Digital rights group says over a dozen Serbians targeted with mercenary spyware

More than a dozen Serbian citizens had their digital privacy compromised through targeted spyware surveillance.
Their phones or computers were compromised. Their communications were exposed.
The targeting of Serbian citizens with spyware represents a complete breach of digital privacy that cannot be reversed.
Mark

So what exactly is mercenary spyware, and why does it matter that it was used in Serbia specifically?

Mimi

It's commercial surveillance software sold to governments and agencies. Once installed on a phone or computer, it gives operators complete access—messages, location, files, everything. The concern is that these tools, designed ostensibly for fighting crime, end up being used against ordinary people and political opponents.

Luke

Do we know who deployed it in Serbia? That's the crucial detail, and the reporting doesn't seem to confirm it yet.

Mimi

That's what the investigation is trying to establish. The digital rights group documented the targeting, but tracing it back to a specific actor—Serbian government, foreign state, private contractor—that's still unclear.

Mark

How many people are we talking about, and what do we know about who they are?

Mimi

More than a dozen individuals. The reporting doesn't name them or describe their backgrounds, so we don't know if they're activists, journalists, opposition figures, or something else entirely.

Luke

That's a significant gap. The pattern of targeting tells you a lot about intent. If it's activists, that's one story. If it's random, that's another.

Mimi

True. And that's why the ongoing investigation matters—it should answer those questions.

Mark

What happens next? Is there any indication Serbia will investigate or respond?

Mimi

The findings will likely draw international attention, possibly from the EU or human rights organizations. Whether the Serbian government acts is an open question.

Luke

And even if they do investigate, the damage to the people targeted is already done. Their privacy is compromised, their trust is broken.

Mimi

Exactly. The investigation can establish accountability, but it can't undo the surveillance that already happened.

  • Over twelve Serbian citizens were deliberately infected with mercenary-grade spyware in what researchers describe as a coordinated campaign, not a series of random incidents.
  • The breach is already done — messages, calls, locations, and files were laid open to unknown operators, and no technical fix can restore what was taken.
  • Investigators are racing to determine whether Serbian state agencies, foreign actors, or private contractors authorized and deployed the operation — each answer carrying its own legal and geopolitical weight.
  • Serbia's position between Western institutions and Russian influence makes it a particularly charged theater for this kind of surveillance, drawing the attention of international bodies that have acted in similar cases elsewhere.
  • Digital rights researchers and journalists are pressing for victim notification, government accountability, and export controls on the surveillance tools that made the operation possible.

In Serbia, more than a dozen citizens have been found to carry invisible wounds — their phones and computers silently breached by commercial spyware of the kind sold to governments and intelligence agencies worldwide. A digital rights organization has documented what appears to be a coordinated surveillance campaign, placing Serbia alongside a lengthening roster of nations where powerful tools meant for law enforcement have turned inward against ordinary people. The discovery raises ancient questions in a modern register: who watches the watchers, and what recourse remains for those already exposed?

A digital rights organization has documented evidence that more than a dozen people in Serbia were deliberately infected with commercial spyware — the kind typically sold to governments and intelligence agencies for surveillance operations. The discovery places Serbia on a growing map of countries where such tools have been turned against citizens, often without their knowledge.

The software is designed to penetrate phones and computers, giving operators access to messages, calls, location data, and private files. Though marketed to law enforcement worldwide, repeated investigations have shown these tools deployed against political opponents, activists, and ordinary people with no connection to criminal activity.

What distinguishes this case is its apparent coordination. Researchers identified more than twelve individuals targeted within the same country in what looks like a deliberate campaign rather than isolated exploitation. The investigation is ongoing, with researchers working to establish the full scope — how many were compromised, over what period, and by what technical means.

Serbia's geography matters. Sitting between Western institutions and Russian influence, it has become a potential testing ground for surveillance tactics, and each new case in the region raises the stakes for accountability. Investigators are still working to determine whether Serbian government agencies were involved, whether foreign actors conducted the operation, or whether private contractors acted independently.

For those targeted, the damage is already done. Their communications were exposed, and that cannot be undone. What remains is the question of consequences — whether those responsible will be identified, whether victims will be formally notified, and whether Serbia will face the kind of international pressure that spyware cases in other countries have triggered from the European Union and the U.S. State Department. The government's response, or silence, will itself be an answer.

A digital rights organization has documented evidence that more than a dozen people in Serbia have been deliberately infected with commercial spyware—the kind typically deployed by governments and private contractors for surveillance operations. The discovery adds Serbia to a growing list of countries where such tools have been weaponized against citizens, often without their knowledge or consent.

The spyware in question belongs to a category of software designed to penetrate phones and computers, granting operators access to messages, calls, location data, and files. These tools are marketed to law enforcement and intelligence agencies worldwide, but investigations by journalists and human rights groups have repeatedly shown them being used against political opponents, activists, and ordinary citizens with no connection to criminal activity.

What makes this case significant is its scale and specificity. Rather than a handful of isolated incidents, the digital rights group identified a pattern: more than twelve separate individuals targeted within the same country during what appears to be a coordinated campaign. The targeting suggests a deliberate strategy rather than random exploitation. The group's investigation is ongoing, and researchers are working to establish the full scope of the operation—how many people were actually compromised, over what period, and through what technical means.

Serbia's position matters here. The country sits at a crossroads between Western institutions and Russian influence, making it a potential testing ground for surveillance tactics. Previous reporting has documented spyware use in neighboring countries and across Eastern Europe, but each new case raises the stakes for accountability. When commercial surveillance tools end up in the hands of actors willing to target citizens indiscriminately, the question of who authorized it and why becomes urgent.

The investigation is still developing. Researchers are working to trace the origin of the spyware deployment and identify who deployed it. They are also attempting to determine whether Serbian government agencies were involved, whether foreign actors conducted the operation, or whether private contractors acted independently. Each scenario carries different implications for Serbian law and international norms around digital sovereignty.

For the people targeted, the breach is already complete. Their phones or computers were compromised. Their communications were exposed. The damage to privacy and trust cannot be undone, even if the spyware is eventually removed. What remains is the question of accountability—whether those responsible will face consequences, whether victims will be notified, and whether Serbia will implement safeguards to prevent future campaigns.

The digital rights group's findings are likely to draw international attention. Spyware cases in other countries have prompted investigations by the European Union, statements from the U.S. State Department, and calls for export controls on surveillance technology. Serbia may face similar pressure to investigate and respond. The government's reaction—or lack thereof—will signal whether it takes digital rights seriously or whether it views such tools as acceptable instruments of state power.

Vuoi la storia completa? Leggi l'originale su Reuters ↗
Contattaci Domande frequenti