"This is not a technical glitch; it is a direct state attack on democracy," the 29 MEPs wrote Friday.
Forensic findings from the SHARE Foundation, Amnesty International, and The Citizen Lab
A report referenced by the European Parliament signatories this week, produced by the SHARE Foundation and corroborated by Amnesty International and The Citizen Lab at the University of Toronto, identified spyware infections on the phones of Serbian student activists and other targets. The groups reported finding both Pegasus and NoviSpy infections. They did not assign responsibility for the Pegasus infections, but said evidence from the NoviSpy infections pointed to Serbian government authorities.
Demands from the 29 MEPs and their framing
The group of 29 members of the European Parliament urged a range of concrete responses from EU institutions. Their letter demanded that Serbia’s accession process be slowed until an investigation into the reported spyware usage is completed, and that Serbia’s EU accession be made contingent on improving rule-of-law accountability. The MEPs also called for President Ursula von der Leyen to cancel a planned visit to Serbia. In the letter they warned: “With upcoming elections ahead, Aleksandar Vučić’s regime is using illegal digital surveillance to systematically dismantle political opposition.”

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleDiplomatic ripple: von der Leyen, Marta Kos, and Serbia
The spyware allegations landed on top of existing tensions between EU leaders and Belgrade. European leaders had already expressed outrage at Serbia’s response to the death of former Bosnian Serb army commander Ratko Mladic; the source reports that Enlargement Commissioner Marta Kos canceled her own visit Friday over the alleged “glorification” of Mladic. The spyware letter adds a separate strand of pressure on the Commission and member states to rethink engagement with Serbia. The MEPs wrote bluntly that “Appeasement has failed” and demanded that the Commission demonstrate that “compliance with fundamental democratic standards is a non-negotiable requirement, not an option.”
EU institutions and internal scrutiny: PEGA committee and member-state allegations
The letter from the 29 MEPs arrives amid broader European concern about misuse of surveillance tools. The source notes that EU member nations have faced their own allegations over using spyware. Recent revelations of spyware found on the device of a member of the European Parliament’s PEGA Committee have prompted renewed calls to enact recommendations from that committee to address spyware abuses — a domestic pressure point inside EU institutions that overlaps with calls to hold candidate countries to democratic standards.
What this means for policymakers, technologists, and Serbian activists
- Policymakers and regulators: The MEPs’ demands explicitly seek to make accession conditional on an investigation and on improvements to rule-of-law accountability; Hannah Neumann, an MEP who signed the letter, told CyberScoop that “It could very well be that some of these demands will be honored, but for sure the spyware won’t be the only reason why.” That comment signals political appetite in parts of the Parliament to press the Commission and member states for concrete consequences.
- Technologists and security teams: Independent forensic work by the SHARE Foundation, Amnesty International, and The Citizen Lab established the presence of Pegasus and NoviSpy on devices tied to Serbian targets, with NoviSpy evidence pointing to government authorities. The finding — and the PEGA-related revelations inside the Parliament — is likely to reinforce calls for EU-level technical and policy responses to spyware misuse.
- Serbian activists and civil-society groups: Student activists were explicitly named as having infected devices in the SHARE Foundation report cited by the MEPs. The letter frames the alleged surveillance as a tool used ahead of elections to undermine opposition, and the Serbian government did not respond to multiple requests for comment late Friday, according to the report.
The immediate next steps set out in the record are procedural and political: an investigation into the reported spyware infections and pressure on the European Commission and member states to decide whether to heed MEP demands to slow accession and to condition progress on rule-of-law reforms. The record in the source is also clear about the broader context: allegations of spyware misuse are not confined to candidate countries, and revelations inside EU bodies have already renewed calls for institutional reforms. How the Commission and member states respond to the MEPs’ letter — whether visits are canceled, investigations opened, or accession timelines altered — will determine whether the letter becomes a turning point or another escalation in an already fraught relationship between Brussels and Belgrade.
Original reporting: https://cyberscoop.com/eu-parliament-serbia-accession-spyware-demands/




