Home / Publications / Hacking Meduza: Pegasus spyware used to target Putin’s critic
Hacking Meduza: Pegasus spyware used to
target Putin’s critic
PUBLISHED: 13 SEPTEMBER 2023
NATALIA
KRAPIVA
@natynettle
LAST UPDATED: 13 SEPTEMBER 2023
An investigation by Access Now and the Citizen Lab at the Munk School of Global Affairs at the
University of Toronto (the Citizen Lab) has revealed that the iPhone of journalist Galina Timchenko,
head of Meduza, a leading Russian independent media outlet based in Latvia, has been infected with
Israeli firm NSO Group’s Pegasus spyware. The spyware attack took place two weeks after the Russian
government declared Meduza an “undesirable organization” for its critical coverage of Vladimir Putin’s
regime and the war in Ukraine. At the same time, some European political leaders were publicly arguing
for surveillance of all Russians in exile. This is the first documented case of a Pegasus infection of a
Russian journalist.
What happened
Russian independent media under attack
Who is behind this Pegasus attack?
Spyware violates human rights and international humanitarian law
Call for action
// What happened
On June 22, 2023, Timchenko, co-founder, CEO, and publisher of Meduza, received a notification from
Apple that state-sponsored attackers may be targeting her iPhone. The next day, Meduza’s Chief
Technology Officer contacted Access Now to check the phone for traces of spyware. Access Now, with
forensic assistance from the Citizen Lab, tested the device, and discovered that it had been infected with
Pegasus spyware on or around February 10, 2023, with the infection likely lasting several days or weeks
after that. At the time of the infection, Timchenko, who lives in Latvia, was in Berlin, attending a private
gathering organized by Redkollegia with other members of Russian independent media living in exile to
discuss the legal risks of “undesirable” and “foreign agent” designations.
RAND
ACCESS NOW
HELPLINE TEAM
@accessnow