The letter follows revelations about Serbian student activists being infected with Pegasus and NoviSpy, and coincides with other pressures on Belgrade.
This aerial photograph shows demonstrators and students as they gather in front of Serbia’s Constitutional Court building during a protest to demand accountability for the Novi Sad railway station tragedy, in Belgrade, on January 12, 2025. Thousands of Serbians protested in the capital Belgrade on January 12, 2025, against corruption and demanding justice for those killed in a train station roof collapse. The demonstrations have been ongoing for two months since a roof in a train station in the northern city of Novi Sad, which had recently undergone restoration work, collapsed on November 1, 2024, and killed 15 people. (Photo by TADIJA ANASTASIJEVIC / AFP via Getty Images)
It’s the first Pegasus infection of 2026 that Citizen Lab is forensically confirming, and the SHARE Foundation said it’s the biggest wave of spyware surveillance in Serbia…
Stelios Kouloglou arrives for a meeting with the police commissioner at the police headquarters on Dec. 3, 2019 in Valletta, Malta. (Photo by ANDREAS SOLARO / AFP) (Photo by ANDREAS SOLARO/AFP via Getty Images)
This illustration photograph taken on November 27, 2024, shows the logo of US instant messaging software Whatsapp displayed on a smartphone’s screen, in Frankfurt am Main, western Germany. (Photo by Kirill KUDRYAVTSEV / AFP)
The company said it spotted a spearphishing campaign linked to the Israeli spyware maker targeting WhatsApp users, despite a court order prohibiting it.
Rep. Summer Lee’s letter, first reported by CyberScoop, follows ICE confirmation of using spyware and news of a Trump ally becoming NSO Group’s executive chairman.
In this photo illustration, an NSO Group logo is displayed on a smartphone with stock market percentages on the background. (Photo Illustration by Omar Marques/SOPA Images/LightRocket via Getty Images)
The system, a five-year effort to address memory safety “at scale,” is the result of spyware developers making zero-click exploits that targeted a device’s memory.