News

Digital Hunting Season

Quarterly Report

The latest overview of the state of digital rights in Serbia covers the period from June to the end of August 2026. During this time, we recorded 48 digital rights violations. By far the largest share fell into the category of fraud, threats, and manipulation – 39 cases in total. Of the remaining two categories, four cases involved violations of privacy and data protection, while five involved cyber incidents. In as many as 27 cases, the violations were classified as security threats, and in 23 of those, the targets were people from the media sector.

The Flight of Pegasus

On August 13, Apple sent the latest round of threat notifications to users in 110 countries, warning of remote targeting by advanced spyware such as Pegasus. Serbia was among the countries affected, with at least 12 high-risk individuals from the student movement, the opposition, and civil society receiving an Apple warning. This is the largest wave of phone spyware targeting since late 2023, when information about Apple notifications first surfaced in Serbia involving members of civil society. As Apple advises, these warnings should be taken seriously, since there is a high degree of confidence that the targeted devices were attacked because of what their owners do.

The Citizen Lab at the University of Toronto and Amnesty International’s Security Lab, working with the SHARE Foundation, found indicators pointing to the first recorded Pegasus infection on an iPhone in 2026, as well as traces of a new type of Android spyware. According to Citizen Lab’s analysis, the iPhone of a student movement member was infected through a zero-click attack between December 2025 and January of this year. Separately, the Security Lab confirmed that two Android phones were infected with a new version of the NoviSpy spyware, first uncovered in 2024 and described in the report “Digital Prison”. The new spyware scandal has drawn reactions from the EU and the US, adding further international pressure on the ruling structures.

The use of invasive spyware tools, whether deployed remotely or through physical access to a device, is illegal under domestic law in any context, while targeting political dissidents and civic activists undermines the very foundations of the constitutional order. Given that early elections appear likely following a request to the President to dissolve the National Assembly, this unlawful surveillance carries further consequences for privacy and fundamental rights such as freedom of expression and movement, threatening a broader range of political freedoms as well.

Digital Hunt for Media Workers

The period under review saw an extremely high number of threats and increasing pressure against media workers online. Notably, attacks also targeted figures from the wider media community, such as Veran Matić, who spoke about the very difficult security situation imposed on the journalist profession in Serbia. Pressure from those in positions of power escalated into open persecution of reporters, some of whom were forced to leave Serbia — the case of military analyst and journalist Aleksandar Radić is illustrative. According to ANEM, four journalists left Serbia in the first six months of the year. Amid the anticipation of early parliamentary elections and the civic unrest still sweeping the country, journalists find themselves to be easy targets, facing constant pressure over their work and public activity, without effective protection from institutions that are constitutionally and legally obligated to provide it.

Veran Matić, chairman of ANEM’s Managing Board, was the target of several consecutive threats on social media in late July and early August. The threats followed his appearance on KTV channel, where he spoke about the state of media freedom in Serbia. As a prominent media figure active in protection of journalists, Matić is frequently targeted both online and in pro-regime media. Nenad Kulačin and Marko Vidojković, hosts of the podcast “The Good, the Bad and the Ugly,” were also threatened multiple times – even after news that earlier threats had been reported or, in Vidojković’s case, that he had been shortlisted for an award for persecuted writers.

The impunity surrounding these threats is especially worrying in smaller communities, where the media situation is chronically worse than in Belgrade and other major cities. Threats continued against Kristina Demeter Filipčev, editor of the “Bečejski mozaik” portal, while the editorial teams of two Vranje-based outlets — Vranje News and Slobodna reč — were also targeted, as was Marija Popović, a journalist with the Lazarevac-based portal “Pravo u centar,” who received death and rape threats. In the case of threats against the editorial team of “Volim Zrenjanin,” the suspect was at least quickly identified and arrested, but in most other cases, the response from the relevant authorities has not been effective, even when the threats came from social media accounts that were not pseudo-anonymous.

One case that illustrates how state institutions and political figures treat the media is the ruling against the Novi Sad-based portal 021.rs, which was ordered by a first-instance court to pay 70,000 dinars in non-material damages for mental distress caused by harm to honor and reputation, following a lawsuit by politician and journalist Nemanja Šarović. Šarović sued the portal for reproducing, in full, an article from the RTS website that included an insulting statement made about him by National Assembly Speaker Ana Brnabić. Although the ruling can be appealed, the case risks setting a precedent regarding the reprinting of other people’s statements, even when reproduced fully and accurately.

Data Like Confetti

Privacy violations in Serbia’s digital environment have become routine, often used as a tool to discipline the disobedient. One such case occurred in Valjevo, where the high school grades of young activist Vuk Vasiljević were read out live on local television, accompanied by mockery and belittling. Given that student grades in electronic school records are protected by technical and organizational safeguards – access is not open even to every teacher of the students – this raises questions about the abuse of access privileges, which is punishable by law. Just how porous Serbia’s student data-processing system is was also shown by the leak of entrance exam results for high schools, which ended up on social media through means that remain unknown.

At the same time, technical flaws in information systems that process the data of millions of citizens remain a persistent weak point, even for state bodies presumed to have the capacity to properly implement protective measures. A recent incident involving the Republic Health Insurance Fund (RFZO) again showed that state systems can often be breached without any sophisticated malware. A user on a hacking forum claimed to have obtained RFZO databases containing roughly five million valid entries. Portions of databases reportedly include highly sensitive data, such as insured persons’ ID numbers (LBO), unique citizen ID numbers (JMBG), doctors’ specializations, healthcare institutions, and the name of each patient’s chosen physician. According to posts on the cybersecurity forum Bezbedan Balkan, the attacker exploited a flaw on a data-verification page on RFZO’s official website.

Against this complicated social backdrop, a draft of the new law on personal data protection was put out for public consultation over the summer. However, changes to the provisions themselves are overshadowed by the urgent need for stronger institutions that consistently enforce regulations in both the public and private sectors, and by the need to finally end the practice whereby breaches of citizens’ data – especially mass breaches – go unpunished and unaddressed. Milan Marinović, the outgoing Commissioner for Information of Public Importance and Personal Data Protection, saw his mandate expire in July, and with early elections and the formation of a new parliament pending, it could be several more months before a successor is appointed. In the end, it is once again ordinary citizens who bear the brunt of institutional and legal uncertainty.

Related content

Facing Digital Risks

Quarterly report In the latest overview of the SHARE Foundation’s digital rights monitoring in Serbia, a total of 35 digital rights violations were recorded between March and the end of May 2026. Fraud, threats and manipulation once again accounted for the largest number of cases, with 22 incidents. The other two categories were significantly less […]

Digital sabotage and physical endangerment

Quarterly report In the latest overview from the digital rights monitoring in Serbia, carried out by the SHARE Foundation, a total of 57 violations of human rights in the digital environment were recorded from December until the end of February 2026. The fraud, threats and manipulation category was again the most prominent with 48 violations. […]

Monitoring digitalnih prava u 2025. godini: Glasovi otpora digitalnom nasilju

SHARE Fondacija je objavila redovan godišnji izveštaj monitoringa povreda digitalnih prava u Srbiji “Glasovi otpora digitalnom nasilju” sa analizom trendova iz preko 250 incidenata zabeleženih u proteklih 12 meseci. Izveštaj monitoringa ove godine obuhvata period od novembra 2024. do decembra 2025. i dokumentuje dramatičan porast slučajeva zloupotrebe tehnologija u cilju nadzora, političkih pritisaka, tehničkih napada […]