14 students and opposition politicians targeted by spyware in Serbia

EDRi member SHARE Foundation has confirmed that at least 14 people in Serbia were targeted with advanced spyware since the beginning of 2026 – the largest documented wave of such surveillance in the country to date. Those targeted include members of the student movement, activists, a member of parliament, and a local councilor, all from opposition parties. The timing the of spyware attacks coincides with the local elections held on March 29, 2026.

By SHARE Foundation (guest author) · September 2, 2026

What happened?

In August 2026, 12 people contacted SHARE’s digital forensics experts after receiving a warning on their phones that they had been targeted in a spyware attack. Apple issues these warnings with high confidence when a user has been targeted by mercenary spyware. SHARE Foundation’s forensic analysis later confirmed two more infections – with a new version of NoviSpy, spyware first discovered in Serbia in 2024. Spyware of this kind can access everything on a device – messages, contacts, photos, app data, and other files – and can secretly record the screen or activate the microphone and camera. Its use is illegal in Serbia.

Two global digital forensics labs – Citizen Lab at the University of Toronto and Amnesty International’s Security Lab – independently confirmed SHARE Foundation’s findings.

Citizen Lab investigators confirmed that the phone belonging to the student movement member who received the warning was infected with Pegasus, a spyware developed by the Israeli company NSO Group. The device was hacked with a zero-click exploit targeting iPhone application iMessage. This means that the device was infected remotely, without any knowledge or interaction by the user.

The remaining 11 devices received Apple Threat Notifications, a high-confidence indicator that they had been targeted with mercenary spyware and should therefore be treated as presumed infected.

“Our forensic findings, and this fresh wave of Apple Threat Notifications reveal that Serbia's peaceful pro-democracy movement is being aggressively targeted with mercenary spyware ahead of key 2026 election cycles."

John Scott-Railton, Senior Researcher at The Citizen Lab.

Amnesty International confirmed the infection with the new version of NoviSpy spyware on the phone of a student movement member whose phone had previously been confiscated when he was brought in for police questioning.

“The forensic findings by SHARE prove that Serbian students continue to be targeted with invasive Android spyware tools, installed while detained by Serbian authorities. The latest 2026 case also reveals a new Android spyware, similar in functionality to NoviSpy, but newly built with specific efforts taken to avoid detection by security experts.”

Donncha Ó Cearbhaill, Head of Amnesty International's Security Lab

The same spyware was detected on another device, after private Viber messages from that phone were disclosed live on the Serbian State-aligned TV Informer. Further forensic analysis is ongoing, with support from digital forensics experts at Citizen Lab and Amnesty International.

A gross abuse of technology

Intrusive spyware varies by infection method and level of technical sophistication. Pegasus is military-grade spyware, sold exclusively to states and state agencies. It can be installed remotely, with no interaction from the user required, and its key components – the control interface and the servers storing collected data – are typically based in the client country, at the agency’s own premises or headquarters. By contrast, installing the newly discovered spyware requires physical access to the device.

The use of such intrusive technologies represents a gross violation of the right to privacy and heightens the “chilling effect” among citizens, which directly affects related rights such as freedom of expression and movement, as well as a broader range of political freedoms.

The targeting of students, an MP, and a local councilor is especially troubling: political espionage strikes directly at the equality of political actors and the integrity of the electoral process. Democracy depends on elected representatives being free to communicate, organise, and hold those in power to account – without fear of secret, unlawful surveillance. If they aren’t protected from such attacks, other citizens can hardly expect their own privacy and political freedoms to be respected. Practices like this erode trust in institutions, and in the very possibility of free political action.

By its function and purpose, spyware qualifies as a computer virus – that is, a program or set of commands that acts on other programs or data within a computer or network – and introducing it constitutes a criminal offense under Serbia’s Criminal Code. Using spyware means gaining unauthorized access to everything on a device – deliberately causing harm not only to the targeted person, but to everyone else whose data happens to be stored on that device.

In late 2024, Amnesty International published a report on the forensic analysis of infected devices belonging to users in Serbia – an analysis the SHARE Foundation also participated in. A previously unknown type of spyware was uncovered, which researchers named NoviSpy. NoviSpy was configured to send data stolen from phones to a server whose IP address belongs to Serbia’s Security Information Agency (BIA). It was also found that the spyware had been installed on devices – confiscated during police interviews with targeted journalists, activists, and civil society members – by misusing Cellebrite, a digital forensics tool Serbia’s Ministry of Interior received as a donation from Norway. Criminal complaints filed in these cases are still pending in court.

The upcoming elections further heighten an already tense political climate, amid growing physical and digital repression of political dissent, including students, journalists, and activists. This digital dimension builds on existing tactics of intimidation, arrest, and detention on baseless charges.

What can citizens do to protect themselves?

Apple (iOS) and Google (Android) periodically notify users if their device has been targeted by spyware. Users receiving such a notification, should contact a trusted expert organisation without delay – they can help collect and analyse the relevant data. Beyond the general advice to keep devices and apps updated and avoid content from unknown sources and suspicious links, citizens at higher risk – students, activists, journalists, and opposition politicians – are advised to enable advanced security features on their devices (Lockdown Mode for iOS and Advanced Protection for newer Android devices).