Home / Publications / Hacking Meduza: Pegasus spyware used to target Putin’s critic Hacking Meduza: Pegasus spyware used to target Putin’s critic PUBLISHED: 13 SEPTEMBER 2023 NATALIA KRAPIVA @natynettle LAST UPDATED: 13 SEPTEMBER 2023 An investigation by Access Now and the Citizen Lab at the Munk School of Global Affairs at the University of Toronto (the Citizen Lab) has revealed that the iPhone of journalist Galina Timchenko, head of Meduza, a leading Russian independent media outlet based in Latvia, has been infected with Israeli firm NSO Group’s Pegasus spyware. The spyware attack took place two weeks after the Russian government declared Meduza an “undesirable organization” for its critical coverage of Vladimir Putin’s regime and the war in Ukraine. At the same time, some European political leaders were publicly arguing for surveillance of all Russians in exile. This is the first documented case of a Pegasus infection of a Russian journalist. What happened Russian independent media under attack Who is behind this Pegasus attack? Spyware violates human rights and international humanitarian law Call for action // What happened On June 22, 2023, Timchenko, co-founder, CEO, and publisher of Meduza, received a notification from Apple that state-sponsored attackers may be targeting her iPhone. The next day, Meduza’s Chief Technology Officer contacted Access Now to check the phone for traces of spyware. Access Now, with forensic assistance from the Citizen Lab, tested the device, and discovered that it had been infected with Pegasus spyware on or around February 10, 2023, with the infection likely lasting several days or weeks after that. At the time of the infection, Timchenko, who lives in Latvia, was in Berlin, attending a private gathering organized by Redkollegia with other members of Russian independent media living in exile to discuss the legal risks of “undesirable” and “foreign agent” designations. RAND ACCESS NOW HELPLINE TEAM @accessnow

Select target paragraph3