Skip to main content
green gradient background, "The Future of Application Security Is Already Here." and a read the report button.
Serbian Student Targeted by Pegasus: Lessons for Privacy OfficersPrivacy and Security
5 min readFor Privacy Officers

Serbian Student Targeted by Pegasus: Lessons for Privacy Officers

The Challenge

A Serbian student activist received an Apple Threat Notification in late 2025, warning of mercenary spyware targeting. The Citizen Lab and SHARE Foundation's forensic investigation revealed NSO Group's Pegasus infection on the individual's iPhone in December 2025 and January 2026. The attack used an iMessage zero-click exploit, requiring no action from the target.

This wasn't isolated. The SHARE Foundation documented at least 14 similar notifications involving Serbia's student movement, civil society organizations, and an opposition parliament member. The timing coincided with Serbia's 2026 elections, suggesting coordinated surveillance of political opposition.

For privacy officers, this case highlights a fundamental threat: your data subjects can practice perfect digital hygiene and still be compromised. The zero-click exploit gave attackers total device access, including notes, pictures, encrypted messages, microphone, and camera. Without Apple's notification, the infection would have been invisible.

The Environment and Constraints

The investigation occurred against Serbia's history of surveillance abuses. The Citizen Lab noted previous Pegasus targeting of Serbian civil society and the use of Cellebrite forensic tools to plant NoviSpy spyware on activists' devices. Amnesty Tech and the SHARE Foundation confirmed a new NoviSpy variant on another student movement member's device the same day the Pegasus case was published.

The technical constraints were significant. The exploit targeted an iMessage vulnerability that Apple believed it had patched in iOS 18.4.1, released in April 2025. Yet infections occurred in December 2025 and January 2026, indicating either a new variant or incomplete remediation. This timeline gap matters for privacy officers managing mobile device policies: patching alone doesn't guarantee protection against nation-state-grade tools.

Operationally, zero-click exploits leave no behavioral indicators for users to detect. Unlike phishing campaigns where you can train staff to spot suspicious links, this attack surface requires vendor-level intervention and forensic expertise that most organizations don't maintain in-house.

The Approach Taken

The Citizen Lab's forensic methodology centered on Apple's threat notification as the initial indicator of compromise. This represents a critical shift in detection strategy. Rather than waiting for behavioral anomalies or network indicators, the investigation treated the vendor notification itself as presumptive evidence of infection.

The laboratory recommended an immediate escalation protocol for notification recipients: seek expert forensic assistance, expand screening to close contacts and collaborators, enable Apple's Lockdown Mode for high-risk individuals, and maintain current software updates across all devices. For Serbian recipients specifically, they directed people to the SHARE Foundation; for others, to Access Now's Digital Security Helpline.

This approach acknowledges that general-purpose IT security teams lack the specialized capabilities to investigate mercenary spyware. The recommendation to screen close contacts recognizes that adversaries targeting one activist will likely target their network. The Lockdown Mode guidance represents a practical tradeoff: accepting reduced device functionality in exchange for a hardened attack surface.

Results and Metrics

The investigation confirmed Pegasus infection with high confidence across a two-month window. The forensic work on the other 13 notification cases was continuing at publication, demonstrating the resource intensity of spyware investigations. One concrete outcome: identification of a previously unknown NoviSpy variant on another device, expanding the threat intelligence picture for Serbian civil society.

The disclosure itself serves as a deterrent metric. By publishing the investigation with the target's consent (while protecting identifying details), the Citizen Lab created public accountability around surveillance targeting. This transparency increases the reputational and diplomatic cost of using commercial spyware against civil society.

The technical outcome was Apple's patch in iOS 18.4.1, though the timeline reveals the patch's limitations. Privacy officers should note this gap between vendor remediation and real-world protection.

What They Would Do Differently

The Citizen Lab's guidance implies several adjustments for future cases. First, the recommendation to treat threat notifications as presumptive infections suggests earlier forensic intervention would be valuable. Organizations supporting high-risk individuals should establish pre-incident relationships with forensic experts rather than scrambling after notification.

Second, the emphasis on screening close contacts suggests that initial scope definition was too narrow. A network-aware investigation model from the start would better match adversary behavior.

Third, the reliance on vendor notifications highlights a detection gap. Organizations can't wait for Apple or Google to flag infections. Privacy officers should consider whether periodic forensic screening makes sense for executives, activists, or employees handling sensitive negotiations.

Takeaways for Your Team

Redefine your threat model for mobile devices. If your risk assessments assume user behavior drives compromise, you're missing zero-click vectors entirely. Your BYOD policy and mobile device management strategy must account for exploits that bypass user interaction.

Establish forensic investigation pathways before you need them. The Citizen Lab and SHARE Foundation represent specialized capabilities most organizations lack. Identify trusted forensic partners now. For high-risk industries or individuals, consider retainer arrangements. Access Now's Digital Security Helpline and similar resources should be documented in your incident response plans.

Treat vendor threat notifications as critical incidents. Apple and Google's mercenary spyware notifications should trigger your incident response structure immediately. Don't wait for secondary confirmation. The Citizen Lab's guidance to presume infection is the correct privacy-protective stance.

Expand your screening scope. If one device shows indicators of compromise, investigate the target's close contacts and collaborators. Spyware operators work at network scale, not individual scale.

Reevaluate Lockdown Mode policies. Apple's Lockdown Mode significantly reduces attack surface but limits functionality. Privacy officers should work with legal and security teams to identify roles or individuals where this tradeoff makes sense: executives during M&A negotiations, employees traveling to high-risk jurisdictions, or anyone receiving threat notifications.

Update your data minimization practices. If you assume mobile devices can be fully compromised, what sensitive data should never touch them? This case argues for stronger separation between mobile and desktop environments for high-stakes communications.

The Serbian student case demonstrates that privacy protection increasingly depends on vendor security capabilities and forensic expertise beyond most organizations' control. Your job is building the policies, partnerships, and incident protocols that give your people the best chance when those sophisticated tools inevitably target them.

Apple's Lockdown Mode

Promotional banner graphic asking if you are ready for PCI DSS 4.0 with a call-to-action to get the guide

You Might Also Like