GBAF Logo
Global Banking & Finance Awards® 2026 Nominations open, free to enter Nominate now →
More than a dozen Serbians targeted with mercenary spyware, digital rights group finds - Finance news and analysis from Global Banking & Finance Review
Finance

More than a dozen Serbians targeted with mercenary spyware, digital rights group finds

Published by Global Banking & Finance Review

Posted on September 3, 2026

5 min read

· Last updated: September 3, 2026

Add as preferred source on Google

Serbia Faces Largest Recorded Spyware Attack Before Local Elections

Spyware Targeting of Serbian Civil Society Ahead of Elections

By AJ Vicens

Sept 2 (Reuters) - At least 14 people across Serbia's civil society were targeted with advanced spyware ahead of local elections in March, the digital rights group SHARE Foundation said on Wednesday.

The wave of spyware infections, discovered in August after Apple notified people in 110 countries that they had likely been victims of mercenary spyware, marks the largest documented wave of such infection in Serbia to date, the SHARE Foundation said in a statement. 

The incident offers a window into the use of powerful and invasive spyware aimed at students and political opposition members amid contentious elections, with national polls looming.

Confirmed Targets and Spyware Used

Confirmed cases of targeting include members of a student movement, activists, opposition party members in parliament and a local councilor, the group said. At least one device was targeted with Pegasus, made by Israeli company NSO Group, while at least two devices were targeted with malware similar to NoviSpy, which was first exposed by Amnesty International in Serbia in December 2024.

Personal Accounts of Surveillance

At a news conference in Belgrade, a student activist who only identified herself as Milica said she received a notification her phone was infected in mid-August.

"They could access the microphone and camera on the phone and turn them on while we shower or speak about private matters. It's not normal to do that; it's not normal that we don't have the right to privacy," she said.

Official Responses and Denials

Reuters could not determine who was responsible for the alleged infections. NSO has said it only sells to governments.  

Speaker of parliament Ana Brnabic, a ranking member of the ruling Serbian Progressive Party (SNS), dismissed the students' claims that they had been spied on. 

"Absolutely not," she told Euronews Serbia TV in an interview on Wednesday. "I do not believe a single word they've (students, SHARE foundation) said."

The NSO Group did not immediately respond to requests for comment. In a report published in January, the NSO Group said it would work with clients to address potential violations. 

“In cases of serious or repeated noncompliance, NSO may suspend or terminate the relationship,” the company said.

Impact on Local and National Elections

Spyware Incidents During Local Elections

LOCAL ELECTIONS SEEN AS TEST

In one incident, a device associated with a member of the student movement was targeted with a zero-click version of Pegasus, meaning it did not require user interaction to deploy on the device. NoviSpy was found on the phone of a student movement member whose device had previously been taken away during police questioning, according to SHARE. 

The targeting coincided with the March 29 local elections held in 10 municipalities, according to SHARE, which said they were seen as a test of how student-backed political opposition groups could organize and compete against ruling party politicians. The digital targeting could be a preview of similar actions for parliamentary elections scheduled for October, the group said.

Expert Analysis and Legal Implications

International and Local Watchdog Perspectives

"These new forensic findings show that Serbian student activists continue to be targeted with invasive spyware,” said Donncha Ó Cearbhaill, head of Amnesty International's security lab, which helped investigate the infections.

In Belgrade, Ana Toskic Cvetinovic, with the Partneri Srbija rights watchdog and a legal expert, said that use of such software without authorisation from the court constitutes a crime under Serbian laws. 

"The Criminal Procedure Code envisions the situations in which secret surveillance is allowed ... there must be a reasoned court decision. To our knowledge, there is no such thing here," said Toskic Cvetinovic.

“Our constitution guarantees the right to the protection of personal data," she said.

Technical Findings and Security Measures

The Pegasus implant was put on at least one student's phone between December 2025 and January 2026, according to Bill Marczak, a senior researcher at the Citizen Lab, a Canadian internet watchdog group which is also investigating the infections. Apple's security updates have since neutralized the spyware, he added.

John Scott-Railton, another senior researcher with Citizen Lab, said his organization's findings and Apple's notifications "reveal that Serbia's peaceful pro-democracy movement is being aggressively targeted with mercenary spyware ahead of key 2026 election cycles."

Broader Context and International Response

NSO Group and Global Concerns

NSO was blacklisted by the U.S. government in 2021 over concerns about rights abuses. In 2025, an American investment group acquired the company, although it is still operating out of Israel and under Israeli regulations.

Apple's Role in Notification and Security

In a statement, Apple said it sent threat notifications on August 13 to targeted users in 110 countries, adding that to date, it has notified users in more than 150 countries overall.

(Reporting by AJ Vicens in Detroit, and Ivana Sekularac and Aleksandar Vasovic in Belgrade; Editing by Thomas Derpinghaus)

Key Takeaways

  • At least 14 individuals were targeted in a wave of spyware infections, confirmed via Apple threat alerts and forensic analysis by SHARE Foundation, Citizen Lab and Amnesty International’s Security Lab, ahead of the March 29, 2026 local elections (sharefoundation.info).
  • Targets included students, activists, an opposition MP and a local councilor; infections involved Pegasus zero‑click exploit and a new version of NoviSpy installed during police detentions, misusing Cellebrite forensic tools (sharefoundation.info).
  • Use of such spyware attacks without judicial warrant constitutes a criminal offense under Serbian law; the timing suggests digital surveillance being used as a test ahead of October parliamentary elections (sharefoundation.info).

References

Frequently Asked Questions

Who was targeted by spyware in Serbia?
Activists, student movement members, opposition party members in parliament, and a local councilor were targeted.
Which spyware was used in the Serbian infections?
Devices were targeted with Pegasus by NSO Group and malware similar to NoviSpy.
When did the Serbian spyware infections take place?
The infections occurred ahead of local elections in March, and were discovered in August.
What protections does Serbian law provide against unauthorized surveillance?
Serbian law requires court authorization for surveillance; unauthorized use of such software is a crime.
How did Apple contribute to uncovering the spyware infections?
Apple notified people in 110 countries, including Serbia, that they may have been targeted by mercenary spyware.

Tags

Related Articles

More from Finance

Explore more articles in the Finance category