Digital investigators say at least 14 people were subjected to sophisticated surveillance in the country’s largest documented spyware campaign, raising fresh concerns over political monitoring ahead of national elections

Serbia is facing renewed scrutiny over the use of powerful commercial spyware after digital-rights researchers confirmed that at least 14 students, activists and opposition figures were targeted with advanced surveillance tools in what they describe as the largest documented wave of spyware attacks in the country to date.
The cases include members of the student-led protest movement that has emerged as one of the most significant political challenges to President Aleksandar Vučić’s government, as well as an opposition member of parliament and a local councillor. The Serbian authorities have denied involvement and dismissed allegations of politically motivated surveillance.
The investigation was led by Serbia’s SHARE Foundation, which said the attacks took place from the beginning of 2026 and intensified around a politically sensitive period that included local elections on March 29.
The organisation began examining a new cluster of cases after 12 individuals approached its digital-forensics specialists in August following warnings from Apple that their devices had been targeted by mercenary spyware. Two additional NoviSpy infections were subsequently identified, bringing the documented total to at least 14.
The findings are particularly significant because they involve more than one surveillance platform.
In one of the most serious cases, researchers from the University of Toronto’s Citizen Lab confirmed that the iPhone of a member of Serbia’s student protest movement had been successfully infected with Pegasus, the highly sophisticated spyware developed by Israel’s NSO Group.
Forensic evidence showed that the device was compromised through an iMessage “zero-click” exploit, meaning the victim did not need to click a malicious link, open an attachment or take any other action for the infection to occur. Citizen Lab identified high-confidence evidence of compromise between December 2025 and January 2026.
Pegasus is capable of effectively transforming a smartphone into a remote surveillance device. Once installed, it can potentially access messages, contacts, photographs, files and application data while also enabling covert access to a device’s microphone and camera.
That level of access makes commercial spyware qualitatively different from conventional hacking tools: an infected phone can become a mechanism for monitoring not only the victim but also journalists, activists, political organisers and confidential sources with whom that individual communicates.
Citizen Lab has not publicly attributed the Pegasus infection to the Serbian government, and investigators have stressed that forensic confirmation of the software itself does not establish who ordered the attack.
That distinction is important.
While several victims suspect Serbian state involvement because of their political activities and the timing of the attacks, researchers have so far not produced direct technical evidence showing which operator deployed Pegasus against them.
The Serbian government and intelligence services have strongly rejected suggestions that they were responsible.
But the controversy is complicated by the appearance of a second surveillance platform with much closer links to Serbia.
NoviSpy returns
SHARE Foundation investigators also detected a new version of NoviSpy, an Android surveillance tool first publicly exposed in 2024.
Amnesty International previously documented what it described as the routine use of NoviSpy and other digital-surveillance techniques against Serbian activists and members of civil society. Its investigation alleged that the software had been installed on some devices after phones were temporarily taken by police or security officials.
According to Amnesty, NoviSpy can obtain highly sensitive information from infected devices and provide access to personal communications and stored data.
The 2024 investigation also documented the use of mobile-forensics equipment produced by Cellebrite, technology commonly employed by law-enforcement agencies to unlock or extract information from smartphones.
Amnesty argued that Serbia’s use of these technologies formed part of a broader system of digital repression targeting journalists, environmental activists and protest organisers.
Serbian officials disputed those allegations at the time.
The reappearance of NoviSpy in the latest cases has nevertheless intensified concern among digital-rights researchers because it suggests that surveillance capabilities documented two years ago may still be operational.
Student movement becomes a target
The political context surrounding the attacks has also drawn attention.
Serbia has experienced sustained anti-government demonstrations since late 2024, when the collapse of a railway-station canopy in Novi Sad killed multiple people and triggered public anger over corruption, accountability and the quality of state institutions.
University students became one of the driving forces behind the demonstrations.
What began as protests demanding accountability gradually evolved into a broader movement challenging the political system dominated by Vučić and the Serbian Progressive Party.
That movement has since developed into one of the most organised sources of political opposition in the country.
The discovery that members of the student network were among those targeted with advanced spyware therefore raises serious questions about whether surveillance technology is being used to map political organisations, identify leadership structures or obtain access to internal communications.
SHARE Foundation said all of the documented victims belonged to groups critical of the government or opposition political structures.
The timing is also sensitive because Serbia is heading toward parliamentary elections expected in October.
Some analysts and activists fear that the surveillance activity recorded earlier this year may have been connected to preparations for the election period, although that hypothesis has not been proven.
Government rejects accusations
Officials close to Vučić have denied involvement and characterised the allegations as politically motivated.
Serbia’s intelligence agency has rejected claims that it used Pegasus against protesters or opposition figures, while senior government officials have dismissed the spyware revelations as attempts to damage the administration ahead of elections.
The government’s position is that evidence identifying Pegasus or NoviSpy on a device does not demonstrate who deployed it.
That argument reflects a genuine technical challenge in spyware investigations.
Commercial surveillance infrastructure is often deliberately designed to conceal the identity of the operator. Investigators may be able to determine what malware infected a device, when the compromise occurred and which exploit was used without being able to conclusively identify the government agency or organisation controlling the operation.
The attribution problem is therefore central to the Serbian controversy.
The existence of the spyware infections is supported by forensic evidence. The identity of the actor behind every case is not.
Pegasus under renewed scrutiny
The Serbian revelations have also returned NSO Group to the centre of the global debate over commercial surveillance technology.
Pegasus has been identified on devices belonging to journalists, dissidents, lawyers, opposition politicians and human-rights defenders in multiple countries.
NSO Group has repeatedly said that its products are intended exclusively for authorised government agencies investigating serious crime and terrorism, and that customers are required to follow legal and contractual restrictions.
The company has nevertheless faced years of international criticism over allegations that governments have used Pegasus against political opponents and members of civil society.
The United States placed NSO Group on a Commerce Department blacklist in 2021, citing concerns that its technology had been used maliciously against officials, journalists and activists.
The discovery of another confirmed Pegasus infection involving a pro-democracy activist therefore carries implications well beyond Serbia.
Surveillance without a click
The technical sophistication of the attack is one of its most concerning features.
The Serbian student’s phone was compromised with a zero-click exploit delivered through iMessage.
Traditional phishing attacks depend on deception: the victim must normally click a link, download a document or enter credentials into a fraudulent website.
Zero-click exploits eliminate that requirement.
A specially crafted message or data packet can exploit a vulnerability automatically, infecting the phone before the user realises anything has happened.
This makes defensive behaviour alone insufficient. Even highly security-conscious activists can potentially be compromised if attackers possess an undisclosed vulnerability in the device’s operating system or messaging platform.
Apple has increasingly responded to such campaigns by sending threat notifications to users it believes have been individually targeted by mercenary spyware.
Those alerts played a decisive role in exposing the latest Serbian cases.
A wider problem for European democracy
The controversy also carries consequences for Serbia’s relationship with the European Union.
Serbia remains an EU membership candidate, and democratic institutions, media freedom, judicial independence and rule-of-law reforms are central elements of the accession process.
Evidence that civil-society figures or political opponents are being subjected to sophisticated digital surveillance is therefore likely to deepen existing European concerns about democratic standards in the country.
Amnesty International’s most recent assessment of Serbia already says protesters, journalists and civil-society organisations have faced intimidation, harassment and unlawful surveillance amid attempts by authorities to contain widespread dissent.
The latest spyware cases reinforce those concerns at a particularly sensitive political moment.
They also illustrate a growing challenge for democracies around the world: surveillance capabilities once associated with the intelligence services of major powers are increasingly commercially available to governments with sufficient financial resources.
That shift has dramatically lowered the technological barrier to conducting highly intrusive surveillance.
The unanswered question
Forensic researchers have established that sophisticated spyware was used against members of Serbia’s civil society.
They have confirmed a Pegasus infection.
They have identified new NoviSpy infections.
And they have documented a pattern involving students, activists and opposition politicians during a period of escalating political tension.
What remains unresolved is the most politically consequential question: who authorised the surveillance?
Until investigators can answer that conclusively, the Serbian government can point to the absence of direct attribution while victims can point to the extraordinary political pattern linking those targeted.
The dispute is therefore unlikely to disappear.
Ahead of Serbia’s elections, the phones of political activists have become another arena in the country’s struggle over power, accountability and democratic legitimacy.
And the revelations underline a fundamental problem of modern political surveillance: the most powerful spying tools can operate almost invisibly, leaving victims unaware that someone may already be listening.



