Atlanta: Canadian cybersecurity company Magnet Forensics Inc. has filed a lawsuit against a former contractor, alleging he stole and disclosed confidential trade secrets related to a previously unknown iPhone security flaw. The legal action centres on an alleged “zero-day” vulnerability affecting Apple’s A12 and A13 chips, which the company claims was shared with rival cybersecurity firm Paradigm Shift Technology S.L.
The lawsuit, filed in the US District Court for the Northern District of Georgia on July 7, accuses former contractor Mario Del Gaudio of breaching contractual obligations by allegedly disclosing sensitive exploit research that Magnet Forensics had developed for government and law enforcement customers. The case highlights the growing competition within the cybersecurity industry, where previously undisclosed software vulnerabilities are considered highly valuable assets.
Lawsuit centres on alleged disclosure of iPhone zero-day vulnerability
According to the complaint, Magnet Forensics developed and used a previously unknown security flaw affecting Apple’s A12 and A13 processors to help authorised government agencies gain access to data stored on locked iPhones during criminal investigations.
The company alleges that Del Gaudio worked extensively on the vulnerability while contracted by Magnet. After leaving the company, he allegedly collaborated with Paradigm Shift Technology on research involving the same flaw.
Magnet claims the vulnerability was later publicly disclosed through a blog post published by Paradigm Shift Technology, making the previously secret exploit available to the wider cybersecurity community.
The company argues that the disclosure significantly reduced the commercial value of the exploit by alerting Apple to the security issue, potentially allowing the company to develop and distribute a software patch.
What is a zero-day vulnerability?
A zero-day vulnerability is a previously unknown flaw in software or hardware that has not yet been identified by the vendor responsible for fixing it. Because developers have had “zero days” to address the issue, such vulnerabilities can often be exploited before security updates become available.
Cybersecurity companies discover these flaws through advanced security research. Some firms report them directly to technology companies under responsible disclosure programmes, while others develop exploit tools for authorised government and law enforcement agencies operating under legal frameworks.
Zero-day exploits are considered among the most valuable assets in cybersecurity because they can bypass existing security protections until patches are released.
Magnet claims disclosure caused financial harm
In its lawsuit, Magnet Forensics alleges that publishing details of the vulnerability caused “irreparable harm” to its business.
The company says the exploit formed part of specialised forensic tools used by law enforcement agencies to recover digital evidence from iPhones that would otherwise remain inaccessible.
Once technical details became public, Apple was alerted to the flaw and could potentially fix it through software updates, reducing the exploit’s usefulness and commercial value for Magnet’s customers.
The lawsuit seeks legal remedies against both Del Gaudio and Paradigm Shift Technology for the alleged misappropriation of trade secrets and breach of contractual obligations.
Neither the former contractor, his legal representatives nor Paradigm Shift Technology had publicly responded to the allegations at the time of reporting.
Apple’s A12 and A13 chips at the centre of the dispute
The disputed vulnerability reportedly affects Apple’s A12 and A13 chipsets, which power several iPhone and iPad models introduced between 2018 and 2020.
The lawsuit does not indicate whether the alleged vulnerability has already been patched by Apple or whether it continues to affect supported devices.
Apple has not publicly commented on the litigation or confirmed any details regarding the alleged security flaw.
As is common practice, technology companies typically avoid discussing undisclosed security vulnerabilities until investigations are completed and any necessary security updates have been issued.
Magnet Forensics serves global law enforcement agencies
Magnet Forensics is a Canadian digital investigations company specialising in forensic software used by police departments, government agencies and corporate investigators.
According to court filings, the company serves more than 6,000 public and private sector customers across 100 countries.
The business was acquired by private equity firm Thoma Bravo in 2023 in a deal valued at approximately $1.3 billion, reflecting the growing demand for digital forensic and cybersecurity solutions worldwide.
Its software enables authorised investigators to extract, recover and analyse digital evidence from smartphones, computers and cloud services during criminal investigations.
Case reflects growing competition in cybersecurity
The lawsuit underscores the increasing value of offensive cybersecurity research and zero-day vulnerabilities, particularly as governments continue investing heavily in digital investigation capabilities.
The dispute also follows other high-profile cases involving the alleged theft of sensitive hacking tools. In 2025, a former government contractor working for military contractor L3Harris Technologies pleaded guilty after stealing and selling offensive cyber capabilities to a Russian broker, highlighting the legal and national security risks associated with proprietary cybersecurity technologies.
Industry experts note that ownership disputes over zero-day research are becoming more common as cybersecurity firms compete to develop advanced digital investigation tools for government clients.
The outcome of the Magnet Forensics lawsuit could have broader implications for intellectual property protection, employee confidentiality agreements and the handling of sensitive cybersecurity research within the industry.
