Suing spyware in Europe: news from the front!
Lori Roussey, Celia/Irídia
39th Chaos Communication Congress (39C3): Power Cycles · Day 2 · Saal Ground
Overview
This talk, "Suing spyware in Europe: news from the front!", delivered by Lori Roussey of Data Rights and Celia from Irídia, delves into the escalating use of mercenary surveillance tools like Pegasus across Europe and the strategic legal battles being waged to combat their unchecked proliferation. The speakers illuminate a disturbing pattern of state-sponsored surveillance targeting human rights defenders, journalists, and lawyers, often without judicial oversight or notification, severely undermining democratic principles and fundamental rights.

Key moments
- 0:00 Speakers introduce organizations and Catalonia political context
- 3:20 Lawyer Andreo's phone infected with Pegasus during lockdown
- 4:00 Citizen Lab reveals 65 Catalan people surveilled by Pegasus
- 4:35 Spanish intelligence suspected; 47 people illegally spied on
- 6:30 Filing criminal complaint against NSO Group for developing Pegasus
- 7:55 NSO Group's complex network and operational gateway in Europe
Suing spyware in Europe: news from the front!
Speakers: Lori Roussey, Director of Data Rights; Celia, Irídia
Conference: 39C3
YouTube: https://www.youtube.com/watch?v=cAemJTHckN4
Overview
This talk, "Suing spyware in Europe: news from the front!", delivered by Lori Roussey of Data Rights and Celia from Irídia, delves into the escalating use of mercenary surveillance tools like Pegasus across Europe and the strategic legal battles being waged to combat their unchecked proliferation. The speakers illuminate a disturbing pattern of state-sponsored surveillance targeting human rights defenders, journalists, and lawyers, often without judicial oversight or notification, severely undermining democratic principles and fundamental rights.
The presentation highlights the critical work of organizations like Irídia and Data Rights, which are at the forefront of strategic litigation, aiming to hold not only states but also the companies that develop and export these powerful tools accountable. By sharing insights from ongoing cases in Spain, Hungary, and Poland, the speakers underscore the urgency of a unified European response. The core message emphasizes the necessity of breaking the "wall of impunity" enjoyed by spyware vendors and state actors, advocating for robust legal precedents and systemic changes to safeguard an internet free from arms races and monopolies.
The talk matters because it exposes how advanced surveillance technology, initially touted for national security, is actively being weaponized to suppress dissent, manipulate public discourse, and erode the rule of law within democratic nations. It serves as a call to action for legal professionals, activists, and the cybersecurity community to collaborate in developing comprehensive strategies—from litigation to policy reform—to counter the "authoritarianism as a service" model that spyware enables, ultimately striving for a future where digital security is recognized as an integral component of human rights.
Background
▶ Watch: Speakers introduce organizations and Catalonia political context (0:00)
The problem of state-sponsored spyware in Europe is deeply rooted in a confluence of political contexts, technological advancements, and regulatory vacuums. Celia opens the talk by detailing the tumultuous period in Catalonia between 2017 and 2021, marked by popular mobilization for self-determination and the controversial 2017 independence referendum. This politically charged environment became the backdrop for widespread surveillance, with Citizen Lab later confirming that at least 65 individuals in Catalonia—including human rights defenders, activists, computer scientists, family members of politicians, and elected officials—were spied on using Pegasus and Candiru. These findings, corroborated by Amnesty Security Lab, revealed that the spying began as early as 2015, positioning Spain as a significant client of NSO Group.
A key aspect of this background is the legal and ethical quagmire surrounding the surveillance. Andreo, a lawyer and Irídia board member, was among those targeted, his phone infected with Pegasus due to his work defending political prisoners. This act aimed to access confidential client information and undermine legal defense strategies. The primary suspect, the Spanish National Intelligence Center (CNA), operates under a 1968 Official Secrets Act, signed by Franco, which classifies all its activities as secret. While neither the CNA nor the Spanish government has officially confirmed the surveillance, the dismissal of the CNA director shortly after the CatalanGate revelations, coupled with leaks suggesting only 18 of the 65 targets had judicial authorization, pointed to systemic illegal spying. This highlights the severe lack of transparency and accountability inherent in Spain's legal framework, where judicial oversight is often theoretical, and targets are never notified.
The existence of this problem is intrinsically linked to the business model of companies like NSO Group, founded in 2010 to address a "European need." Their flagship product, Pegasus, has evolved from requiring user interaction (a "click") to sophisticated zero-click exploitation, capable of not only accessing communications and extracting data but also manipulating content on the device itself. NSO Group's operational structure as an "umbrella brand" with a global network of companies, including a significant hub in Luxembourg (e.g., Q Cyber Technologies and OSY Technologies), further complicates accountability. These entities are not merely passive distributors; evidence shows their active involvement in deployment, installation, monitoring, and ongoing operational support, enabling a "wall of impunity" that strategic litigation aims to crack.
Key Findings
▶ Watch: Citizen Lab reveals 65 Catalan people surveilled by Pegasus (4:00)
The talk reveals several critical findings that underscore the pervasive nature of state-sponsored spyware and the emerging legal strategies to counter it:
- Groundbreaking Legal Precedent Against NSO Group Directors: In a global first, a judge in Spain accepted Irídia's request to indict directors of NSO Group's Luxembourg-based companies (OSY Technologies and Q Cyber Technologies) in connection with the Pegasus targeting of Andreo. This marks the initial criminal investigation anywhere in the world directly involving NSO directors for their role in a Pegasus victim's case, significantly challenging the long-standing impunity of spyware manufacturers and setting a precedent for future litigation.
- NSO Group's Active Role and Corporate Veil: Investigation into NSO's corporate structure revealed direct and structural ties between its Israeli entity and its Luxembourg subsidiaries, including shared board members (like NSO founders Lavi and Shalev Julio) and offices. Crucially, the evidence demonstrated NSO's active participation in the deployment, installation, monitoring, and operational support of Pegasus, disproving the claim of passive software distribution and establishing a corporate chain of responsibility.
- Patterns of Surveillance and "Authoritarianism as a Service": Across Spain, Hungary, and Poland, a consistent pattern emerged: primary targets are individuals in historically protected professions crucial for democracy, such as lawyers and investigative journalists, particularly those working on anti-corruption. This systematic targeting suggests that spyware functions as "authoritarianism as a service," undermining the separation of powers, free press, rule of law, and basic freedoms.
- Absence of Notification and Effective Remedy: Despite a 2020 EU court ruling (stemming from a French case Data Rights was involved in) mandating notification after secret surveillance when a threat is no longer perceived, none of the 65 Spanish victims were notified. This lack of notification prevents individuals from becoming aware of rights violations, seeking remedies, or implementing necessary safeguards, leaving them without any avenue for justice.
- Judicial Resistance to Independent Forensic Evidence: In Spain, judges repeatedly rejected forensic analyses from reputable organizations like Citizen Lab and Amnesty Security Lab as evidence. Instead, victims were asked to pay for additional independent analyses or, more alarmingly, submit their phones to the police for testing, a process deemed "re-victimization" that further obstructs justice and places an undue burden on targets.
- Spyware's Capacity for Data Manipulation (Polish and Indian Cases): The Polish case demonstrated spyware's capability to extract vast amounts of data (10 years of text messages), which were then rearranged by law enforcement to create a false narrative and used in a smear campaign on national television during elections. An even more egregious example from India involved police partnering with hackers to inject fake evidence onto activists' computers via Pegasus, leading to their subsequent arrest and imprisonment. These cases highlight a critical shift from mere surveillance to active data integrity attacks and evidence fabrication.
- Strategic Litigation and Cross-European Coalition: Recognizing the fragmented and often ineffective national responses, a coalition of European organizations, including Data Rights and Irídia, has been launched. This coalition aims to pool resources, share strategies, and pursue strategic litigation across Europe, with the ultimate goal of establishing precedents in European courts and pushing for comprehensive policy change.
Technical Deep Dive
▶ Watch: Spanish intelligence suspected; 47 people illegally spied on (4:35)
The technical aspects of spyware, particularly Pegasus, are central to understanding its profound impact and the challenges in combating its misuse. Initially, Pegasus required user interaction, often via a malicious link that, once clicked, would install the spyware. However, it has alarmingly evolved to zero-click exploitation, meaning it can infect a device without any user action, simply by exploiting vulnerabilities in popular operating systems or applications. Once installed, Pegasus grants extensive control over a personal device, enabling access to communications, extraction of virtually all data, and crucially, the manipulation of content on the device itself. This capability extends beyond passive listening to active interference, allowing attackers to plant or alter information.
The talk highlights the devastating potential of such capabilities through specific examples of data integrity attacks. In the Polish case, Pegasus was used to extract a decade's worth of text messages from a politician's phone. Law enforcement then "rearranged" these texts, merging different messages to construct an entirely new, fabricated narrative, which was subsequently broadcast on national television during elections. This demonstrates how spyware can be leveraged not just for information gathering but for active disinformation campaigns. An even more chilling example from India involved police partnering with hackers who used Pegasus to infect activists' computers and then "inject" fake evidence onto those devices using another tool. This fabricated evidence was then used by the police to raid and imprison the activists, illustrating the extreme dangers of tools that grant full administrative control over a device.
Lori Roussey emphasizes that the core issue extends beyond "just a new surveillance tool" to the inherent risks of stockpiling hacking tools and zero-days. She cites the WannaCry ransomware attack as a stark reminder of how stolen hacking tools (reportedly developed by the NSA) can wreak havoc on critical infrastructure globally. This underscores the argument that stockpiling zero-days turns governments into "honeypots" for malicious actors. The Constitutional Court of Germany has highlighted that cybersecurity is intertwined with fundamental rights, implying that states unable to manage vulnerabilities effectively should not possess such tools.
Furthermore, the speakers touch upon the highly monopolistic environment of operating systems, with essentially two dominant mobile OS platforms. This concentration makes it economically viable for spyware developers to invest heavily in finding vulnerabilities that grant broad access. A more diversified OS landscape would significantly increase the cost and complexity of developing effective spyware, thereby acting as a natural deterrent.
Finally, the talk broadens the scope to categorize spyware as a dual-use technology. These are technologies with potent military and civil applications, often developed for legitimate purposes but easily repurposed for nefarious ones. Other examples include AI, satellite imagery, and biometrics. The example of biometric cameras trained in China to recognize ethnic origins of Muslims for police alerts illustrates how seemingly neutral technologies can be weaponized for discriminatory surveillance. This dual-use nature makes states reluctant to implement safeguards, as they perceive an "edge" in possessing such capabilities, leading to an urgent need for tech-neutral conversations and regulations that anticipate future challenges, such as the convergence of AI and spyware.
Demo / Proof of Concept
▶ Watch: Filing criminal complaint against NSO Group for developing Pegasus (6:30)
The talk focused on legal strategies, investigative findings, and the broader implications of spyware misuse rather than presenting a live technical demonstration or proof of concept. The information regarding Pegasus's capabilities and exploitation methods was derived from forensic analyses and reports by organizations like Citizen Lab and Amnesty Security Lab, which confirmed infections on targeted devices.
Defensive Implications
▶ Watch: NSO Group's complex network and operational gateway in Europe (7:55)
The revelations from "Suing spyware in Europe: news from the front!" carry profound implications for cybersecurity defenders, human rights advocates, and policymakers, necessitating a multi-faceted defensive strategy:
- Strategic Litigation and Accountability: The most direct defensive implication is the need for aggressive strategic litigation against both states and the companies that develop and distribute spyware. The Barcelona case, in which NSO Group directors are being criminally investigated, sets a crucial precedent. Defenders should support and replicate such efforts, focusing on establishing corporate and individual liability for human rights abuses linked to spyware. This involves demonstrating the active participation of companies in deployment and support, not just passive distribution.
- Mandatory Notification of Surveillance: A fundamental safeguard highlighted is the mandatory notification of surveillance to targets once they are no longer considered a threat. The 2020 EU court ruling on this matter, though widely ignored, provides a legal basis. Defenders must advocate vigorously for the enforcement of this right, as it is essential for individuals to seek effective remedies and protect their digital security.
- Acceptance of Independent Forensic Evidence: National courts' reluctance to accept forensic analyses from reputable independent labs (like Citizen Lab and Amnesty Security Lab) is a critical barrier to justice. Defenders must push for judicial education and reform to ensure that scientifically sound, independent evidence is admissible and given due weight, rather than forcing victims into re-victimizing processes of police-led investigations.
- Prioritizing Vulnerability Management over Stockpiling Zero-Days: Governments must fundamentally shift their approach from stockpiling zero-day exploits to prioritizing robust vulnerability management. The German Constitutional Court's stance—that states unable to ensure cybersecurity for their citizens should not use spyware—underscores this. Stockpiling exploits creates dangerous "honeypots" that can be stolen and unleashed globally, as seen with WannaCry. Policy should discourage the trade and use of zero-day exploits.
- Diversification of Operating Systems: As a long-term strategic defense, promoting a more diversified ecosystem of operating systems can significantly raise the cost for spyware developers. If hacking tools need to target numerous platforms rather than just two dominant ones, the economic viability of universal spyware would diminish.
- Regulation of Dual-Use Technologies: The current EU dual-use regulation, which governs the export of technologies with both civilian and military applications, is deemed a "disaster" and easily bypassed. Defenders must advocate for a comprehensive overhaul of these regulations to prevent the uncontrolled spread of surveillance technologies. This includes scrutinizing rebranding efforts by companies like NSO Group and their attempts to operate under less stringent regulatory environments.
- Empowering Activist and Citizen Coping Strategies: While legal battles are crucial, individuals and activists must also be empowered with practical coping strategies for digital self-defense. This includes using more secure networks, adopting privacy-enhancing tools, and regularly auditing device security, even if full detection of zero-click exploits remains challenging.
- Countering Public Discourse: Defenders need to actively counter narratives that justify spyware use against "terrorists" or "separatists." Public education and collaboration with investigative journalists are vital to expose abuses and shift public opinion towards recognizing spyware as a threat to fundamental freedoms for everyone.
- International Cooperation and Data Life Cycle Understanding: The formation of cross-European coalitions (like the PEGA coalition) is essential for sharing strategies, legal arguments, and resources. Furthermore, a more granular understanding of the data life cycle—from infection to data exfiltration and storage—is crucial for forensic analysis and legal argumentation, requiring greater collaboration between researchers, lawyers, and cybersecurity experts.
- Enforcing Existing Laws: Ultimately, as highlighted by the speakers, "most safeguards already exist." A significant defensive step is simply ensuring that existing laws and human rights principles are rigorously followed and enforced by states, rather than constantly seeking new legislative solutions while current ones are ignored.
Key Takeaways
- Pioneering Legal Action Against Spyware Vendors: The criminal investigation initiated in Spain against NSO Group directors marks a critical global precedent, challenging the long-standing impunity of spyware manufacturers and establishing a pathway for holding corporate entities accountable for human rights violations.
- Spyware as a Tool for Authoritarianism: Pegasus and similar tools are systematically used by states, often illegally and without judicial oversight, to target journalists, lawyers, and activists, effectively functioning as "authoritarianism as a service" to undermine democratic safeguards and fundamental freedoms.
- Beyond Surveillance: Data Manipulation and Fabrication: Advanced spyware capabilities extend beyond mere data interception to active data manipulation, including rearranging texts for smear campaigns (Poland) and injecting fake evidence onto devices (India), demonstrating a severe threat to data integrity and the justice system.
- Systemic Barriers to Justice in Europe: Across Europe, victims face significant obstacles, including a lack of notification about surveillance, judicial reluctance to accept independent forensic evidence, and inadequate legal frameworks that allow unchecked use of spyware, creating a "re-victimization" cycle for those seeking justice.
- The Power of Cross-European Strategic Litigation: A coalition of European organizations is actively building a unified strategy for litigation to address these abuses, aiming to establish binding legal precedents at the European level and push for comprehensive policy reforms against mercenary surveillance tools.
- Urgent Need for Policy Reform and Technical Safeguards: Effective defense requires a shift from stockpiling zero-days to robust vulnerability management, diversification of operating systems, and a fundamental overhaul of dual-use technology export regulations, coupled with increased public awareness and digital self-protection strategies.
About the Speaker(s)
Lori Roussey is the Director of Data Rights, an organization that began its activities in 2024 with a scope covering the entirety of the EU. Data Rights is dedicated to fighting for an internet free from arms races and monopolies that control people's lives. Lori has a background in legal advocacy, having been involved in a significant 2020 case in France that led to a top EU court ruling on the necessity of notifying individuals after secret surveillance. Her work focuses on leveraging legal frameworks to push for accountability and systemic change in the realm of digital rights.
Celia represents Irídia, a human rights association based in Catalonia, Spain. Irídia specializes in civic and political rights, employing a multi-faceted approach that combines direct support for victims of rights violations with strategic litigation, psychosocial intervention, transformative communication, and political advocacy. Celia and Irídia work from an intersectional and feminist perspective, aiming to promote public policy change and achieve justice for those affected by human rights abuses, including state-sponsored surveillance. Their current focus includes leading the criminal complaint in Spain against NSO Group directors in connection with the Pegasus spying scandal.
All talks from 39th Chaos Communication Congress (39C3): Power Cycles