Visualização de leitura

Dark Web Service Nexus Sells 153M+ Driver’s Licenses

FBI probes suspected breach at IDScan.net after dark web service Nexus offered 153M+ US and Canadian driver’s license scans.

A dark web identity theft service called Nexus appeared on September 1, 2026, offering searchable access to more than 153 million scanned driver’s licenses belonging to people in the United States and Canada.

The FBI’s New Orleans field office opened a formal investigation the same day. Brian Krebs at KrebsOnSecurity, who broke the story, traced the source to idscan.net, a New Orleans-based identity verification company whose clients include Hertz, Target, FedEx, Motorola Solutions, Caesars Entertainment, and the financial services firm Jack Henry.

“On Monday, Aug. 31, a source alerted KrebsOnSecurity to a service advertised by a new user on the Russian cybercrime forum Exploit, offering access to digital scans of identity documents on more than 170 million people in North America. The source brought it to my attention because the proprietor of this identity theft service offered my Virginia drivers license as a free sample in their initial sales thread on Exploit.” wrote Krebs. “The service, dubbed Nexus, claims to have more than 153 million drivers licenses for people in the United States and Canada, as well as more than 10 million identification cards; more than three million travel documents and/or international IDs; and at least 579,000 medical cards.”

The record total was also increasing by roughly 400,000 per day at the time of publication, which the operators attributed to ongoing active exfiltration from a live breach they claim has been running for over a year.

Krebs found his own driver’s license in the database after a source alerted him to the service. The operators had posted his Virginia license as a free sample on the Russian cybercrime forum Exploit. Each record contains six images of the license, showing the front and back in visible, infrared, and ultraviolet light, with a timestamp. Krebs’ timestamp matched a June 2025 flight and car rental.

He then checked nine friends and relatives, and everyone who found their license confirmed traveling or renting a car around the same date. His license and his mother’s, who rented a Hertz car with him that day, had timestamps just seconds apart.

Security researcher Zach Edwards, whose license also appeared in Nexus, narrowed the source further. His timestamp matched a trip to Las Vegas for DEF CON in August. He hadn’t rented a car, but he had shown his license at a marijuana dispensary: Planet13, a multi-state chain. In 2022, idscan.net published a press release announcing an exclusive identity verification partnership with Planet13’s dispensaries nationally. The company now serves more than 1,000 marijuana dispensaries in 19 states, and its own documentation confirms that its technology scans IDs with both infrared and ultraviolet light, precisely the format of the images appearing in Nexus.

Idscan.net performs more than 21 million verifications per month at more than 20,000 locations globally. Its client list spans car rentals, retailers, hotels, financial services, and dispensaries, which explains both the volume and the geographic spread of the records. The dataset also includes marijuana dispensary cards and records marked with the notation “CAC,” which may refer to Common Access Cards, the government-issued credentials used to enter federal buildings and secure facilities. If confirmed, that would significantly expand the security implications beyond consumer identity theft.

The database reportedly contained the driver’s licenses of U.S. Defense Secretary Pete Hegseth and the FBI’s assistant director, but not FBI Director Kash Patel’s.

Idscan.net said Krebs’ findings would help its internal investigation but gave no further details. The company later said it was working with law enforcement and forensic experts. Soon after the story became public, the Nexus service went offline.

Identity verification systems that require driver’s licenses are spreading sensitive data across an expanding network of third-party vendors, and oversight mechanisms haven’t kept pace. Every bar, hotel, car rental counter, dispensary, and age-verification system that scans an ID is creating a copy of that image in a system whose security posture the cardholder has no way to assess.

The idscan.net incident, if confirmed at the reported scale, would be among the largest exposures of government-issued identity document images ever recorded.

Krebs reports that Nexus shut down after his article, while the FBI opened an investigation after learning that stolen IDs may include licenses belonging to FBI agents.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Nexus)

Pegasus and NoviSpy Used Against Serbian Protesters

Serbian activists were targeted with zero-click Pegasus and NoviSpy spyware, exposing a major surveillance campaign ahead of elections.

A member of Serbia’s student protest movement had their iPhone infected with NSO Group‘s Pegasus spyware without ever clicking a link or opening a file. The Citizen Lab confirmed the infection in collaboration with the SHARE Foundation, tracing it to an iMessage zero-click exploit and identifying high-confidence indicators of compromise between December 2025 and January 2026, with the possibility of additional infections not ruled out.

“In collaboration with the SHARE Foundation, the Citizen Lab analyzed forensic artefacts from the iPhone of a member of Serbia’s student protest movement after they received an Apple Threat Notification warning of targeting with mercenary spyware.” reads the report published by Citizen Lab. “Our analysis confirmed that an iMessage zero-click exploit was used to infect the device with NSO Group’s Pegasus spyware. “

The attack required no action from the victim, which makes zero-click attacks especially dangerous. Citizen Lab said the Pegasus infection could stay hidden while giving the attacker full access to the phone, including messages, photos, notes, microphone, and camera. Apple later fixed this specific exploit through security updates in iOS 18.4.1.

“We believe that the zero-click exploit used in this attack targeted Apple iMessage, and has subsequently been patched by Apple as of iOS 18.4.1.” continues the report. “A zero-click infection with Pegasus spyware would not have been visible to the target, and would give the Pegasus attacker total access to the device. Pegasus allows an attacker to do anything that a user can do, ranging from accessing private data like notes, pictures and even encrypted messages. Pegasus also has the ability to covertly enable the phone’s microphone and camera.”

This one confirmed infection sits inside something considerably bigger. The SHARE Foundation has documented at least 14 individuals targeted with advanced spyware since early 2026, spanning student movement members, civil society activists, an opposition member of parliament, and a local councilor, which the organization is calling the largest documented surveillance wave in Serbia’s history. Twelve people approached SHARE’s digital forensics team in August after receiving Apple’s own threat notifications, warnings the company sends when it detects likely state-sponsored spyware targeting; eleven of those devices remain presumed infected pending further forensic confirmation.

The timing lines up uncomfortably well with Serbia’s political calendar. This surveillance wave coincides with local elections held on March 29, 2026, and stretches toward planned early parliamentary elections in October, following months of student-led anti-government and anti-corruption protests.

“These notifications and forensic confirmation highlight the aggressive mercenary spyware targeting of the peaceful pro-democracy movement with mercenary spyware ahead of key 2026 election cycles.” continues the report.

Targeting activists and opposition figures specifically in the run-up to elections isn’t subtle, and it fits a pattern Serbia has shown before.

Serbia has a history of using commercial spyware. Citizen Lab previously documented Pegasus targeting civil society and the use of Cellebrite tools to install the locally developed NoviSpy on activists’ phones. In this case, SHARE Foundation and Amnesty Tech found a new version of NoviSpy on a student activist’s Android phone after Serbian authorities seized it during police questioning.

Amnesty International’s Security Lab head, Donncha Ó Cearbhaill, connected the dots plainly between state custody and spyware installation.

“The forensic findings by SHARE prove that Serbian students continue to be targeted with invasive Android spyware tools, installed while detained by Serbian authorities” he said.

If you’ve received an Apple Threat Notification, whether in Serbia or anywhere else, the Citizen Lab’s guidance is unambiguous: treat it as a presumed infection and get expert help immediately rather than waiting to see if anything seems wrong. Individuals in Serbia should contact the SHARE Foundation directly, and anyone elsewhere can reach Access Now’s Digital Security Helpline, which supports journalists, human rights defenders, and other high-risk civil society targets worldwide. Anyone who suspects they might be a target based on their work or public role should also turn on Lockdown Mode, Apple’s built-in feature that significantly narrows what a zero-click exploit can actually reach, and keep every device updated, since the patch that closed this specific hole has already existed for well over a year for anyone who installed it.

“We believe that the zero-click used in this attack has been rendered ineffective by a patch from Apple in recent iOS versions. We urge everyone, especially those facing increased risks because of who they are or the work they do, to keep all devices updated.” concludes the report. “Click HERE for instructions on how to keep your iPhone up to date.”

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Pegasus)

North Korean Lazarus Group Uses Windows Zero-Day in Operation Dream Job

Lazarus targets defense professionals with fake Lockheed Martin jobs, exploiting a Windows zero-day to deploy backdoors and evade security controls.

Check Point Research has uncovered a new wave of Operation Dream Job, the long-running North Korean campaign that lures defense and aerospace professionals with convincing fake job offers. This iteration is more dangerous than previous versions: it includes a previously unknown Windows vulnerability now patched as CVE-2026-68820, a newly documented backdoor called Troy, and command infrastructure built almost entirely from legitimate servers the attackers didn’t build, they hijacked them. Targets confirmed in France, Germany, Brazil, and India.

“The attackers used a previously unknown vulnerability in Windows (CVE-2026-68820) to gain full control of infected computers and evade EDR visibility. Check Point reported the issue to Microsoft, which released a fix before this research was published” reads the report published by Check Point Research. “Rather than running their own servers, the attackers are hijacking legitimate but compromised websites and webmail servers to relay commands, making the malicious traffic harder to distinguish from normal activity”

The vulnerability, CVE-2026-68820, is the same actively exploited zero-day that Microsoft patched on August 11 as part of Patch Tuesday, a privilege escalation flaw in AFD.sys, the kernel driver underlying Windows Sockets. Check Point reported the issue to Microsoft on July 28, Microsoft confirmed it three days later, and the fix shipped two weeks after that. The zero-day in this campaign and the zero-day under active exploitation are the same bug.

The attack runs through two parallel infection chains. In the first, victims download an encrypted archive containing a legitimate signed PDF viewer and a malicious DLL. The DLL displays a convincing Lockheed Martin job description while silently loading MISTPEN, a lightweight downloader that communicates through Microsoft Graph API and OneDrive. MISTPEN then runs reconnaissance modules, triggers the AFD.sys exploit to achieve SYSTEM privileges, and deploys ForestTiger, a well-documented Lazarus backdoor, along with an updated version of the group’s kernel-mode rootkit, FudModule 3.1, which can now tamper with Windows Smart App Control to bypass software verification.

“The second chain is more recent and shares several characteristics with a campaign described by ESET against the UAV sector in 2025. Victims are instructed to download SecurityPDF, a trojanized PDF viewer, from one of several websites impersonating Enveil, a legitimate privacy technology company with no actual connection to the attack. Once installed, the modified viewer inspects any PDF opened through it for a hidden marker.” continues the report. “When the marker is present, the application decrypts and launches an embedded payload that loads the Troy backdoor directly into memory.”

Troy is a single DLL implant that supports 17 operator commands covering file operations, shell access, process termination, in-memory DLL injection, and configuration updates. Its name comes from a PDB path embedded in the binary that Check Point also observed in earlier Lazarus samples. Enveil has no connection to the campaign; its brand was simply borrowed because it sounds credible to defense sector professionals.

The C2 infrastructure is built from compromised Roundcube webmail installations and WordPress sites, many vulnerable to CVE-2025-49113, infected with a previously undocumented PHP webshell called RelayShell. RelayShell functions as a relay rather than a traditional backdoor, exchanging commands and responses through simple text files. In at least one confirmed case, an already-breached French organization was used to send phishing messages to new victims — the attackers borrowed the company’s reputation to get past filters. Check Point identified at least 17 unique server identifiers in this relay network, with operators connecting through commercial VPNs to further obscure their location.

The most urgent action is applying the August 2026 Patch Tuesday update, which contains the CVE-2026-68820 fix. For organizations running public-facing Roundcube or CMS installations, the secondary risk is becoming part of the relay infrastructure rather than the intended target: the servers used in this campaign were compromised through leaked credentials and a known unpatched vulnerability, not anything exotic. The full indicators of compromise are in Check Point’s report.

“Given the combination of a zero day vulnerability that now have a patch, a new modular backdoor, and web based infrastructure designed to resemble legitimate traffic, security teams in these sectors should prioritize the August Patch Tuesday update, review the indicators of compromise published in Check Point Research publication, and apply the same level of scrutiny to unsolicited recruiting outreach that they would apply to any unverified download request.” concludes the report.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Lazarus)

eSIM Plus and Nicegram Share Belarus-Linked Codebase, Analysis Finds

Analysis found eSIM Plus and Nicegram share a Belarus-linked codebase, while eSIM Plus routes data and calls through Russian services.

Two popular apps available in EU app stores, Nicegram, with over 50 million downloads, and eSIM Plus, with over 1 million, are presented to users as Lithuanian products. The Mysterium VPN Research Team pulled apart both Android packages to see what the binaries themselves reveal, following OCCRP reporting that both apps are allegedly developed and controlled from Belarus. What they found in the code substantially corroborates that reporting.

“Most decisively, the eSIM Plus package is cryptographically signed by “Mobyrix, Minsk” (a Belarusian signature on an app marketed under the Lithuanian “Appvillis” brand), and it ships live integrations with two Russian services, Yandex AppMetrica (analytics) and Voximplant (call routing, via a .ru endpoint).” reads the report published by Mysterium VPN Research Team. “Nicegram shares the same “Appvillis” codebase and backend, though the specific Russian SDKs aren’t present in the Nicegram build we examined.”

eSIM Plus 4.4.26Nicegram 1.55.0
Signing certificateMobyrix, Minsk, Belarus (original key)Google Play re-sign (developer identity hidden)
Yandex AppMetricaYes — full SDK (yandex.net, appmetrica.io)No SDK present
VoximplantYes — full SDK (.ru balancer)No
LocationFine + coarse, tracking wiredFine + coarse + background
Other telephonyTwilioN/A
Analytics/CDPAppMetrica, Mixpanel, Segment, Customer.io, AppsFlyer, Facebook, Firebase, QonversionFirebase, Adjust, Qonversion, AdMob, AppsFlyer
Notable extrasPayment SDKsCrypto wallet (seed phrases), “God’s Eye” profiling

The signing certificate is the most decisive piece of evidence. It carries the Minsk postal code 220020. An app publicly presented under a Lithuanian-facing brand is cryptographically signed by a company in Belarus, not by inference, but directly from the certificate.

The Russian integrations in eSIM Plus are both confirmed and live. Yandex AppMetrica is fully wired in with around 2,900 code references, communicating with Yandex infrastructure at startup and reporting events to appmetrica.io. AppMetrica derives client IP server-side by design, and location tracking is enabled.

“eSIM Plus integrates the Voximplant calling SDK across a full call stack (VoximplantCallManager, VoximplantIncomingCallService, and related classes, ~1,700 references). It routes through balancer.root.voximplant.ru — a Russian (.ru) endpoint — under the account appvillis.n8.voximplant.com. (Confirmed.)” continues the report. “These are the two specific “leads to Russia” technical indicators named in the reporting, and both are genuinely present and wired to live production hosts.”

In other words, a user making a call through eSIM Plus is routing that call through Russian infrastructure, with no indication of this in the store listing.

The data collection surface on eSIM Plus is unusually wide even by the standards of free apps. It requests 35 permissions including fine and coarse location, contacts, camera, microphone, and telephony. On top of AppMetrica it carries Mixpanel, Segment, Customer.io, AppsFlyer, Facebook SDK, Firebase, and Qonversion, plus payment SDKs and a second telephony vendor. Nicegram’s data collection footprint is similarly broad — 73 declared permissions including background location, camera, and phone identity — and it additionally bundles a non-custodial crypto wallet with seed-phrase handling and a module the researchers call “God’s Eye” that profiles Telegram users’ activity patterns by sending channel and session data to Nicegram’s servers.

“the Nicegram 1.55.0 package we examined does not contain the Yandex AppMetrica SDK, does not contain Voximplant, and contains no .by endpoints or Mobyrix strings.”continues the report. “The only Russian-hosted domains reachable from Nicegram are static-maps.yandex.ru (an optional map-tile provider inherited from upstream Telegram) and coub.com (a media-embed service) — both benign, user-action-gated, and not telemetry channels. “

The Russian-SDK evidence is in eSIM Plus, not in this specific Nicegram build. The two apps corroborate the shared-developer claim; eSIM Plus is where the Belarusian signature and Russian data flows are direct and technical.

The structural problem this research exposes is straightforward. A user in the EU installs an app that presents as Lithuanian and unknowingly routes their identifiers, location, and voice calls through analytics and telephony services in Russia, built and signed by a company in Minsk. Nothing in the store listing told them this. The trust was assumed; the reality was only recoverable by pulling the binary apart. That gap — between what an app’s label says and what the package itself contains — is invisible at install time and only legible to someone willing to do a static teardown. Most users aren’t, and shouldn’t have to be.

“For users, the practical takeaway is that an app’s store-listed “publisher” and country can differ materially from who actually builds, signs, and receives data from the software — a gap that’s invisible in the store listing but legible in the package itself.” concludes the report.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, eSIM Plus)

Iran-Linked Actors Breach Are Targeting US Water and Energy Control Systems

US agencies warn Iran-linked actors are targeting internet-exposed water and energy control systems, risking disruption.

Federal agencies updated their cybersecurity advisory this week: Iran-linked actors are inside American water and energy control systems, and they’re not just looking around. They’re changing things.

The updated advisory from CISA, the FBI, NSA, and the Department of Energy says these actors are getting into programmable logic controllers, the small industrial computers that run pumps, valves, and safety alarms. Once inside, they can mess with what operators see on their screens. That’s how you get outages nobody saw coming.

“The authoring agencies urgently warn U.S. organizations of ongoing Iranian-affiliated cyber targeting of internet-connected operational technology (OT) devices, including programmable logic controllers (PLCs).” reads the advisory. “These actions disrupted PLCs across several U.S. critical infrastructure sectors through malicious project file interactions and manipulation of data on human machine interface (HMI) and supervisory control and data acquisition (SCADA) displays, resulting in operational disruption and financial loss.”

This isn’t new territory. Back in April, the same agencies flagged Iranian hackers going after Rockwell Automation controllers specifically. The updated advisory widens the net. Now Schneider Electric and Siemens equipment is on the list too.

US agencies have expanded guidance on detecting malicious code changes in PLCs after observing attacks targeting Rockwell Automation, Schneider Electric, Siemens, and other internet-exposed industrial controllers.

Attackers access exposed devices via OT ports (44818, 2222, 102, 502) and modems over SSH (port 22), then exfiltrate PLC project files using vendor tools such as Studio 5000, EcoStruxure Control Expert, and TIA Portal. They modify or delete project logic, including Add-On Instructions (AOIs), manipulate HMI and SCADA displays, and disable shutdown and alarm functions, allowing industrial systems to enter unsafe states without alerting operators.

Organizations should follow vendor security best practices, remove PLCs from direct internet access using secure gateways and firewalls, and monitor logs for indicators of compromise and suspicious traffic on OT ports such as 44818, 2222, 102, and 502. Rockwell users should set controllers to Run mode, while suspected victims should contact vendors and federal agencies.

The agencies say potentially any internet-exposed industrial control system could be a target. Here’s the part that should make plant operators lose some sleep. In one case, the hackers didn’t just peek at a system. They rewrote the controller’s programming logic to disable the processes meant to trigger shutdowns and alarms during dangerous conditions.

“At one U.S. victim, the FBI observed the APT actors download a malicious project file to a targeted PLC using configuration software. Analysis indicated the project file retained ladder logic for downstream function but added logic that overrode specific instruction sets responsible for maintaining safe operating parameters in the victim’s environment.

“Since at least March 2026, the authoring agencies identified (through engagements with victim organizations) an Iranian-affiliated APT group disrupted the function of PLCs.” states the advisory. “Organizations across several U.S. critical infrastructure sectors (including Government Services and FacilitiesWWS, and Energy Sectors) deployed these PLCs within a wide variety of industrial automation processes. Some of the victims experienced operational disruption and financial loss.”

Systems could then drift into unsafe territory with nobody watching the warning lights, because the warning lights had been switched off from the inside.

“After the actors extracted device project files, the FBI and CISA identified the modification and deletion of project file logic, to include Add-On Instructions (AOIs) and data manipulation on HMI and SCADA displays [T1565].” continues the advisory.” Additionally, the changes disabled critical shutdown and alarm logic, allowing systems to enter unsafe conditions without notifying operators of the anomalies.”

The advisory ties the activity to the ongoing conflict between Iran and the US and Israel, framing it as an effort to cause disruption inside the United States. It fits a pattern going back to February, when the war started and Iranian-linked hacking picked up sharply across the region.

Not all of it looks like this. Some of it has been standard espionage and embarrassment campaigns, like the leak of FBI Director Kash Patel’s personal email account. Some of it has been genuinely destructive. The Iranian group known as Handala remotely wiped tens of thousands of employee devices at medical device maker Stryker, and separately claimed a breach at California’s Cal Water, saying it could disrupt the water supply. Cal Water pushed back, saying it found no sign anyone had touched its operational networks.

That’s the pattern worth watching: espionage on one track, disruption on another, and now a wider set of manufacturers exposed on the operational technology side. If your PLC talks to the internet, it’s not a bystander anymore.

Nobody wants their water plant’s alarm system to be the one thing an adversary quietly switches off. Time to check who can actually reach those controllers from outside.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Iran-Linked Actors)

Pegasus Used Against MEP Investigating Pegasus, Citizen Lab Finds

A former EU lawmaker was hacked with Pegasus spyware while investigating its use, according to Citizen Lab.

The Citizen Lab published a report documenting one of the more darkly ironic findings in recent surveillance research: former Member of the European Parliament Stelios Kouloglou was repeatedly infected with NSO Group‘s Pegasus spyware while serving on the very committee tasked with investigating Pegasus abuses across the EU. The PEGA Committee ran from March 2022 to July 2023. Kouloglou was on it the entire time.

“We found that former Member of the European Parliament Stelios Kouloglou was hacked with Pegasus spyware while serving on the PEGA committee, which investigated Pegasus and other spyware abuses in Europe.” reads the Citizen Lab report. “Through forensic analysis of his device, we found that the attackers could have had access to confidential documents and committee deliberations.”

The infections happened on October 21, 2022, and again on March 6 and 7, 2023, both during periods of intense PEGA activity. The first infection came ten days before a planned committee visit to Greece and Cyprus, and while drafts of the first PEGA report were circulating among members. The second hit while the committee was deep in the final drafting process, two months before the report’s adoption in May 2023.

The delivery mechanism for the first infection was PWNYOURHOME, a zero-click exploit targeting Apple’s HomeKit system.

“On 2022-10-21 10:16, there was a lookup for a HomeKit email address rauharepo888 [@]gmail.com. Two minutes later, a Pegasus process used mobile data. We assess that the phone was hacked with the PWNYOURHOME zero-click exploit at this point.” continues the report. “PWNYOURHOME appeared to first involve the attacker sending a specially crafted NSKeyedArchive that landed in HomeKit, followed by malicious content that landed in MessagesBlastDoorService.”

the researchers noted. No interaction required from Kouloglou. His device was running iOS 15.5 on both infection dates — a version Apple had already moved past. He also received three Apple threat notifications about mercenary spyware targeting, in March 2023, August 2023, and April 2024. He told the Citizen Lab he didn’t recall seeing any of them.

The timing of the first infection adds another layer. On October 21, 2022, Kouloglou was in a Greek hospital for elective surgery. He was visited that day by investigative journalist Thanasis Koukakis, who had himself been confirmed as a Predator spyware target and had testified before the PEGA Committee the month before. If Pegasus captured conversations in that hospital room, Greek law covering confidentiality of health data may have been violated.

Citizen Lab says it is highly confident that former MEP Stelios Kouloglou was infected with Pegasus, but cannot identify the NSO’s customer behind the attack. Researchers found no evidence linking the operation to the Greek government, which has instead been associated with Predator spyware. Technical evidence suggests the same Pegasus operator also targeted Russian and Belarusian journalists and activists in Europe. The infections occurred in both Greece and Belgium, indicating the spyware operator likely held a license allowing surveillance across multiple EU countries.

“We further note that infections appear to have been present on his phone in at least two European jurisdictions (We further note that infections appear to have been present on his phone in at least two European jurisdictions (Greece and Belgium).” continues Citizen Lab. “Based on what we know of NSO Group’s licensing, this would likely indicate that the customer had a license that enabled infections in multiple EU jurisdictions, narrowing the list of potential Pegasus operators that could be responsible for this case.”

The same HomeKit email address used against Kouloglou in 2022 appeared in a prior Citizen Lab investigation into Pegasus infections of Russian and Belarusian-speaking journalists and activists living in Europe.

This is the first confirmed case of a PEGA Committee member being hacked with Pegasus while the committee was in session. It’s not the first MEP targeted with spyware, Catalan MEPs were hit with Pegasus as far back as 2019, and French MEP Nathalie Loiseau confirmed she was targeted in early 2024. The Citizen Lab is now calling on the European Parliament to investigate the full scope of spyware targeting during the PEGA proceedings, and urging DG ITEC, which already offers optional spyware screening for MEPs, to significantly increase screening rates and publish yearly statistics.

The committee spent more than a year investigating who was spying on Europeans. Someone was apparently taking notes the whole time.

“Whichever entity is responsible for the hacking, the infection could have exposed strictly confidential exchanges among PEGA Committee members and their staff, and other sensitive and confidential parliamentary proceedings, including to parties under investigation by the Committee itself.” concludes the report. “The finding that a PEGA Committee member was targeted with Pegasus spyware during the Committee’s work highlights the serious threat that mercenary spyware poses to the integrity of democratic processes. “

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Pegasus spyware)

❌