Israel Israel NSO Group Pegasus surveillance policy

Israel's Pegasus Export Licences Control Who Buys the Spyware, but They Can't Stop Misuse After Sale

A Serbian activist's Pegasus infection tests Israel's 2021 export reforms. Licence-time promises need audit, disclosure and revocation to protect civil society.

Pegasus in Serbia and Israel's Export Rules People of Internet Research · Israel 14+ Threat Notification cases documented SHARE documented at least 14 cases… 1 Confirmed Pegasus infections The Citizen Lab confirmed one iPho… 6 yrs Serious-crime prison threshold DECA's December 2021 end-user cert… peopleofinternet.com
Pegasus in Serbia and Israel's Export … People of Internet Research · Israel 14+ Threat Notification cas… 1 Confirmed Pegasus infections 6 yrs Serious-crime prison threshold peopleofinternet.com

Key Takeaways

On 2 September 2026, the Citizen Lab and the SHARE Foundation confirmed that a member of Serbia's student protest movement had an iPhone infected with NSO Group's Pegasus spyware. The vector was an iMessage zero-click exploit, and the Citizen Lab found high-confidence indicators of infection from December 2025 to January 2026. Apple has patched the flaw in iOS 18.4.1. SHARE has documented at least 14 people in the student movement, civil society and the opposition, including an opposition MP, who received Apple Threat Notifications.

The report does not name who operated the Pegasus infection, and the Citizen Lab page does not discuss Israeli export licensing. Press coverage of the case also stops short of attributing the Pegasus infection to any Serbian agency. The licensing question is ours: if Israel's licensing system works as designed, what is it actually designed to prevent?

The strongest case for the licensing regime

Spyware is a dual-use capability. Governments have a legitimate need to intercept communications of terrorists and organised criminals, and encrypted phones make that hard. Israel treats Pegasus as a controlled export administered by the Defence Export Controls Agency (DECA), which means a state agency decides who may buy it. That is better than an unlicensed market. Supporters can also point to real reform. On 6 December 2021, DECA tightened its end-user requirements, according to Janes. Buyers must commit to using cyber products only to prevent terrorism or investigate serious crimes, defined as offences carrying at least six years' imprisonment. The certificate states that criticism of a state is not itself terrorism or a serious crime. It also bars targeting people on the basis of religion, race or political affiliation.

On paper, a student protester or an opposition MP falls squarely outside that permitted use.

Where the design falls short

The weakness is that these are promises made at the point of sale. A certificate is only as good as the ability to detect breaches and the willingness to act on them. Three gaps stand out.

The United States took a different tack. On 4 November 2021, the Commerce Department's Bureau of Industry and Security added NSO Group to the Entity List, finding that it "developed and supplied spyware to foreign governments" that used it against journalists, activists and others, according to the BIS release. That is a consequence that attaches to the vendor, not to a buyer's signature.

A proportionate fix, not a ban

The pro-innovation response is not to abolish Israel's cyber-export industry or to ban lawful interception tools. Blunt bans push capability into unlicensed gray markets with no oversight at all, and they punish the security researchers who build defensive tools. The goal should be to make existing licensing credible.

First, DECA should publish aggregate data: number of cyber licences granted, denied and conditioned, and number of end-use breaches investigated. Aggregates reveal nothing operationally sensitive. Second, licences should carry a defined revocation trigger. If a credible forensic finding from a respected lab links a product to targeting of an opposition politician or protest organiser, the licence holder should have to respond within a fixed period, and DECA should have to state whether it opened a review. Third, Israeli courts should allow a standing route for forensic evidence from groups like the Citizen Lab, so that victims are not required to prove what only the spyware vendor can see.

None of this restricts speech or innovation. It is the kind of ordinary accountability that licensed industries accept elsewhere. A licensing regime that cannot show it has ever said no after the fact leaves civil society relying on Apple's threat notifications to find out it was spied on.

What to watch

Two questions will determine whether Serbia changes the picture. One is whether Israeli authorities say publicly if they are reviewing the case, and whether any review reaches the end-use certificate. The other is whether the Citizen Lab and SHARE findings, with at least 14 documented notification cases, prompt the Knesset to ask DECA for the data above. A one-off patch fixes one phone. Only a credible consequence for misuse changes what a buyer expects when it signs.

Sources & Citations

  1. Citizen Lab: Pegasus infection of Serbian student activist
  2. US Commerce BIS: NSO Group added to Entity List (4 Nov 2021)
  3. Columbia GFoE: Malekar v. DECA (Tel Aviv-Jaffa District Court, 2020)
  4. Janes: Israel tightens regulations around cyber exports
  5. Security Affairs: Pegasus and NoviSpy used against Serbian protesters