// Who is behind this Pegasus attack? Pegasus is designed to obfuscate which government is behind a particular attack, making it difficult for us to attribute. However, based on NSO Group’s assertion that Pegasus is only sold to state agencies and the available technical and circumstantial evidence, there are several theories of which state is likely behind the attack. Meduza’s host state, Latvia, could have been responsible, as they appear to be a Pegasus customer. However, according to the Citizen Lab, there has not been any indication of Latvia using Pegasus to spy outside of its borders. Germany, where Timchenko was staying at the time of her phone’s infection, is another potential culprit, as they also appear to be a Pegasus customer, although the reported German customer is a police agency, rather than an intelligence agency. Two other reported European Pegasus customers, the Netherlands’ General Intelligence and Security Service (AIVD) and an unnamed Estonian government agency, appear to use Pegasus extensively outside their borders, including within multiple European countries, according to the Citizen Lab. While there are claims that NSO Group does not allow Estonia to target Russian phone numbers, Timchenko’s phone number has a Latvian country code (+371). The E.U. PEGA Committee revealed at least 14 E.U. states and 22 operators of Pegasus in the E.U. In fact, just two months before Timchenko’s phone was infected, Latvia declared another independent media organization in exile — TV Rain — to be “a threat to the national security and public order” and canceled its license. This decision was criticized by the Latvian Association of Journalists as “disproportionate.” Other E.U. leaders, like the president of the Czech Republic, Petr Pavel, have publicly stated that all Russians living in the West should be put under “strict surveillance” as the price of Russia’s war against Ukraine. The public pressure on E.U. leaders to demonstrate support for Ukraine in the face of Russia’s aggression may be deepening the risks for Russian independent media groups like Meduza that are already in danger because they seek to hold Putin accountable. Another possibility is that states with ties to Russia that are suspected Pegasus users — Azerbaijan, Kazakhstan, or Uzbekistan — may have hacked Meduza on behalf of Russia. In May 2023, an investigation by Access Now and partners revealed that Azerbaijan is a potential culprit behind the targeting of media workers and other civil society actors in Armenia. Notably, Kazakhstan itself has blocked Meduza over a controversial article. However, according to the Citizen Lab, there is no evidence of Azerbaijan or Kazakhstan targeting people in Germany, Latvia, or other E.U. states. Also, Uzbekistan is not believed to have been a Pegasus customer during the period in question. Finally, as we have seen with the state targeting of independent media and journalists in countries from El Salvador to Hungary, it is possible Timchenko’s own government — Russia — is behind the hacking. As we have noted, the attack happened just two weeks after Russia designated Meduza an “undesirable organization,” which, unlike the “foreign agent” designation, immediately criminalizes all activities of an organization, requiring it to shut down. Meduza also experienced a spike in digital attacks in February 2023; for example, attackers blocked mirror websites, and engaged in phishing and other efforts to compromise user accounts. However, according to the Citizen Lab, there is currently no evidence that the Russian government is operating the Pegasus system. Experts on Russia’s intelligence services, like journalist Andrei Soldatov, are not convinced that Russia has been using Pegasus. // Spyware violates human rights and international humanitarian law Whether during war or peace, surveillance of journalists and independent media by intrusive spyware like Pegasus is prohibited under E.U law, international human rights law, and international humanitarian law.

Select target paragraph3