Digital forensic researchers have found evidence that at least 14 people in Serbia were targeted with advanced spyware, with the targeting beginning in December. The targets included a sitting member of Parliament, a local opposition politician, and student protesters. The findings came from outside researchers, not from any official government investigation or public admission. That distinction matters.
What happened
The discovery of spyware targeting opposition figures in Serbia was made by digital forensic specialists — civil society researchers who examine devices when someone reports suspicious behaviour. No government body initiated the investigation. No official inquiry has been announced.
The number confirmed so far is at least 14 individuals. The targeting reportedly began in December. Beyond those details, the full technical specifics of how the spyware was deployed have not been disclosed publicly.
What makes this newsworthy is not just the spyware itself. It is that the people who found it are outside the state, and the people best placed to investigate it institutionally have not done so.
Who is affected
The confirmed targets share a pattern: they are people who challenge or scrutinise those in power. A sitting parliamentarian. A local opposition politician. Student protesters who have been publicly active.
That last category is significant. Student protesters are not professional politicians with security teams or legal advisers on call. Their inclusion suggests that the surveillance net, as researchers found it, extends to emerging civic voices — people who have recently become visible through street-level activism rather than formal political roles.
If you organise, advocate publicly, or support opposition activity in Serbia, the relevant question is not whether your name has appeared in a report. It is whether the conditions that produced this pattern also apply to you.
What the real risk is
Advanced spyware does not work like someone reading your emails. When it is installed on a device, it can access contacts, location data, planned meetings, funding conversations, and private exchanges that reveal personal vulnerabilities. The person targeted loses more than their own privacy — they potentially expose everyone they communicate with.
That is the structural danger. One compromised device inside an organised movement can give whoever deployed the spyware a picture of the entire network: who talks to whom, when, about what, and through which channels.
There is a second harm that is harder to measure. When people know or reasonably suspect they are being watched, many stop organising. They cancel meetings. They avoid certain topics in messages. They step back from public activity. This chilling effect spreads through communities even among people whose devices were never touched.
Because the source of the targeting has not been publicly disclosed, those affected cannot fully assess what was accessed or for how long. That uncertainty makes it difficult to contain the damage or to warn specific contacts that their information may be compromised.
What to do today
This section is for anyone who organises, protests, reports, or advocates — in Serbia or elsewhere. You do not need to be a professional politician for this to apply to you.
Step one: Do not keep using a device you suspect
If you are an activist, journalist, or opposition figure and you have any reason to think your phone or laptop may be compromised, stop using it for sensitive communications now. Do not reset or wipe it yet — that can destroy evidence. Set it aside and use a different device for anything urgent.
Step two: Contact a specialist, not a consumer antivirus tool
Standard antivirus software does not detect the kind of advanced spyware described in this case. The forensic work here was done by specialist researchers. Organisations such as Access Now’s Digital Security Helpline, Frontline Defenders, and the Citizen Lab offer direct support to activists and journalists. These services are free. Reach out to them before drawing conclusions about whether your device is clean.
Step three: Know what to look for
Unusual battery drain, unexpected spikes in mobile data usage, the device running hot when idle, or apps behaving strangely are not proof of spyware — but they are worth documenting. Write down what you noticed and when. Take screenshots of data usage statistics if your phone allows it. This information is useful to a forensic researcher even if it turns out to be nothing.
Step four: Report rather than reset
If you contact a digital rights organisation, they may ask to examine your device. Resetting it first removes the evidence they need to confirm what happened and to build the broader picture that protects others. Preserve the device in its current state until you have spoken to someone qualified.
Step five: Separate your communications
While you wait for guidance, move sensitive conversations to a device that has not been used for the same accounts or networks. This limits further exposure even if you cannot yet confirm whether the original device is compromised.
Why this keeps happening
Advanced surveillance tools are sold commercially. Sellers can and do disclaim responsibility for how buyers deploy them, and buyers in many jurisdictions face no enforceable legal consequence for using them against their own citizens. The market operates largely without binding international rules.
The oversight problem runs deeper than regulation, though. The institutions with formal authority to investigate — state prosecutors, parliamentary committees, national intelligence oversight bodies — are often part of the same institutional structure that benefits from keeping opposition figures off-balance and under surveillance. Asking those bodies to investigate themselves is not a realistic mechanism.
There is also a less-discussed structural problem: online systems have no reliable way to tie actions to identifiable, responsible parties. Spyware can be deployed through infrastructure that obscures its origin. Even well-designed oversight bodies struggle to find a target when attribution is technically contested and politically inconvenient. Without a clear, undeniable chain of responsibility, accountability proceedings stall before they start.
The result is that the investigative work falls to civil society researchers — organisations with limited budgets and no enforcement powers. They can expose what happened. They cannot compel a consequence. Without a credible threat of prosecution, sanctions, or loss of contracts, the incentive to deploy spyware against political opponents remains intact, and the pattern repeats in the next country, or the same one.
Frequently asked questions
How do researchers detect spyware on a targeted person’s device?
Forensic researchers use specialised tools to examine the technical logs and processes running on a device. They look for traces — unusual network connections, hidden processes, or artefacts left by known spyware families — that ordinary software would not flag. It requires expertise and often physical or remote access to the device in question. Consumer security tools are not built to do this work.
Does being a private citizen rather than a politician mean you are not at risk?
Not necessarily. The confirmed targets in this case include student protesters, not just elected officials. Anyone who becomes publicly visible through activism, organising, or dissent can become a target. The relevant factor appears to be whether someone challenges or scrutinises those in power, not whether they hold an official title.
Why is it so difficult to hold anyone accountable when spyware abuse is discovered?
Several factors combine. Attribution is technically difficult and contested. The institutions with formal investigative authority are often part of the same structure implicated in the surveillance. Spyware vendors operate across borders, making single-jurisdiction enforcement complicated. And because digital systems rarely produce a clear, undeniable paper trail that ties a specific person to a specific deployment decision, accountability proceedings frequently stall at the evidence stage. Exposure by outside researchers is currently the most reliable check available — but exposure alone does not produce consequences.
Originally reported by therecord.media. This article summarises that reporting and adds practical guidance.
Scams, fraud, bots, and manufactured noise keep spreading because the internet was built with no reliable way to know who anyone actually is. Everyone deserves authenticity and accountability online, and that is the mission we are working on. Subscribe to follow the work.
