Press to release document — or hit Enter
Episode II — Pegasus, Case II
5W+1H — Case Summary
WHO: Pedro Sánchez — Prime Minister of Spain since June 2018. Leader of the Spanish Socialist Workers' Party (PSOE). Head of a NATO/EU member state government. Also targeted: Defence Minister Margarita Robles, Catalan independence leaders.
WHAT: Pegasus spyware deployed via zero-click iMessage exploit against the phones of Spanish government officials. Full device compromise — messages, microphone, camera, GPS, encrypted apps.
WHEN: Infections disclosed by the Spanish government in May 2022. Investigation shelved July 2023, reopened April 2024, and dropped again January 2026 after continued non-cooperation from Israel. Three NSO-linked executives were placed under investigation in Barcelona in 2025.
WHERE: Spain — Moncloa Palace (PM's office), Ministry of Defence, Catalan regional government offices.
WHY: Two linked scandals collided: confirmed infection of senior Spanish ministers by an unresolved actor, and extensive Pegasus/Candiru targeting of Catalan independence figures where Citizen Lab found strong circumstantial evidence pointing to Spanish authorities.
HOW: NSO Group provided Pegasus to government clients. The Spanish government publicly confirmed the ministerial infections but has not identified the operator. Citizen Lab documented the Catalan cases through forensic analysis and exploit traces.
In May 2022, the Spanish government made an announcement that had no precedent in European history: the phone of a sitting prime minister had been infected with commercial spyware. Pedro Sánchez, head of the government of Spain — a NATO ally, an EU member state, the fifth-largest economy in the bloc — had been carrying a compromised device. So had his Defence Minister, Margarita Robles.CL
This was not the targeting of a dissident in a faraway autocracy. This was the head of a Western government, inside his own country, infected by a product sold to governments — and the investigation could not even definitively say which government pulled the trigger.
The shock in Brussels was immediate. If the prime minister of Spain was not safe, no European leader was. The episode exposed a fault line that had been widening for years: commercial spyware built by private firms was now capable of penetrating the devices of the most heavily protected officials on the continent, and the legal frameworks meant to constrain its use had not kept pace.
The Sánchez case cannot be separated from Catalonia. Alongside the prime minister and defence minister disclosures, Citizen Lab documented at least 65 Catalan figures targeted or infected with Pegasus and Candiru, including elected officials, lawyers, activists, and family members.CL
The dual-use nature of the spyware was laid bare. Tools acquired under the banner of counterterrorism — to protect the state from violent threats — were allegedly turned against elected officials, civil society organizers, and political opponents whose activity centered on independence politics. The line between national security and political surveillance did not blur. It was contested in court.
Within Spain the scandal cut deeper still. Citizen Lab did not conclusively attribute the Catalan operation to a specific entity, but said strong circumstantial evidence suggested a nexus with Spanish authorities. For Sánchez and Robles, attribution remained officially unresolved, even as Spanish courts repeatedly hit the same wall: Israel would not provide the information needed to identify the operator.
Spain's attempt to investigate the infections ran into a wall almost immediately. Israel — whose Ministry of Defense regulates NSO Group's export licenses — refused to cooperate with the Spanish inquiry. By July 2023, the investigation was shelved, with officials citing, in reported terms, the complete lack of cooperation from Israeli authorities.
The shelving was not the end. In April 2024, under sustained public and political pressure, the case was reopened. In January 2026, Spain's Audiencia Nacional dropped the Sánchez/Robles investigation again, citing continued non-cooperation from Israel. The European Parliament's PEGA Committee had already documented systemic abuse across multiple member states and called for binding restrictions on mercenary spyware.GDNEP
What the PEGA Committee made clear was that Spain was not an outlier. It was a data point in a continental pattern: spyware acquired for legitimate security purposes, deployed against the very people the state is supposed to protect.
In 2025, the case took a turn no previous Pegasus investigation had reached in Spain. Three NSO-linked executives — Shalev Hulio, Omri Lavie, and Yuval Somekh — were placed under formal criminal investigation by a Barcelona court over the alleged spying on lawyer Andreu Van den Eynde. It was a rare move from investigating companies to investigating named individuals behind them.EPais
The Barcelona proceedings arose from Pegasus allegations involving Catalan civil society, not directly from the Sánchez phone infection. But together, the cases showed the same accountability gap: the state could confirm infections and courts could open files, yet the vendor, export regulator, and operators remained difficult to compel.
The significance was not lost on anyone. For over a decade, NSO Group had operated in a gray zone — selling military-grade surveillance tools to governments while insisting its products were used only against terrorists and criminals. The Barcelona proceedings punctured that defense by naming executives, not only corporate entities, in a criminal investigation.
If the prime minister of Spain — protected by one of Europe's largest intelligence services, carrying a device managed by government security staff — could be infected, then the premise that any official, anywhere, can secure their communications collapses. The Sánchez case demonstrated that the technical capacity of commercial spyware now exceeds the defensive capacity of most states.
The normalization is the deeper problem. Spyware is no longer exceptional. It is procured, budgeted, deployed, and renewed as a line item in intelligence operations across democratic governments. The PEGA findings, the Catalan cases, and the Barcelona proceedings all point to the same reality: mercenary spyware has become standard infrastructure, and the legal and democratic controls meant to restrain it have been outpaced by the market that sells it.
The line between legitimate intelligence and political surveillance is a procedural one — it depends on warrants, oversight, proportionality, judicial review. In Spain, that line became the central question. It has become the same question in Hungary, Poland, Greece, and Serbia: who has mercenary spyware, who authorizes it, and what can courts actually prove when vendors and states refuse to cooperate?FSCL
European cases
European states where mercenary spyware — Pegasus and equivalents — has been confirmed deployed against officials, journalists, and civil society. Not exhaustive.
Sources: Citizen Lab, Amnesty International, European Parliament PEGA Committee. Not exhaustive.
"The prime minister of Spain carried a compromised phone. His defence minister carried a compromised phone. Catalan activists carried compromised phones. The government confirmed infections. Citizen Lab documented a wider political surveillance pattern. Courts opened cases, closed them, reopened them, and hit the same wall: the operator could not be named without cooperation from the state that licensed the spyware."
The line between legitimate intelligence and political surveillance depends on oversight. In Spain, oversight ran into silence.