Researchers from SHARE Foundation, an EDRi member organisation, have documented spyware infections targeting a minimum of 14 individuals across Serbia beginning in 2026. Those affected span student movement participants, civil society workers, an opposition parliamentarian and a municipal official. The revelations emerged as Serbia's pro-democracy movement faces intensifying state pressure. Simultaneously, the European Union's inaction on surveillance technology within its own member states undermines its standing to demand reform from candidate nations.
Student movement caught in spyware net ahead of elections
On 15 September, tens of thousands gathered in Belgrade for the student movement's "Victors' March", marking the formal registration of what has become a major political force ahead of parliamentary elections scheduled for late October. The mobilisation represents a shift from street protests—which have dominated the past two years—into electoral competition, with polling suggesting the movement could challenge Aleksandar Vucic's ruling SNS party. Yet this political breakthrough came shadowed by revelations that numerous student activists had been compromised through state-deployed surveillance tools.
What the forensic evidence shows
During August 2026, twelve individuals approached SHARE Foundation's digital forensics team after receiving Apple notifications indicating they had been targeted with "mercenary spyware"—software created by commercial vendors. SHARE's technical analysis identified two further infections running a newly discovered variant of NoviSpy, an Android-based spyware first documented in Serbia in 2024. Both Citizen Lab and Amnesty International's Security Lab independently verified SHARE's conclusions.
Citizen Lab determined that a student activist's device carried Pegasus, a spyware product manufactured by NSO Group. The phone was compromised via a zero-click iMessage vulnerability, requiring no user interaction to execute the attack.
Amnesty International confirmed a separate NoviSpy infection on another device. Notably, the phone had been seized during police interrogation of its owner, and the spyware was installed while in Serbian authorities' custody.
A third case demonstrated direct state involvement: the same spyware appeared on a different phone shortly after private Viber communications from that device were broadcast on the state-aligned television outlet "Informer". Ongoing forensic work is examining this incident further.
These incidents build on earlier documented patterns. In late 2024, Amnesty International and SHARE Foundation identified NoviSpy on devices belonging to individuals who had undergone police questioning. Their investigation revealed the spyware was configured to transmit data to a server controlled by Serbia's Security Information Agency (BIA), with installation occurring after device seizure using Cellebrite, a forensic extraction platform accessible to Serbian law enforcement. In March 2025, Amnesty International separately documented two journalists being targeted with Pegasus.
Following these earlier cases, EDRi and 60 partner civil society groups urged EU bodies to launch investigations, provide victim support and address state spyware deployment. Two years on, the underlying issues persist while documented targets have multiplied and additional spyware variants have surfaced.
Spyware as a rule of law indicator
Spyware does not exist in isolation. The timing and selection of targets reveal its function within broader patterns of authoritarianism and suppression targeting political rivals and civic participation. It represents one particularly potent mechanism through which authorities can dismantle democratic functioning.
Those identified by SHARE—students, organisers and opposition figures—were predominantly active in local elections held in May 2026. Phone access grants authorities visibility into communications, contacts, movements and organisational networks, enabling state actors to orchestrate character attacks or extract blackmail material. Even when state involvement becomes public, the deterrent effect ripples immediately through the political sphere. In contexts of democratic erosion like Serbia, this directly constrains the operational capacity of opposition movements and civil society actors.
This reality positions spyware as central to EU rule of law assessments. Governments cannot authentically claim commitment to fundamental rights while deploying technology inherently designed for abuse. Spyware misuse has become a European pattern, adopted by administrations across the political spectrum—from Poland's far-right governments to Spain's socialist leadership.
Serbian authorities, including the judiciary, bear responsibility for investigating these cases and providing remedies. Yet the EU shares this obligation. As an accession candidate, Serbia's rule of law record shapes its path toward membership. The European Commission has repeatedly flagged concerns about shrinking democratic space, patronage networks, press freedom and political deterioration. Yet the latest spyware findings demonstrate that years of repeated warnings have yielded no resolution. The Commission should explicitly incorporate spyware use into democratic backsliding assessments and tie Serbia's accession progress to an immediate cessation of state spyware operations. This aligns with a demand from 29 Members of the European Parliament following recent surveillance revelations.
Europe's unresolved surveillance crisis
What standing does the EU possess to demand Serbian accountability when it tolerates widespread spyware abuse within member states?
Despite repeated scandals across EU countries, the Commission has systematically disregarded recommendations from the PEGA Committee, the European Parliament body that investigated surveillance spyware misuse. No action has been taken to constrain the proliferation of spyware vendors operating within or from Europe, nor to establish victim compensation mechanisms or future rights protections.
This contradiction cuts to the heart of the EU's identity. The Union simultaneously enables the spyware industry—hosting a robust market and abandoning hundreds of victims—and presents itself as a rule of law project. Yet the same institutions demanding that candidate countries implement safeguards against arbitrary state power have declined meaningful intervention when identical abuses occur within member borders. This inconsistency corrodes the EU's credibility as a rule of law authority and, more fundamentally, weakens its own democratic legitimacy. The longer the Commission permits member state violations to proceed without consequences, the stronger the incentive for continued rights violations—whether through spyware or other repressive tools—across both the Union and candidate countries.
The pattern is already entrenched. Spyware victims across Europe encounter identical barriers: state invocations of national security or confidentiality; vendors leveraging the single market to operate and export freely while constructing opaque corporate hierarchies; and victims navigating hostile judicial systems where proving an attack occurred remains nearly impossible. Meanwhile state actors—whether in Spain, Italy or Hungary—simply deny involvement or ignore inquiries entirely.
The EU possesses immediate tools. It can exclude spyware vendors from EU funding and procurement. It can launch infringement cases against member states that have illegally deployed spyware against citizens. It can establish meaningful victim remedies. It can also integrate spyware into rule of law evaluations for both member states and candidates, rather than treating each scandal as a discrete incident that "deeply concerns" the Commission.
The Serbian situation crystallises what is at stake. The EU should condemn spyware abuse and leverage its influence to hold Serbian officials accountable. But if Commission demands on Serbia are to carry weight, action must follow when identical rights violations occur within the Union. The EU cannot defend the rule of law internationally while permitting its own spyware crisis to fester unaddressed.



