US cybersecurity company Netragard, once one of the best-known firms specializing in vulnerability research and the development of code to exploit them. He knows the problem well. In 2015, he sold one such capability to Italian spyware company Hacking Team. The company was later accused of supplying its products to undemocratic governments.
After that episode, Desautels left the industry. He has no intention of returning «unless a miracle produces an enforceable international framework that solves the problem». Otherwise, «the abuses will continue. You cannot control what law enforcement or one of these agencies does with these tools», he warns. These technologies can theoretically be identified through a kind of fingerprint and therefore tracked. But Desautels says such technical controls are of little use without binding rules.
Zapparoli Manzoni reaches a similar conclusion. «Ethical conduct, understood as proper risk management, is not difficult in itself», he says. The main limitation is that a company’s checks can work only before the software is sold. «Once the capability has been delivered, control is completely lost until abuses are uncovered».
There is also a strong subjective component. «These tools are necessary and, in the right hands, produce genuinely positive results», Desautels concludes.
«The problem is that the expression “right hands” is entirely subjective. It depends on which side you are on, which government you answer to and what you consider a legitimate target. Lawful interception in one country is political repression in another. The problem is fundamentally impossible to solve, because the technology itself is neutral and its ethics depend entirely on the people who possess it».
Rosita Rijtano is a 2026 Bertha Challenge Fellow. This investigation was carried out with the support of the Bertha Challenge Fellowship
Le inchieste e gli eventi di IrpiMedia sono anche su WhatsApp. Clicca qui per iscriverti e restare sempre aggiornat*. Ricordati di scegliere “Iscriviti” e di attivare le notifiche.