Summary
- Twenty-nine MEPs are pressing the European Commission to respond to spyware findings involving Serbian activists and opposition figures.
- Researchers confirmed Pegasus on one phone and NoviSpy-related infections on others, but did not attribute the Pegasus infection to Serbia.
- The dispute is moving surveillance allegations into EU accession, funding, and democratic-governance policy.
Twenty-nine members of the European Parliament are pressing the European Commission for consequences against Serbia after researchers documented a major wave of advanced spyware targeting students, activists, and opposition politicians.
The lawmakers want Brussels to slow Serbia’s EU accession process and impose financial consequences following forensic findings published by the SHARE Foundation with support from Citizen Lab and Amnesty International’s Security Lab.
SHARE said at least 14 people in Serbia had been targeted with advanced spyware since the beginning of 2026, describing it as the largest documented wave of such surveillance in the country. Those targeted included members of the student movement, activists, a member of parliament, and a local opposition councillor.
Twelve people approached SHARE’s digital-forensics specialists in August after receiving Apple threat notifications indicating they had been targeted with mercenary spyware.
Citizen Lab subsequently confirmed that the iPhone of one member of the student movement had been infected with NSO Group’s Pegasus spyware. That infection was previously covered by Cyber Insider.
The latest political response does not resolve who deployed Pegasus against that device. The researchers confirmed the infection but did not attribute it to the Serbian authorities, a distinction that remains important as the case moves into EU politics.
The evidential position around NoviSpy is different. SHARE said forensic analysis confirmed infections involving a new version of NoviSpy or closely related spyware. Earlier investigations by SHARE and Amnesty International had linked NoviSpy infrastructure and deployment methods more directly to Serbian state authorities, including cases involving devices taken during questioning.
Serbian officials have rejected allegations that the authorities conducted unlawful surveillance. Those denials sit alongside a growing body of forensic evidence about spyware use in the country, although the evidence does not support treating every infection as having the same attribution.
The latest cases are moving the issue beyond digital forensics and into the EU’s relationship with an accession candidate. The 29 MEPs are seeking to connect alleged surveillance of political opponents and activists to assessments of democratic institutions, the rule of law, EU funding, and Serbia’s progress towards membership.
That creates a different accountability path from the response normally available after commercial spyware is found. Device analysis can identify an exploit, malware family, or infrastructure, but political consequences depend on whether governments and institutions are willing to connect those findings to procurement, oversight, funding, or diplomatic leverage.
European institutions have already expressed concern about unlawful surveillance in Serbia. Previous European Parliament language has condemned the use of Pegasus, Cellebrite, and NoviSpy against demonstrators and called for stronger oversight of surveillance technology.
The latest evidence arrives amid continuing political tension in Serbia and ahead of further elections, increasing scrutiny of whether opposition groups and civil-society organisations can communicate and organise without covert surveillance.
The technical distinctions will remain important as that debate develops. Pegasus is sold to government customers, but identifying the malware on a device does not by itself establish which customer deployed it. Evidence around previous NoviSpy cases points more directly towards Serbian state structures, but that evidence should not be transferred automatically to the separate Pegasus infection.
The confirmed position is therefore narrower than some of the political allegations but still consequential: advanced spyware has targeted Serbian political and civil-society figures, several infections have been forensically established, and 29 MEPs now want those findings reflected in the EU’s financial and accession relationship with Belgrade.





