Serbia’s spyware scandal is also the EU’s problem
At least 14 people in Serbia have been targeted with spyware since the beginning of 2026, according to new findings by EDRi member SHARE Foundation. The targets include members of the student movement, activists, a member of parliament from the opposition party and a local councillor. These findings comecame to light amid growing pressure on Serbia’s pro-democracy movement. The EU’s failure to address spyware at home undermines its credibility in demanding accountability from Serbia.
Spyware threatens Serbia’s burgeoning student movement right before elections
On 15 September, thousands of people joined Serbia’s student movement in Belgrade for what organisers called the “Victors’ March”, as the movement formally registered to participate in the country’s upcoming parliamentary elections scheduled for late October. The march marked a new phase in the mobilisation that has brought students to the centre of Serbia’s political opposition after months of protests demanding accountability, democratic reforms and early elections.
After almost two years of protests in the streets, the students are now moving into institutional politics, and polls show that they stand a chance against the current ruling party, Aleksandar Vucic’s SNS. However, two weeks before the elections were called, a scandal shook the public opinion in the country and abroad: many members from the student movement had been targeted by Serbian authorities with spyware.
What happened?
In August 2026, 12 people contacted SHARE Foundation’s digital forensics experts after receiving Apple threat notifications warning that they had been targeted with “mercenary spyware”, that is, spyware developed by private companies. SHARE’s forensic analysis later confirmed two additional infections with a new version of NoviSpy, the Android spyware first identified in Serbia in 2024. Citizen Lab and Amnesty International’s Security Lab independently confirmed SHARE’s findings.
Citizen Lab confirmed that the phone of a student movement activist was infected with Pegasus, a spyware developed by NSO Group. The device was compromised through a zero-click exploit targeting iMessage, meaning that the victim did not need to click a link or take any action for the attack to succeed.
Amnesty International confirmed another infection with the new version of NoviSpy. In this case, the phone had previously been confiscated when its owner was brought in for police questioning. The spyware was installed while the device was in the hands of Serbian authorities.
In another case demonstrating the clear connection of Serbian authorities to the targeting, the same spyware was detected on a different device after private Viber messages from the phone were disclosed live on Serbian state-aligned television channel “Informer”. Further forensic analysis is ongoing.
These cases add to evidence of the use of spyware against journalists, activists and members of civil society in Serbia. In late 2024, Amnesty International and SHARE Foundation documented NoviSpy on devices belonging to people who had been subjected to police questioning. Researchers found that the spyware was configured to send data extracted from infected phones to a server whose IP address belonged to Serbia’s Security Information Agency (BIA). The spyware had been installed after devices were confiscated, using Cellebrite, a digital forensics tool available to Serbian authorities. In March 2025, Amnesty International also documented that two journalists had been targeted with Pegasus.
At the time, EDRi and 60 other civil society organisations called on EU institutions to demand an investigation into the cases, ensure remedies for victims and address the use of spyware by Serbian authorities.
Two years later, the same concerns remain, while the number of documented targets has increased and new spyware has been identified.
Countless scandals, one conclusion: spyware is a rule of law issue
The Serbian case is a clear example of how spyware does not operate in a vacuum. The timing of an attack and the people targeted are essential to understanding the reason behind it, and it usually fits a wider pattern of authoritarianism and repression against political opponents or civic space. Spyware is one more tool in the authorities’ arsenal for undermining democratic life, but a particularly powerful one.
The targets identified by SHARE include students, activists and opposition politicians, most of them actively involved in the local elections in May 2026. Access to their phones can expose their communications, contacts, movements and networks, making it possible to identify who they organise with or what they are planning, making it possible for the state to organise smear campaigns against them or to blackmail them. Even if the state’s involvement in spying on activists is revealed, the chilling effect is immediate on anyone active in political life. In a context of growing democratic backsliding, like in Serbia, it’s needless to say that this can directly – and critically – affect the ability of opposition actors and civil society to operate.
This is why spyware belongs at the centre of the EU’s rule of law debate. A state cannot credibly claim to respect fundamental rights while using this highly intrusive technology that is, by design, prone to abuse. It’s been a European trend to use spyware against political opponents, activists or journalists. And this candy has proven to be sweet to any government, from far-right Poles to socialist Spaniards.
Of course, the Serbian authorities, including its judiciary, have a responsibility to investigate these cases and provide effective remedies to those targeted. But the EU also has a responsibility.
Serbia is an EU candidate country, and the rule of law is one of the foundations of the accession process. The European Commission has repeatedly raised concerns about shrinking civic space, clientelism, attacks against journalists and the deterioration of the political environment in Serbia. Yet the latest spyware findings show that the concerns raised repeatedly for years have not been resolved. The Commission should explicitly include the use of spyware in the assessment of democratic backsliding, and condition progress in Serbia’s accession process on an immediate halt to the use of spyware by security agencies and other state authorities. This is in line with the demand by 29 Members of the European Parliament to the Commission after the most recent cases of spyware abuse came to light.
The EU’s own spyware problem
How can the EU demand any accountability from Serbia when it is not doing anything against its own spyware problem?
Despite the innumerable scandals across EU countries, the Commission’s approach has been to totally ignore all the recommendations by the PEGA Committee in the European Parliament which investigated the abuse of surveillance spyware. Nothing has been done to stop the proliferation of companies operating in and from Europe, nor to provide meaningful remedies to victims or establish a framework to protect people’s rights in the future.
This is particularly problematic for the EU because the Union is both a major enabler of the spyware industry – with a thriving market and hundreds of victims abandoned by national authorities – and a political project built around the rule of law. But the same institutions that expect candidate countries to establish safeguards against arbitrary state power have yet to take meaningful action when those abuses happen within the Union itself. This double standard undermines the EU’s credibility as a rule of law actor and, more importantly, erodes its own democratic foundations. The longer the Commission allows these violations in Member States to go on without consequences, the stronger the incentive to keep violating fundamental rights – whether through spyware or other forms of repression – both in the EU and in candidate countries.
The consequences are already visible. Across Europe, spyware victims repeatedly run into the same obstacles: authorities invoke national security or secrecy rules; companies are using the EU single market to thrive and export and they freely create complex corporate structures and networks of shell companies; and victims are left by themselves to seek remedies in a hostile judicial system in which even proving that an attack took place is nearly impossible. Meanwhile the state authorities – be it Spain, Italy or Hungary – can simply deny it – or even ignore it.
The EU has tools to take immediate action against this. It can ban spyware vendors from getting any EU funding and procurement, it can initiate infringement procedures against Member States that have illegally used spyware against their citizens, and it can ensure that victims have meaningful routes to remedy. It can also make spyware an explicit part of its rule of law assessments, both for Member States and candidate countries, rather than treating each new scandal as an isolated incident that “deeply concerns” the Commission.
The Serbian case makes clear what is at stake. The EU should condemn spyware abuse, and use its leverage to hold the Serbian authorities accountable. But if the Commission wants its demands on Serbia to carry any weight, it also needs to act when the same rights are violated within the Union. The EU cannot credibly defend the rule of law abroad while allowing its own spyware problem unresolved.
Contribution by: Aljosa Ajanovic Andelic, Policy Advisor, EDRi & Andrijana Ristic, Policy Advisor, SHARE Foundation
