// Who is behind this Pegasus attack?
Pegasus is designed to obfuscate which government is behind a particular attack, making it difficult for
us to attribute. However, based on NSO Group’s assertion that Pegasus is only sold to state agencies and
the available technical and circumstantial evidence, there are several theories of which state is likely
behind the attack.
Meduza’s host state, Latvia, could have been responsible, as they appear to be a Pegasus customer.
However, according to the Citizen Lab, there has not been any indication of Latvia using Pegasus to spy
outside of its borders. Germany, where Timchenko was staying at the time of her phone’s infection, is
another potential culprit, as they also appear to be a Pegasus customer, although the reported German
customer is a police agency, rather than an intelligence agency. Two other reported European Pegasus
customers, the Netherlands’ General Intelligence and Security Service (AIVD) and an unnamed Estonian
government agency, appear to use Pegasus extensively outside their borders, including within multiple
European countries, according to the Citizen Lab. While there are claims that NSO Group does not allow
Estonia to target Russian phone numbers, Timchenko’s phone number has a Latvian country code
(+371).
The E.U. PEGA Committee revealed at least 14 E.U. states and 22 operators of Pegasus in the E.U. In fact,
just two months before Timchenko’s phone was infected, Latvia declared another independent media
organization in exile — TV Rain — to be “a threat to the national security and public order” and canceled
its license. This decision was criticized by the Latvian Association of Journalists as “disproportionate.”
Other E.U. leaders, like the president of the Czech Republic, Petr Pavel, have publicly stated that all
Russians living in the West should be put under “strict surveillance” as the price of Russia’s war against
Ukraine. The public pressure on E.U. leaders to demonstrate support for Ukraine in the face of Russia’s
aggression may be deepening the risks for Russian independent media groups like Meduza that are
already in danger because they seek to hold Putin accountable.
Another possibility is that states with ties to Russia that are suspected Pegasus users — Azerbaijan,
Kazakhstan, or Uzbekistan — may have hacked Meduza on behalf of Russia. In May 2023, an
investigation by Access Now and partners revealed that Azerbaijan is a potential culprit behind the
targeting of media workers and other civil society actors in Armenia. Notably, Kazakhstan itself has
blocked Meduza over a controversial article. However, according to the Citizen Lab, there is no evidence
of Azerbaijan or Kazakhstan targeting people in Germany, Latvia, or other E.U. states. Also, Uzbekistan is
not believed to have been a Pegasus customer during the period in question.
Finally, as we have seen with the state targeting of independent media and journalists in countries from
El Salvador to Hungary, it is possible Timchenko’s own government — Russia — is behind the hacking.
As we have noted, the attack happened just two weeks after Russia designated Meduza an “undesirable
organization,” which, unlike the “foreign agent” designation, immediately criminalizes all activities of
an organization, requiring it to shut down. Meduza also experienced a spike in digital attacks in February
2023; for example, attackers blocked mirror websites, and engaged in phishing and other efforts to
compromise user accounts. However, according to the Citizen Lab, there is currently no evidence that
the Russian government is operating the Pegasus system. Experts on Russia’s intelligence services, like
journalist Andrei Soldatov, are not convinced that Russia has been using Pegasus.
// Spyware violates human rights and international
humanitarian law
Whether during war or peace, surveillance of journalists and independent media by intrusive spyware
like Pegasus is prohibited under E.U law, international human rights law, and international
humanitarian law.