Serbian Opposition Targeted: Who Watches the Watchers?

Digital forensic researchers have found evidence that at least 14 people in Serbia were targeted with advanced spyware, with the targeting beginning in December. The targets included a sitting member of Parliament, a local opposition politician, and student protesters. The findings came from outside researchers, not from any official government investigation or public admission. That distinction matters.

What happened

The discovery of spyware targeting opposition figures in Serbia was made by digital forensic specialists — civil society researchers who examine devices when someone reports suspicious behaviour. No government body initiated the investigation. No official inquiry has been announced.

The number confirmed so far is at least 14 individuals. The targeting reportedly began in December. Beyond those details, the full technical specifics of how the spyware was deployed have not been disclosed publicly.

What makes this newsworthy is not just the spyware itself. It is that the people who found it are outside the state, and the people best placed to investigate it institutionally have not done so.

Who is affected

The confirmed targets share a pattern: they are people who challenge or scrutinise those in power. A sitting parliamentarian. A local opposition politician. Student protesters who have been publicly active.

That last category is significant. Student protesters are not professional politicians with security teams or legal advisers on call. Their inclusion suggests that the surveillance net, as researchers found it, extends to emerging civic voices — people who have recently become visible through street-level activism rather than formal political roles.

If you organise, advocate publicly, or support opposition activity in Serbia, the relevant question is not whether your name has appeared in a report. It is whether the conditions that produced this pattern also apply to you.

What the real risk is

Advanced spyware does not work like someone reading your emails. When it is installed on a device, it can access contacts, location data, planned meetings, funding conversations, and private exchanges that reveal personal vulnerabilities. The person targeted loses more than their own privacy — they potentially expose everyone they communicate with.

That is the structural danger. One compromised device inside an organised movement can give whoever deployed the spyware a picture of the entire network: who talks to whom, when, about what, and through which channels.

There is a second harm that is harder to measure. When people know or reasonably suspect they are being watched, many stop organising. They cancel meetings. They avoid certain topics in messages. They step back from public activity. This chilling effect spreads through communities even among people whose devices were never touched.

Because the source of the targeting has not been publicly disclosed, those affected cannot fully assess what was accessed or for how long. That uncertainty makes it difficult to contain the damage or to warn specific contacts that their information may be compromised.

What to do today

This section is for anyone who organises, protests, reports, or advocates — in Serbia or elsewhere. You do not need to be a professional politician for this to apply to you.

Step one: Do not keep using a device you suspect

If you are an activist, journalist, or opposition figure and you have any reason to think your phone or laptop may be compromised, stop using it for sensitive communications now. Do not reset or wipe it yet — that can destroy evidence. Set it aside and use a different device for anything urgent.

Step two: Contact a specialist, not a consumer antivirus tool

Standard antivirus software does not detect the kind of advanced spyware described in this case. The forensic work here was done by specialist researchers. Organisations such as Access Now’s Digital Security Helpline, Frontline Defenders, and the Citizen Lab offer direct support to activists and journalists. These services are free. Reach out to them before drawing conclusions about whether your device is clean.

Step three: Know what to look for

Unusual battery drain, unexpected spikes in mobile data usage, the device running hot when idle, or apps behaving strangely are not proof of spyware — but they are worth documenting. Write down what you noticed and when. Take screenshots of data usage statistics if your phone allows it. This information is useful to a forensic researcher even if it turns out to be nothing.

Step four: Report rather than reset

If you contact a digital rights organisation, they may ask to examine your device. Resetting it first removes the evidence they need to confirm what happened and to build the broader picture that protects others. Preserve the device in its current state until you have spoken to someone qualified.

Step five: Separate your communications

While you wait for guidance, move sensitive conversations to a device that has not been used for the same accounts or networks. This limits further exposure even if you cannot yet confirm whether the original device is compromised.

Why this keeps happening

Advanced surveillance tools are sold commercially. Sellers can and do disclaim responsibility for how buyers deploy them, and buyers in many jurisdictions face no enforceable legal consequence for using them against their own citizens. The market operates largely without binding international rules.

The oversight problem runs deeper than regulation, though. The institutions with formal authority to investigate — state prosecutors, parliamentary committees, national intelligence oversight bodies — are often part of the same institutional structure that benefits from keeping opposition figures off-balance and under surveillance. Asking those bodies to investigate themselves is not a realistic mechanism.

There is also a less-discussed structural problem: online systems have no reliable way to tie actions to identifiable, responsible parties. Spyware can be deployed through infrastructure that obscures its origin. Even well-designed oversight bodies struggle to find a target when attribution is technically contested and politically inconvenient. Without a clear, undeniable chain of responsibility, accountability proceedings stall before they start.

The result is that the investigative work falls to civil society researchers — organisations with limited budgets and no enforcement powers. They can expose what happened. They cannot compel a consequence. Without a credible threat of prosecution, sanctions, or loss of contracts, the incentive to deploy spyware against political opponents remains intact, and the pattern repeats in the next country, or the same one.

Frequently asked questions

How do researchers detect spyware on a targeted person’s device?

Forensic researchers use specialised tools to examine the technical logs and processes running on a device. They look for traces — unusual network connections, hidden processes, or artefacts left by known spyware families — that ordinary software would not flag. It requires expertise and often physical or remote access to the device in question. Consumer security tools are not built to do this work.

Does being a private citizen rather than a politician mean you are not at risk?

Not necessarily. The confirmed targets in this case include student protesters, not just elected officials. Anyone who becomes publicly visible through activism, organising, or dissent can become a target. The relevant factor appears to be whether someone challenges or scrutinises those in power, not whether they hold an official title.

Why is it so difficult to hold anyone accountable when spyware abuse is discovered?

Several factors combine. Attribution is technically difficult and contested. The institutions with formal investigative authority are often part of the same structure implicated in the surveillance. Spyware vendors operate across borders, making single-jurisdiction enforcement complicated. And because digital systems rarely produce a clear, undeniable paper trail that ties a specific person to a specific deployment decision, accountability proceedings frequently stall at the evidence stage. Exposure by outside researchers is currently the most reliable check available — but exposure alone does not produce consequences.

Originally reported by therecord.media. This article summarises that reporting and adds practical guidance.

Scams, fraud, bots, and manufactured noise keep spreading because the internet was built with no reliable way to know who anyone actually is. Everyone deserves authenticity and accountability online, and that is the mission we are working on. Subscribe to follow the work.

Grab Your Free Ebook

Subscribe to our mailing list and get your free copy of Escape the Plantation.

“No problem can withstand the assault of sustained thinking.”

                                                                                                                                                 — Voltaire

🔒 YOU own the information that identifies YOU.
The operation of this website is governed by the ordinances of the City of Osmio, including its Privacy Ordinance.
View Privacy Ordinance

No Tracking Pixels or Beacons

Today's internet has become infested with hidden trackers — tiny “pixel beacons,” scripts, and device tracking tools designed to follow you without your knowledge.

As a Member Enterprise of The Authenticity Alliance, the operator of this website uses no tracking pixels, no beacons, and no covert identity-reporting mechanisms of any kind.

If we want to know something about you, we’ll ask — we won’t spy.
Learn About Spyfree

What is Authenticity™?

The word “Authenticity™” identifies a digital or physical space of “accountable anonymity” in which people enjoy both privacy for themselves and accountability from others.

Authenticity™ is the condition that exists in a space where there are

  • Digital Signatures Everywhere backed by
  • Measurably Reliable Identity Certificates that are
  • Owned by their Users and which provide
  • Privacy via Accountable Anonymity.

 

Learn about digital signatures and identity certificates in this short video →

What is The Authenticity Alliance?

We are an Authenticity Growers Cooperative

Similar to familiar agricultural cooperatives in the physical world, The Authenticity Alliance is a network of enterprises and individuals whose purpose is to “grow” Authenticity and bring it to the digital world.

Each Authenticity Enterprise—that is, each Member Enterprise of the Alliance—solves a particular inauthenticity problem in its chosen target market or audience.

What Does The Authenticity Alliance Do?

The Alliance brings together independent enterprises that share a common mission: creating spaces of accountable anonymity where digital signatures, reliable identity certificates, and privacy protection work together to solve real-world inauthenticity problems.

WHO is the Authenticity Alliance?

The Authenticity Alliance is comprised of two groups working together to promote trust and transparency across digital ecosystems.

  • Enterprises: Authenticity Enterprises that provide Authenticity solutions for the inauthenticity pains in a specific market or industry.
  • Individuals: People who understand the problems of inauthenticity that plague the world’s information systems and who want to help implement and promote Authenticity™ principles.

Authenticity Enterprises

Each is an Enterprise Member of The Authenticity Alliance

Individual Enterprise in The Authenticity Alliance

Customers and members of an Authenticity Enterprise are automatically eligible to become Individual Members of The Authenticity Alliance.You may also join directly as an individual Member here.

 

© 2026 The Authenticity Alliance. All rights reserved. REAL Security | REAL Privacy | REAL Accountability