Before SHARE, BIRN, their media outlets, lawyers, the entire civil society sector of Western intelligence services embodied in NGOs, as well as their European political patrons discovered that wiretapping is an unforgivable crime against democracy, the “Sky” affair took place in the heart of Europe. Instead of calling the illegal interception of citizens’ communications, which did not stop at France’s borders, by its proper name – a scandal, a violation of privacy and an attack on fundamental human rights – it was presented to the public as a spectacular victory of European agencies over organized crime.
French, Belgian and Dutch authorities managed to penetrate the encrypted Sky ECC platform and, without individual court warrants from each country where the users were located, monitor the communications of tens of thousands of people beyond their own borders.
BEWARE OF PEGASUS. SKY IS OK.
According to official Eurojust data, by mid-February 2021 European agencies were already able to monitor the flow of information involving around 70,000 Sky ECC users and access hundreds of millions of messages, while a major police operation was carried out on March 9 of the same year. The platform had around 170,000 users worldwide, was operated from the United States and Canada, while its servers were located in Europe. Most of the material later used in Serbia was provided to the domestic authorities by France through mutual legal assistance. However, just as was the case in other European countries, neither the Serbian public nor the defense teams in numerous proceedings were given full insight into how the data had been obtained, decrypted, extracted and linked to specific individuals.
Instead of the proper question being how a foreign agency could massively penetrate the communications of people on the territory of other states, whether all those people were suspects at the time of the surveillance, where the individual court orders were, and how the authenticity of the material provided could be verified, “Sky” was declared almost a sacred text in Serbia. Courts in Germany, Hungary and Austria, and even the Court of Justice of the European Union, in its judgment of April 30, 2024, concerning a similar “EncroChat” operation, addressed the conditions under which data obtained in this manner may be transferred and used, emphasizing the role of domestic courts, the rights of the defense, and the consequences of any violation of EU law. Such information is absent from the Serbian media space.
The same media outlets, NGOs, opposition politicians, lawyers and “students” who today turn Apple’s warning, without public evidence identifying the operator, into supposedly irrefutable proof that the Security Intelligence Agency is spying on protesters with “Pegasus,” treated “Sky” communications for years as something completely normal.
ELEMENTS FOR A POLITICAL NOVEL
The basic questions – who was conducting the surveillance, on whose orders, on whose territory and with what right – were not only never raised, but entire political novels were constructed from fragments of messages, unverified interpretations and usernames, identities were assigned to encrypted accounts, and these constructions were then used to target the highest state leadership, the President of the Republic, his family and his closest associates.
With such an absence of any criticism of the West, we have reached a situation in which an international scandal involving illegal surveillance is called one of the greatest achievements in the fight against organized crime, while an Apple warning on the phone of a blockade activist, even before the attacker was identified, is declared state terrorism, with sanctions against Serbia being demanded. And this brings us to the answer to all those unasked questions: surveillance itself is not what matters, but who is conducting it and the reason for offering a new crisis during the election campaign in the absence of a clear political programme.
As for the latest scandal involving the alleged spying on students, activists and opposition politicians in Serbia, it could be said that the only thing new is the date of publication. The same organization tried to promote the same story in an identical manner three years ago, then two years ago, and finally a few days ago. Apart from the fact that the same people are once again in focus, the method of operation has not changed either: first, phones and warnings are provided to selected media outlets and NGOs, then “independent” partners confirm each other’s findings, and finally, selected European politicians, before any state authority or genuinely independent international investigation has even begun, pass judgment on Serbia and demand political and financial sanctions.

FOURTEEN “INFECTED,” ONE HALF-CONFIRMED
Thus, on September 2, 2026, Citizen Lab published a brief report stating that, in cooperation with the SHARE Foundation, it had found traces of infection with the “Pegasus” spyware on the phone of one unnamed member of the “student movement.” The very next day, while the alleged forensic examination of the remaining phones was still underway, the European Greens knew not only which agency had been involved in the alleged spying operation, but also which punitive measures should be applied.
The first manipulation occurs when technical findings are turned into media headlines and a single lead – the SHARE Foundation announced that since the beginning of 2026 it had registered at least 14 people who had been targets of advanced spyware. But when the statement is read carefully, which is already an undertaking because “everything is in the headline,” the figures and headlines are far from the truth and any kind of sensationalism.
Namely, during August, 12 people who had received an Apple security notification contacted SHARE, but apart from the fact that these were 12 particularly interesting people, the more important point that does not appear in the headlines is the fact that of those twelve individuals who made their phones available to a foreign organization that is an affiliate of a foreign intelligence service, Citizen Lab publicly confirmed a “Pegasus” infection on one device, out of the 12 submitted. For the remaining eleven, it is stated that they received a notification and should therefore be treated as “likely infected,” while the investigation is still ongoing. In addition, a new version of the “NoviSpy” program was allegedly found on two Android phones.
Therefore, it has not been confirmed that 14 phones were infected with “Pegasus.” The only thing Citizen Lab confirms is one “Pegasus” infection, but not who infected the phone, when, or with what intention. Likewise, the eleven Apple notifications indicate that the users were targets, but do not constitute proof that the infection was successful. Two cases concern another program and a different method of installation.
In addition, Apple itself explained that its notifications are based on internal intelligence data that represents an assessment with a high degree of likelihood, but not a claim that is certain.
All of this represents an important distinction between a forensic finding, a security notification, and a politically exploited number promoted by blockade propaganda platforms.
More importantly, Apple explicitly states that, based on these notifications, it does not attribute the attack to a specific attacker, a particular state, or a geographical area.
THE SAME OLD STORY IN A NEW PHONE
We wrote about this network and the way it operates back in 2024, in the articles “Even If He Is an Agent, He Is Mine” and “SHARE Foundation with Four Million Euros in Foreign Donations Provides Evidence of Wiretapping.” At the time, BIRN, Amnesty International and SHARE promoted the claim that the Security Intelligence Agency (BIA) and the Ministry of Internal Affairs (MUP) were abusing the “Cellebrite” forensic tool to unlock the phones of journalists and activists and install “NoviSpy” on them.
Back in November 2023, SHARE announced that two members of the civil society sector of Western intelligence services, that is, members of NGOs, had received Apple warnings. SHARE then, in cooperation with the organization Internews, allegedly obtained confirmation from an unnamed representative of Apple that the messages were authentic, after which Access Now and Amnesty International reviewed the submitted data and confirmed an attempted attack through a vulnerability in the HomeKit function. The details, of course, were not published, allegedly at the request of the phone owners. Because details, the full report and facts are not necessary when the campaign is good.
In December 2024, Amnesty International published a report on the “NoviSpy” program and the phones of Slaviša Milanov, Nikola Ristić and an activist from the “Krokodil” organization. In March 2025, the same Amnesty published a report stating that two BIRN journalists had received Viber messages containing links that allegedly led to “Pegasus” infrastructure. One journalist did not open the link, the other deleted it, and Amnesty explicitly stated that no infection had been found on the analyzed phone.
Two years later, SHARE, Amnesty, Citizen Lab, Apple warnings, and the phones of the same activists are once again on the scene; the only difference is in their roles: the first time they were fighters “for Serbia against violence,” then against lithium, and today they are part of the so-called “student movement.”
SHARE and BIRN are not even organizationally distant worlds that happened to find themselves working on the same issue by chance. The official SHARE Foundation website states that SHARE and BIRN jointly founded the SEE Digital Rights Network in 2020, a regional network comprising more than twenty organizations. SHARE is simultaneously a member of the European Digital Rights network and the international CiviCERT coalition.
“CLEAN FORENSICS”
The first thesis they put forward was based on the falsification of an IP address. However, what is questionable about this thesis is that an infection with a program such as “Pegasus” is not proven by a single suspicious internet address. Forensic investigators must compare a whole range of traces on the phone: messages, system logs, the time when suspicious changes occurred, remnants of deleted files… Therefore, it is not enough for someone to simply “mask” an IP address for that to constitute sufficient evidence of an infection. A much more important question is who had access to the phone before the analysis, whether Citizen Lab was provided with the original data or already extracted logs, and whether any genuinely independent laboratory examined the same, untouched copy of the device. Since these data have not been published, the public cannot independently verify the findings or rule out the possibility that the material was altered or contaminated before the analysis. Along with all of this, one must also accept the possibility that Citizen Lab is indeed an independent organization and that the data concerning that one infected phone are in fact accurate.
If someone wanted to produce a false finding, for which there is reasonable suspicion, they could easily contaminate the forensic material, backup, databases, system logs, or the manner in which the phone was obtained and copied.
That is why one of the key elements is also the chain of custody, who had the phone, for how long, in what condition, which tool was used to create the copy, what the control hashes of the original and the copy were, and whether an independent laboratory received a sealed copy or an already prepared selection of “relevant” logs.
A SCANDAL AS IRREFUTABLE PROOF
Citizen Lab’s brief report contains none of these details. It does not even state the phone model, the operating system version at the time of the alleged infection, the method used to obtain the data, the control hashes, the complete timeline of the analysis, or who had access to the device before the material reached Toronto. Nor does it provide information on which specific indicators led to the conclusion that it was specifically “Pegasus.”
In certain cases, there are reasons not to disclose some of the indicators, primarily because the spyware manufacturer could study them and adapt or improve new versions. But when a particular political group makes a spectacular appearance offering “evidence,” demands the financial blockade of an entire state, and makes the most serious accusations, there is no good excuse for the absence of all the data.
However, aware of what can be presented to a segment of the public that still believes the Sky application is like WhatsApp or Viber, and to whom these same media propaganda platforms serve up their thrillers from the French espionage affair as irrefutable proof that Serbia’s entire state leadership is involved in crime, they will never pay attention to those “secondary details.” All it takes is a good headline, and the show can begin.
A “PATCH” OLDER THAN THE ALLEGED ATTACK
A particularly interesting detail in Citizen Lab’s report is the timing of the alleged infection. They claim that the phone was infected between December 2025 and January 2026, but at the same time state that Apple introduced protection against such an attack back in iOS 18.4.1, released on April 16, 2025. Put simply, Apple “fixed the lock” eight months before the alleged intrusion. The attack could nevertheless have succeeded if the phone’s owner had not installed that update and continued using an older version, which is something that almost never happens among users of these phones. Admittedly, alongside all the other important answers, Citizen Lab also failed to disclose which phone model was being used at the time of the attack.

A GRANT AS A GUARANTEE
If we had not had the experience of October 5 and the fact that in 2000 we were a testing ground for hybrid warfare, foreign funding in itself would not be proof that someone’s forensics were false. But if all of the above is taken into account and the organization’s activities are viewed within the broader ecosystem – whom it submits project reports to, which topics it chooses, and with whom it builds international campaigns – then the reasonable suspicion and question arise: who pays the organizations that simultaneously produce the technical finding, the media interpretation and the political pressure?
Earlier media reports published estimates that the NGO SHARE had received around four million euros through various foreign donations by 2023. The latest data from the Serbian Business Registers Agency (APR) show total revenues of the SHARE Foundation amounting to 67.453 million dinars in 2023, 79.561 million in 2024, and 76.091 million dinars in 2025, a total of more than 223 million dinars in just three years. If we disregard other grants that do not pass through the APR system, because, in an effort to avoid visible sources of funding, most NGOs today operate on a system of blockchain and donations, we are not dealing with a spontaneous group of enthusiasts who examine phones in their spare time.
Citizen Lab is also not a volunteer organization that is financially self-sustaining. On its own funding page, it lists the Ford Foundation, MacArthur Foundation, Oak Foundation, Open Society Foundations, Hopewell Fund, Sigrid Rausing Trust and other donors. The laboratory simultaneously claims that it operates independently of government and corporate interests, which does not at the same time imply that it operates independently of a far more dangerous bloc, namely the NGO sector and the so-called deep state.
THE GREENS’ ASSAULT
Perhaps the crucial evidence that this affair has had a political background from the very beginning was not found on that one phone, but in the speed of certain European politicians.
Citizen Lab and SHARE published their findings on September 2. As early as September 3, the Greens group in the European Parliament announced that the Serbian government had “actively spied on at least 14 people over a period of two years.”
But SHARE listed 14 targets since the beginning of 2026, not 14 people proven to have been infected over a period of two years. Citizen Lab publicly confirmed one infection and did not publish a single piece of evidence attributing the operator to the Serbian government. That did not stop the Greens from demanding the freezing of all payments to Serbia allocated through the development and pre-accession funds under IPA III, as well as international oversight of the BIA and MUP.
Green MEPs particularly insist that a member of their team, a person who is a statistical error in Serbian politics, Radovan Lazović, co-president of the Green-Left Front and a member of the European Green Party, was a target. These claims have absolutely no evidence whatsoever, but the fact that Lazović is part of the European Green community has shifted this entire affair to the international level. So, the political connection is no secret; it is practically written into the statement itself.
The official position of the European Union was, at least formally, more cautious: spying on political opponents would be unacceptable “if confirmed,” Radio Free Europe reported. The Greens, however, skipped the “if confirmed” condition and went directly to demanding that funding to Serbia be halted and that domestic security services and the MUP be placed under foreign oversight.
THE MOMENT WAS WAITED FOR…
Earlier attempts to push these theses were merely a dress rehearsal and a wait for the right political moment. The affair was launched at a time when the election campaign is in full swing and the elections are just around the corner. But since the blockade list, or the so-called “student list,” has neither official names nor a political programme, the only tried-and-tested way to mobilize student and opposition structures anew is to promote new spins and accusations against the state.
Following the deliberately provoked clash in Užice, domestic activists are given a new moral argument: the narrative is that the authorities are so afraid that they are using the world’s most expensive spyware weapon. Foreign politicians are given a reason to demand the suspension of funds, the diplomatic isolation of Belgrade, and external oversight of the security services. The media are given the word “Pegasus.”
Thus, the “domestic” political conflict does not remain within Serbia’s borders, but takes on an international dimension. And Serbia, of course, remains the accused party, which must prove that it did not do what the prosecutor has not yet presented complete evidence for.
SHARE and Citizen Lab do, admittedly, face a serious logistical and propaganda problem if someone demands a genuine verification of their findings. The Serbian state should also, in addition to conducting its own forensics, involve an independent party, because the mere term “Pegasus” is not enough to say, for example, why the traces on the phone allegedly could not have been introduced afterward. They would have to address system logs, cryptographic hashes, databases, timestamps, network indicators and the chain of custody.
The average social media user will stop listening after the second sentence.
ONE MAN TOLD ME
On the other hand, a simple message is enough: “Western NGOs prepared fake phones in order to bring down Serbia.” A technically complex explanation almost always loses the media battle against a simple and emotional claim, which is why we have reached a situation where a good headline, subtitle and lead are enough for a claim, and often even a post from an anonymous social media account.
That is precisely why criticism of this affair must not be reduced to an equally simplistic conspiracy theory. There is no need to prove “IP spoofing,” nor to invent an invisible hacker who manually wrote every log; it is enough simply to ask questions that a serious forensic investigation must be able to answer.
Who took possession of each phone, and when? Who had physical access to the devices before the forensic copying? Are there hashes of the original copies? Which version of the operating system was installed at the time of the attack? Did Apple directly confirm the authenticity of all twelve warnings? Which findings confirmed an infection, and which indicated only an attempted attack? How many of the 14 people were actually infected? On the basis of what public evidence is the “Pegasus” operator attributed to the BIA, MUP or some other intelligence service? Did any laboratory that is not organizationally, project-wise or donor-wise connected to this network receive a sealed copy of the material?
As long as there are no answers to these questions, everything remains at the level of – one man told me, take my word for it.




