Israel Israel NSO Group Pegasus surveillance policy

Serbia's 14-Case Pegasus Wave Shows Israel's Post-2021 Export Reforms Aren't Working

A zero-click iMessage hack on a Serbian student activist reveals gaps in Israel's cyber-export licensing regime that self-certification alone cannot close.

Israel's Spyware Export Oversight, By the Numbers People of Internet Research · Israel 14+ Documented Serbian targets Individuals in Serbia's student mo… 37 Approved buyer countries Down from ~102 after Israel's Nove… 5 Years on US Entity List NSO Group has been blacklisted by … peopleofinternet.com
Israel's Spyware Export Oversight, By … People of Internet Research · Israel 14+ Documented Serbian targets 37 Approved buyer countries 5 Years on US Entity List peopleofinternet.com

Key Takeaways

The Citizen Lab and Serbia's SHARE Foundation confirmed on September 2, 2026 that NSO Group's Pegasus spyware infected the iPhone of a member of Serbia's pro-democracy student movement via an iMessage zero-click exploit — an attack that requires no click, link, or user error to succeed (Citizen Lab). Forensic analysis found high-confidence indicators of infection between December 2025 and January 2026, using an exploit chain Apple patched in iOS 18.4.1. SHARE Foundation says the case is one of at least 14 it has documented against Serbia's student movement, civil society, and an opposition member of parliament, timed ahead of Serbia's 2026 election cycle (The Hacker News).

This is not Serbia's first spyware scandal. Amnesty International and Serbian civil-society groups have previously documented Cellebrite forensic tools being used to plant NoviSpy, a homegrown Android spyware, on the phones of detained activists after police confiscated their devices — including one case where private messages extracted this way surfaced on a pro-government television channel. Pegasus's reappearance alongside NoviSpy suggests a surveillance apparatus willing to mix a commercial Israeli tool with domestic capabilities depending on what a given target's phone allows.

The Regulatory Question Israel Still Hasn't Answered

Every Pegasus sale requires a Ministry of Defense export license, issued through the Defense Export Controls Agency (DECA) and negotiated via SIBAT, Israel's defense-export directorate. That is the steelman for keeping oversight in Jerusalem rather than handing it to a multilateral body: Israel's government, not NSO, decides who may buy the tool, and it has used that leverage before — tightening the approved buyer list from roughly 102 countries to 37 in November 2021, after the original Pegasus Project revelations, and requiring purchasing governments to sign end-use declarations restricting deployment to terrorism and serious-crime investigations (The Record). A licensing chokepoint, in theory, is more accountable than an unregulated global market in intrusion software — and unilateral Israeli export control is, as Lawfare has noted, considerably more expansive in scope than the equivalent EU or US frameworks (Lawfare).

The problem is that a license-and-declaration model only works if breaches are actually punished, and the record on enforcement is thin. Tel Aviv's District Court rejected a 2020 petition by Amnesty International Israel to revoke NSO's export license outright, leaving the entire compliance burden on the Ministry of Defense's own after-the-fact investigations. Five years and multiple documented abuse cases later, those investigations have not produced a single publicly confirmed license revocation tied to activist or journalist targeting. When the same client jurisdiction is caught misusing licensed spyware against its own opposition ahead of an election, self-certification stops looking like oversight and starts looking like a formality NSO's customers know they can ignore.

Washington Already Made Its Call — Israel Hasn't Matched It

The US Commerce Department's Bureau of Industry and Security added NSO Group to its Entity List on November 4, 2021, restricting American suppliers from servicing the company on the grounds that its tools had "enabled foreign governments to conduct transnational repression" against journalists, dissidents, and activists abroad (BIS; Federal Register). That designation still stands in 2026, even as NSO lobbies for removal. Israel has never taken an equivalent public step against its own licensee. The asymmetry matters: the country with the deepest visibility into who NSO actually sells to — because it approves every sale — has been more permissive than the foreign government relying on secondhand evidence of misuse.

The European Commission's response to the Serbian revelations was characteristically cautious: "any attempts to illegally access the data of citizens and political opponents, if confirmed, are unacceptable" (European Western Balkans). Serbia is an EU accession candidate, which gives Brussels real leverage it has so far declined to spend loudly.

The Innovation Case Still Holds — But Only With Teeth

Israel's cyber-offense sector is a genuine economic asset, and a blanket ban on commercial spyware would push the same capabilities toward less accountable state and criminal developers rather than eliminate them — intrusion capability is not a genie that export bans put back in the bottle. But an accountability regime that updates its buyer list every few years after the last scandal breaks, while never publicly pulling a license after a documented democracy-eve surveillance campaign, is not proportionate regulation; it is regulation in name only. If DECA wants the credibility to keep unilateral national control rather than cede ground to multilateral oversight proposals, it needs a public, case-linked revocation record — not just a periodically refreshed list.

Key Takeaways

Sources & Citations

  1. Citizen Lab: Pegasus Spyware Infection of Serbian Activist
  2. BIS Press Release: NSO Group Added to Entity List
  3. Federal Register: Addition of Certain Entities to the Entity List
  4. The Record: Israel Restricts Cyberweapons Export List
  5. European Western Balkans: EU Statement on Serbia Wiretapping
  6. Lawfare: Can Export Controls Tame Cyber Technology?
  7. The Hacker News: Pegasus Zero-Click Spyware Exploit Serbia