Israel Israel NSO Group Pegasus surveillance policy

Serbia's Documented Pegasus Wave Shows Israel's Export-License Regime, Not Just NSO Group, Needs Scrutiny

Citizen Lab and Amnesty confirmed Pegasus hit a Serbian student activist's iPhone, part of a 14-person wave DECA's licensing system was supposed to prevent.

Serbia's Pegasus Wave: The Numbers People of Internet Research · Israel 14+ People targeted since early 2026 Students, activists, an MP, and a … Dec 2025–Jan 2026 Confirmed infection window High-confidence Pegasus indicators… 5 years Years since first NSO scandal Israel's court deferred to DECA's … Oct 2025 NSO ownership shift US investors took controlling owne… peopleofinternet.com
Serbia's Pegasus Wave: The Numbers People of Internet Research · Israel 14+ People targeted since early 2026 Dec 2025–Jan 2026 Confirmed infection window 5 years Years since first NSO scandal Oct 2025 NSO ownership shift peopleofinternet.com

Key Takeaways

A Confirmed Infection, Not an Allegation

On September 2, 2026, Citizen Lab published forensic confirmation that the iPhone of a member of Serbia's student pro-democracy protest movement was infected with NSO Group's Pegasus spyware via a zero-click iMessage exploit, later patched by Apple in iOS 18.4.1. High-confidence indicators place the infection between December 2025 and January 2026. Amnesty International's Security Lab independently corroborated the finding and separately confirmed a domestically-built spyware variant, NoviSpy, on two other devices. Working with the Belgrade-based SHARE Foundation, the two labs situated the single confirmed Pegasus case inside a much larger pattern: at least 14 people — student activists, opposition party members, a sitting Member of Parliament (Radomir Lazović of the Green-Left Front), and a local councilor — received Apple threat notifications since the start of 2026, SHARE Foundation and Citizen Lab reported.

The timing is the story. The campaign clusters around Serbia's March 29, 2026 local elections, a period of opposition coordination that Lazović has since linked to his own contacts with EU officials. Citizen Lab's John Scott-Railton put it plainly in the report: "NSO has spent a decade promising reform... yet the product and the abuses haven't changed." Serbian authorities have dismissed the findings as "trivial sensationalism." NSO Group did not respond to requests for comment.

The Steelman: Why Export Controls on Spyware Exist

The case for tight controls on tools like Pegasus is not hypothetical, and it deserves to be stated fairly before any pro-innovation pushback. Zero-click spyware that silently activates a phone's microphone and camera and exfiltrates encrypted messages is categorically different from ordinary dual-use technology — it functions only by covertly defeating the security of a device the target had every reason to trust. When such tools are sold to governments, the buyer decides who is a legitimate target, and history shows that discretion gets abused against journalists, dissidents, and now, apparently, an opposition parliamentarian and student demonstrators in an EU-candidate country holding elections. A licensing regime that cannot reliably prevent that outcome isn't protecting national security interests; it is outsourcing repression.

Where Israel's Regime Actually Stands

That's precisely why Israel's Defense Export Control Agency (DECA), the Ministry of Defense body that licenses every Pegasus sale, exists — and why its track record on cases like Serbia matters more than its stated policy. DECA's own site describes a licensing process built around "national security," "foreign policy," and preventing transfers linked to terrorism, and the agency did tighten its end-user declaration in the wake of the 2021 NSO scandal, requiring purchasing governments to certify that cyber tools won't be used against legitimate expression or criticism of the state. The problem is enforcement, not text. When Amnesty International and Israeli petitioners asked Tel Aviv's District Court in 2020 to force DECA to revoke NSO's license outright, the court deferred to the ministry's internal vetting, ruling it need not second-guess DECA's process — a deference that looks harder to justify with each new documented abuse case, Serbia included.

NSO Group itself changed hands in October 2025: an American investor group led by producer Robert Simonds took controlling ownership, tens of millions of dollars, with NSO's spokesperson stressing the company "continues to be fully supervised and regulated by the relevant Israeli authorities, including the Ministry of Defense." That reassurance is the crux of the policy problem. Ownership moved to the US; licensing authority, and therefore accountability for who gets to buy Pegasus, stayed in Tel Aviv. NSO remains on the US Commerce Department's Entity List, imposed in 2021, and a 2025 bid for removal was rebuffed — a sharper check, in practice, than anything DECA has produced since.

The Case for Narrower, Verifiable Rules

A blanket export ban would be the wrong lesson to draw. Lawful-intercept and forensic tools have legitimate uses against organized crime and terrorism, and Israel's cyber sector is a genuine source of defensive security innovation that a blunt prohibition would gut alongside the abusive contracts. The proportionate fix is narrower: DECA's end-user declarations should carry automatic, non-discretionary suspension triggers the moment a licensed deployment is independently confirmed against journalists, opposition politicians, or civil society — not case-by-case ministry review that a court has already signaled it won't overturn. Serbia, an EU candidate country whose own parliament member was targeted mid-election-cycle, is as close to an unambiguous trigger case as this framework will ever get. If confirmed misuse against a sitting MP doesn't produce a license suspension, the declaration is a compliance document, not a control.

The alternative — leaving enforcement entirely to reputational pressure from Citizen Lab reports and Amnesty statements, one forensic confirmation at a time — has now run for five years since the first major NSO scandal broke in 2021. Fourteen more names in Serbia is the result.

Sources & Citations

  1. Citizen Lab: Pegasus Spyware Infection of Serbian Pro-Democracy Student Activist
  2. EDRi: 14 Students and Opposition Politicians Targeted by Spyware in Serbia
  3. Israel Defense Export Control Agency (DECA), Ministry of Defense
  4. Amnesty International: Israel court rejects bid to revoke NSO's export license (2020)
  5. TechCrunch: NSO Group confirms acquisition by US investors
  6. The Record: Large group of Serbian opposition, activist figures targeted with spyware