From the archive Report
Researchers find spyware on phones of Serbian students and opposition politicians
A Belgrade digital rights group counted at least 14 targets in 2026. Citizen Lab confirmed one Pegasus infection and Amnesty a new version of a tool tied to Serbian intelligence.
- Event date
- Published
- Reading time
- 3 min
Key points
- SHARE Foundation reported on 2 September 2026 that at least 14 people in Serbia were targeted with spyware during the year.
- Citizen Lab confirmed a Pegasus infection on a student's iPhone dating from December 2025 to January 2026.
- Amnesty confirmed a new version of NoviSpy, a tool it has previously linked to Serbia's intelligence agency.
- Serbia's president and the intelligence agency denied the allegations.
At least 14 people in Serbia, among them members of the student protest movement, activists, a member of parliament and a local councillor, were targeted with advanced spyware in 2026, the Belgrade-based digital rights organisation SHARE Foundation said on 2 September. It called the cases the largest documented wave of such surveillance in the country.
The politicians are from opposition parties, SHARE said. Two international forensic teams, the Citizen Lab at the University of Toronto and the Security Lab of Amnesty International, independently confirmed parts of its findings. Serbia’s president and its intelligence agency rejected the allegations.
How the cases came to light
In August, 12 people contacted SHARE’s forensic experts after Apple warned them that their iPhones had been targeted. Apple sends such notifications when it has high confidence that a user has been attacked with commercially sold, or “mercenary”, spyware.
The Citizen Lab confirmed that one of those phones, belonging to a member of the student movement, had been infected with Pegasus, a surveillance tool made by the Israeli company NSO Group and sold only to governments. “We confirmed that the student’s device was hacked with a Pegasus zero-click exploit across December 2025-Jan 2026,” said Bill Marczak, a senior researcher at the lab, in SHARE’s statement. A zero-click attack needs no action by the victim; in this case it arrived through Apple’s iMessage service. Marczak told the news site CyberScoop that Apple’s software updates had since broken that particular exploit and urged users to update their phones. The other 11 devices should be treated as presumed infected, SHARE said.
The student, Jelena Kontić, said at a press conference that she is active in the movement’s field campaign and in contact with many citizens, and that the privacy of everyone she had communicated with was affected as well, the regional news site European Western Balkans reported.
A second tool that needs physical access
SHARE’s own analysis found two further infections with a new version of NoviSpy, Android spyware first discovered in Serbia in 2024. Unlike Pegasus, it has to be installed by someone holding the phone. Amnesty confirmed the new version on the device of a student whose phone had been taken during police questioning. The second case surfaced after private messages from a phone were broadcast on TV Informer, a channel aligned with the government.
An Amnesty report in late 2024, to which SHARE contributed, found that NoviSpy sent stolen data to a server with an internet address belonging to Serbia’s Security Information Agency, known as the BIA. Both organisations assess that Serbian police or the intelligence service are behind the new NoviSpy cases, CyberScoop reported. Investigators did not say who operated Pegasus against the student; identifying the customer behind a Pegasus attack is rarely possible.
“Serbia’s peaceful pro-democracy movement is being aggressively targeted with mercenary spyware,” said John Scott-Railton, a senior researcher at the Citizen Lab. NSO Group says its product is meant for fighting terrorism and crime and that it halts abuses it discovers.
Political setting
Serbia has seen sustained student-led protests since the canopy of the railway station in the city of Novi Sad collapsed in 2024. SHARE said the surveillance coincided with local elections held on 29 March 2026; a parliamentary election was expected in October, and polls showed the student movement as the main challenger to the governing Serbian Progressive Party, European Western Balkans reported.
President Aleksandar Vučić called the claims “stupid and pointless” and said they were “made without any evidence”. The BIA denied wiretapping the student movement. Ana Brnabić, the speaker of parliament, said the state was not responsible: “We haven’t heard any evidence that it was actually used,” she told Euronews Television. A European Commission spokesperson told Radio Free Europe that “any attempts to illegally access the data of citizens and political opponents, if confirmed, are unacceptable.”
SHARE argues that planting spyware is a criminal offence under Serbian law. It advised people at risk to switch on Lockdown Mode on iPhones or Advanced Protection on recent Android phones, and to contact a specialist organisation immediately if they receive a warning.
Sources
- Students and Opposition Politicians Targeted by Spyware
- Pegasus, NoviSpy variant spyware found on devices of Serbian activists
- SHARE Foundation reveals: Opposition and student activists in Serbia targeted with advanced spyware
- Reactions to surveillance scandal: EU: If the claims of illicit wiretapping in Serbia were confirmed, it would be unacceptable
- 14 students and opposition politicians targeted by spyware in Serbia
Spotted an error? See how to request a correction.


