A total of 14 students, activists, and opposition politicians have been spied on with illegal mobile phone software since the beginning of the year. The mobile phone surveillance was confirmed by a forensic analysis conducted by two international laboratories – the University of Toronto’s Citizen Lab and Amnesty International – as announced by representatives of the Students in Blockade movement during their first press conference since the start of the student protests.
“Their phones were attacked with some of the most advanced spyware in the world today. This software is sold exclusively to states, and someone must be held accountable for it,” stated Ela Zeković, a student at the Faculty of Political Sciences.
This software reads every message, views every photo, and can activate the mobile phone’s microphone and camera. Its use constitutes a criminal offence under Serbian law, she added. “Pegasus spyware was found on a colleague’s phone, installed remotely without a single click and without the user’s knowledge,” Zeković said.
Serbian President Aleksandar Vučić dismissed the student movement’s statement as “suspicions without any evidence”, further claiming that he himself had been the target of wiretapping, both as head of state and previously as an “opposition leader”.
“Did I make scenes over it and prosecute someone at the BIA [Security Information Agency] afterwards? Never! They hooked me on four or five hooks. I didn’t play the victim. I took it like a man and kept quiet,” he said following a visit to Rusko Selo, near Kikinda, on 3 September.
The Security Information Agency (BIA) described the allegations regarding the use of spyware as “cheap sensationalism”. “The content of these allegations clearly indicates the true intentions of the individuals and organisations making them – namely, to work in the interests of certain foreign intelligence services and pressure groups,” the agency stated in a press release on 3 September.
Among the 14 targeted individuals, the majority were members of the student movement, said Andrijana Ristić, a researcher at the Share Foundation who participated in uncovering the attacks.
The period in which the attacks were concentrated largely coincides with the campaign for the local elections held on 29 March 2026. “This represents the largest wave of such spyware usage ever recorded in the country,” Ristić explained.
The Pegasus attack is the first confirmed case of infection with this spyware globally in 2026, she added. “The cost of using Pegasus is estimated in the millions of euros.” The software is produced by the Israeli company NSO Group and sold exclusively to governments and state institutions, Ristić highlighted.
Students at a press conference at the Miljenko Dereta venue in Belgrade
NSO Group did not respond to Reuters’ request for comment, but in a report published in January, the company stated that it works with clients to address potential abuses. “In cases of severe or repeated non-compliance, NSO may suspend or terminate the relationship,” the company stated, as reported by Reuters.
Among those affected, as many as 12 turned to the Share Foundation in August this year after receiving notifications on their mobile phones warning them that they were likely targets. “It wasn’t just any warning: the notification came directly from Apple, the phone’s manufacturer,” Ristić said.
The conference at the “Miljenko Dereta” space in Belgrade took place on the same day that several media outlets in Serbia reported that citizens will head to the polls on 25 October.
Elections have not yet been formally called, which remains one of the key demands of the student movement, along with establishing accountability for the tragedy at the Novi Sad railway station, where 16 people died following the collapse of a concrete canopy.
‘As if your phone were in their hands’
Jelena Kontić, a member of the student movement, was targeted by the Pegasus software.
During the press conference, she emphasised that she had never been detained or arrested, meaning there had been no opportunity to install software or tracking devices directly on her phone. “This leads to one question: why me? I wondered how it was possible that what I do led someone to monitor and wiretap me,” she said.
Jelena highlighted that illegal access was gained not only to her data, but also to the data and information of everyone around her. “As a result, everyone became a victim of someone’s surveillance and of this system. It genuinely feels as though your phone is in their hands,” she added.
Kontić believes that what happened to her was “an attempt at blackmail and intimidation”. She considers it “likely” that she was targeted because she was “very active” in the A Student in Every Village initiative, conducted by the movement since it put forward its demand for early elections.
Milica, a student at the University of Niš, discovered her phone had been targeted when she received a notification in mid-August. “At first, I thought it was a generic notification or an advertisement. Only when I looked closer did I realise it stated a spyware attack had been attempted on my phone, and I forwarded it to a colleague in Niš who works in IT. By getting in touch with colleagues in Belgrade, we realised I wasn’t the only one who had received that warning,” she recounted during the conference.
When she travelled to Belgrade to have her phone examined, she understood the gravity of the situation. “I realised that through that attack they had access to my whole life – not just to student meetings, but also to private conversations, the microphone, and the camera. They could turn on the camera while we were taking a shower or talking about personal matters,” she added.
As she explained, the attackers had access not only to her data, but also to that of “people who support the students and fight alongside them”. “This is not just an attack on students; it’s an attack on every contact in my address book,” she stressed.
How was the spying carried out?
Pegasus spyware from the Israeli company NSO Group was installed on the student’s phone using the zero-click method. Put simply: in zero-click attacks, the software is installed remotely without any need to click on anything or have physical contact with the device. Hence the name: zero clicks.
The spyware remained on the phone until the next operating system update. This is an advanced version of spyware, as it does not require someone to physically take your phone, as previously occurred in Serbia following arrests and police interrogations.
The consequences are similar. The spyware has access to everything on the device: messages, contacts, photos, application data, etc., and can secretly record the screen or activate the microphone and camera.
NSO Group had previously stated that its products and services “are used exclusively by government security agencies and law enforcement to combat crime and terrorism”. In the case of the other 11 people who received the same notification, checks are still ongoing to determine which spyware was involved. Furthermore, two other phones were infected with a new version of the NoviSpy spyware.
In one case, involving a member of the student movement, the spyware was installed when the young man was taken to a police station for questioning. The phone was forcibly unlocked, all its content was extracted, and software was installed that collected data and sent it to an external server. The same spyware was found on a second phone, discovered after a private Viber message originating from that device was read out during a broadcast on Informer TV.
“On a device belonging to a member of the student movement, we found over 1,500 frame captures, or screenshots, taken to monitor activity on the phone,” Andrijana Ristić revealed during the press conference. “First, the person is taken to police premises, after which they are physically separated from their phone; the device is illegally unlocked, all data is copied, and spyware is installed that gathers all subsequent data and sends it to a server whose IP address we have identified,” she added.
She described this practice as a “grave violation of the right to privacy, which heightens fear among citizens and undermines related rights, such as freedom of expression and assembly”.
Previous spying cases in Serbia
This is not the first case of its kind in Serbia, the Share Foundation points out.
At the end of 2024, an analysis by Amnesty International’s Security Lab into the illegal surveillance of activists, journalists, and NGOs in Serbia showed that “dozens, if not hundreds, of devices have been targeted by NoviSpy spyware in recent years”. Beyond the direct breach of privacy, such practices can deter people from engaging in politics, speaking out publicly, or expressing dissent.
In November 2023, attempted spyware attacks were uncovered on the mobile phones of two civil society figures, and in February 2025, two female journalists from the BIRN Serbia portal were targeted by Pegasus spyware. They had received suspicious Viber messages from the same unknown Serbian phone number.
In December 2025, Amnesty reported on the tracking of students during protests through zero-day attacks and the Cellebrite forensic tool.
A zero-day exploit is a security vulnerability unknown to developers, for which no immediate fix exists. Malicious actors can exploit it, and only then does the vendor become aware of it, starting from that “day zero” to resolve the issue.
Following pressure from activists and the publication of evidence, the company announced it would suspend the use of its technology in Serbia.
The student movement emerged following the collapse of the canopy at the Novi Sad railway station on 1 November 2024, which claimed the lives of 16 people and left one woman severely injured. Massive protests and student-led blockades followed. Almost two years have passed since the tragedy, and no judicial proceedings have yet been initiated. In addition to demanding accountability for the incident, the student movement put forward a demand in May 2025 for early parliamentary elections to be called.
Pending the calling of the repeatedly flagged elections, the ruling Serbian Progressive Party (SNS) is also organising rallies across the country.
The elections could be held on 18 or 25 October, and the exact date “will be known in a few days”, Serbian President Aleksandar Vučić stated on 20 August.
(BBC Serbia, 03.09.2026)
https://www.bbc.com/serbian/articles/cpwldn5ejq1o/lat