1 hr ago
Serbian Civil Society Targeted by Spyware Before Elections
A digital rights group says spyware secretly targeted at least 14 people in Serbia.
The people included students, activists and opposition politicians.
Spyware is software that can secretly watch or listen through a phone.
At least one phone was reportedly infected with Pegasus, and others with malware similar to NoviSpy.
One student said the software could turn on her phone’s camera and microphone.
The targeting happened around local elections that were important to student-backed opposition groups.
Researchers and legal experts said this kind of surveillance may violate privacy and Serbian law if it was not approved by a court.
No one has been identified as responsible, and Serbia’s government and the spyware company did not respond to Reuters’ requests for comment.
The SHARE Foundation said at least 14 Serbian civil society members were targeted with advanced spyware.
Those targeted included student activists, opposition politicians, activists and a local councilor.
At least one device was targeted with Pegasus, while two were infected with malware similar to NoviSpy.
The alleged targeting coincided with March local elections viewed as a test for student-backed opposition groups.
Researchers and rights experts called the surveillance invasive, but Reuters could not identify who was responsible.
- Who
- At least 14 members of Serbian civil society, including student activists, activists, opposition party members and a local councilor, were reportedly targeted; the SHARE Foundation and researchers documented the cases.
- What
- Advanced mercenary spyware, including Pegasus and malware similar to NoviSpy, was allegedly used to target their devices.
- Where
- Across Serbia, with the findings presented in Belgrade.
- When
- The targeting coincided with local elections in March; SHARE reported the infections after Apple threat notifications in August. The article also refers to Pegasus targeting between December 2025 and January 2026.
- Why
- SHARE said the targeting occurred as student-backed opposition groups organized for elections, but the person or organization responsible has not been determined.
Rights Groups and Researchers
Unresolved Responsibility and Company Position
Nature of the surveillance
Rights Groups and Researchers
SHARE, Amnesty International researchers and Citizen Lab described the spyware targeting as invasive and directed at Serbia’s student and pro-democracy movement.
Unresolved Responsibility and Company Position
No responsible party has been established publicly, and Reuters could not independently determine who carried out the alleged infections.
Legal authorization
Rights Groups and Researchers
Serbian legal expert Ana Toskic Cvetinovic said using such software without judicial authorization constitutes a crime under Serbian law and said there appeared to be no reasoned court decision known to her organization.
Unresolved Responsibility and Company Position
The Serbian government did not respond to Reuters’ request for comment, so its position on authorization was not provided.
Pegasus sales and safeguards
Rights Groups and Researchers
Researchers raised concerns about the use of Pegasus against civil society members, and the United States blacklisted NSO Group in 2021 over rights-abuse concerns.
Unresolved Responsibility and Company Position
NSO Group has said it sells only to governments and said in a January report that it would work with clients to address potential violations; the company did not respond to Reuters’ request for comment.
Key facts
- Reported targets
- At least 14 people across Serbian civil society
- Targeted groups
- Student movement members, activists, opposition parliament members and a local councilor
- Spyware identified
- At least one device with Pegasus and at least two with malware similar to NoviSpy
- Election context
- The targeting coincided with March 29 local elections in 10 municipalities
- Apple notifications
- Apple notified targeted users on August 13 and said it had sent notifications in 110 countries
- Investigation
- The SHARE Foundation, Amnesty International’s security lab and Citizen Lab examined the infections
- Responsibility
- Reuters could not determine who was responsible; the Serbian government and NSO Group did not respond to requests for comment
Quotes
Milica
A Serbian student activist who said her phone was infected
“They could access the microphone and camera on the phone and turn them on while we shower or speak about private matters. It’s not normal to do that; it’s not normal that we don’t have the right to privacy.”
theprint.in
Donncha Ó Cearbhaill
Head of Amnesty International’s security lab
“These new forensic findings show that Serbian student activists continue to be targeted with invasive spyware.”
theprint.in
John Scott-Railton
Senior researcher with Citizen Lab
“reveal that Serbia’s peaceful pro-democracy movement is being aggressively targeted with mercenary spyware ahead of key 2026 election cycles.”
theprint.in



