Hooked! #16: Spyware is bad and it is past time to do something about it

Photo: Akshar Dave/Unsplash

Hello! 

Three years ago, in one of the first articles published on Binding Hook, Dutch former member of the European Parliament Sophie in ‘t Veld wrote that, ‘the illegal use of spyware in Europe is a clear and present danger to European democracy.’ In her warning of spyware’s threat, she concluded that ‘the European Commission now leaves it to the member states to police themselves, which in practice amounts to no policing at all,’ and that by not addressing urgent privacy issues, Europe might be walking the road to totalitarianism.

Given that strong condemnation and all of the plenary sessions and processes and court cases that have happened since then, a casual reader might have been surprised to read Citizen Lab researcher John Scott-Railton in Wired last week saying ‘Europe has a mountain of spyware abuses, and nothing has happened—it’s an embarrassment for European institutions.’

Context: Citizen Lab has just released a report finding that Greek MEP Stelios Kouloglou’s phone was infected with NSO Group’s Pegasus spyware while he was on the PEGA Committee investigating Pegasus and spyware in Europe – twice.

Read more from Siena Anstis, one of the Citizen Lab report authors, on countering transnational dissident cyber espionage involving spyware.

While the incidents occurred in 2022 and 2023, the fact that the situation has not improved much has become something of a scandal in itself. PEGA Committee recommendations from June 2023 included very many, very specific action items, ranging from calling for Cyprus and Israel to join the Wassenaar Arrangement and the creation of an EU Tech Lab to proactively launching infringement procedures against member states for rule-of-law deficiencies. These have not been fully implemented.

Read more about the Wassenaar Arrangement in Mark Bromley and Giovanna Maletta’s piece arguing that it is time for the EU and Pall Mall Process to make export controls more effective against the misuse of spyware.

Citizen Lab was careful to state that it had found no indication that the Greek government was behind it – an odd clarification, except that the Greek government is managing its own ongoing spyware scandal, in which it used Intellexa’s Predator spyware to target journalists, politicians, and military officials. (Several of the victims sued Intellexa last week for millions in damages, following a February court decision that found Intellexa’s founder and others guilty of violating data protection laws.) 

The unidentified operator who targeted Kouloglou was instead linked by Citizen Lab to hacks of the phones of seven Belarusian- and Russian-speaking activists and journalists in Europe – perhaps a hint as to who might be behind it.

Back in 2023, Runa Sandvik responded to MEP in ‘t Veld in Binding Hook, arguing that the spyware problem wasn’t an awareness problem, and that it was up to politicians to take the lead in acting to combat it, since journalists, activists, and researchers had been ‘doing everything in their power to sound the alarm at every turn’ for over a decade.

The essential contours of the problem haven’t changed in the three years since she wrote that. Whatever civil society (and the EU Parliament’s new ‘interest group’) says, EU governments are sufficiently addicted to spyware that they are willing to tolerate both uncomfortable external alliances and recurrent internal abuses to retain this capability, while paying lip service to efforts to rein it in. 

The one thing that might move the dial? A roll-out of the highly controversial and recently revived Chat Control (an EU regulation that would mandate the scanning of private conversations, potentially including encrypted messages, for child sex abuse material). If spyware isn’t necessary to access encrypted conversations, the market may well dampen. Out of the frying pan, into the fire… 

Until next month.

Katharine Khamhaengwong

Binding Hook Senior Editor


More Binding Hook on spyware: