Kouloglou, dressed in a blue suit and white, open-neck shirt, stands in a street holding a mobile phone in one hand in front of him, as if he is either speaking to someone on it via video or taking a photo.

Tackling Spyware Abuse: What States Must Do Under International Law to Protect Journalists and Strengthen Security

The Citizen Lab, a digital-security research group at the University of Toronto, published a report this past July revealing that Stelios Kouloglou, a prominent Greek investigative journalist and former member of the European Parliament, was hacked with NSO Group’s Pegasus spyware multiple times in 2022 and 2023. At the time, Kouloglou was serving on the PEGA Committee, a European Parliament body created to investigate government misuse of commercial surveillance tools — the very abuse to which he was being subjected. Investigations revealed that the attacks coincided with key decision-making periods during the drafting of the committee’s final reports.

Kouloglou’s case is striking, but it is far from unique. Around the world, governments have turned commercial spyware against dissenting politicians, journalists, human rights defenders, and activists. Investigations by Citizen Lab, Amnesty International’s Pegasus Project, and the Predator Files — along with work by many other civil society organizations — document a pattern of abuse that implicates the right to privacy, freedom of expression and association, press freedom, due process, and the integrity of democratic institutions.

Software like Pegasus is installed on a target’s phone by exploiting security flaws in the device’s operating system. The most advanced versions use what researchers call “zero-click” exploits, which means that the target does not need to open a link or take any action at all. The infection is silent, often undetectable, and gives the operator full access to the device’s camera, microphone, messages, and location data.

These tools have proliferated in part because they are marketed as “dual use,” a term of art meaning a product has both legitimate government applications (such as counterterrorism or criminal investigations) and potential for misuse. The dual-use label gives spyware vendors a veneer of legitimacy and complicates export-control measures, because the same tool that helps a government track a terrorist suspect can also be turned on a journalist or political opponent. In practice, the misuse cases are staggering: spyware has been deployed to invade privacy, facilitate arbitrary detention, and, in the most extreme instances, enable assassination. Women are disproportionately targeted, often facing sexualized harassment designed to intimidate and silence them. And while spyware is marketed as a tool for defending national security, it is readily exploited to undermine it — enabling transnational repression and foreign interference that weaken the very governments deploying it.

The High Level Panel of Legal Experts on Media Freedom, a diverse group of leading lawyers from around the world, on which I serve as deputy chair, has been working to address this crisis. The Panel serves as the independent legal advisory body to the Media Freedom Coalition, a partnership of 51 countries committed to protecting press freedom. On June 23, the Panel published an Advisory Note setting out a legal and policy roadmap for governments to regulate commercial spyware, the latest in a series identifying threats to journalists and media freedom worldwide.

The Panel warns that the use of commercial spyware against journalists has reached crisis levels. The market has expanded well beyond Pegasus, which was created by the Israeli spyware firm NSO Group, to include tools such as Paragon’s Graphite and products from dozens of smaller vendors. Between 2016 and 2021, at least 180 journalists in 21 countries were confirmed targets of Pegasus alone, and attacks have only accelerated since. Among the most high-profile cases are those of Jamal Khashoggi (Washington Post), Lenaïg Bredoux (Mediapart), and Siddharth Varadarajan (The Wire). Yet even as the threat grows, spyware has slipped down, or off, the political agenda entirely.

Why Voluntary Efforts Are Not Enough

Over the past decade, civil society and the private sector have mounted impressive efforts to counter spyware abuse. The Pegasus Project, a collaboration of 80 journalists across 17 organizations, exposed 50,000 potential surveillance targets worldwide. Amnesty International developed forensic tools to detect smartphone infections. Citizen Lab tracks ongoing lawsuits. In May 2025, a U.S. federal court granted an injunction to stop the NSO Group from targeting WhatsApp users. 

These are real achievements, but they are inherently reactive. Without a binding regulatory framework, civil society will remain locked in a resource-draining cycle of investigating attacks after the fact and assisting individual victims, rather than preventing abuse at its source. The spyware industry is growing faster than the ad hoc efforts attempting to contain it.

Many civil society organizations and U.N. bodies have called for a complete moratorium on the sale and use of commercial spyware. But even governments that reject a moratorium, or that view spyware as an essential tool for national security, should recognize that the technology’s inherent design — its capacity for secret, unchecked surveillance — creates a structural risk of abuse. Regulation is not an alternative to using spyware; it is a prerequisite for using it responsibly, and the window to install effective guardrails is narrowing.

Some governments have begun to act. In March 2023, 11 countries, including the United States, United Kingdom, France, and Australia, signed a joint statement committing to ensure that any domestic use of commercial spyware would be consistent with human rights and the rule of law. By September 2024, 23 countries had endorsed the statement. The commitment is significant — but it is political, not legal, and carries no enforcement mechanism.

The Pall Mall Process, launched by the United Kingdom and France in 2024, has drawn 25 endorsing countries into a shared framework organized around four pillars: accountability (holding vendors and deploying states responsible), precision (limiting spyware use to defined lawful purposes), oversight (requiring independent review of deployments), and transparency (disclosing procurement and use policies). These principles are sound, but they remain voluntary.

What a Binding Framework Should Look Like

Despite these efforts, the gap between rhetoric and enforcement is still wide. Voluntary commitments lack binding force, and export controls are inconsistently applied across jurisdictions. Even after the surveillance of one of the PEGA committee’s own members came to light, the European Parliament took no significant action to curb the use of commercial spyware. This pattern repeats around the world, even as the security threats posed by unregulated spyware intensify.

The High Level Panel’s Advisory Note urges governments to treat spyware governance as a top-tier political priority and to work toward a binding, enforceable regulatory framework, not just another set of voluntary commitments.

The note lays out a concrete framework for regulating spyware across the full product lifecycle, from development and export to procurement, deployment and post-deployment review. It calls for strict legal requirements on both the companies that sell spyware and the governments that buy it, backed by a robust infrastructure for detecting and tracking attacks. Critically, the framework insists that fundamental freedoms, especially freedom of expression and association, must be protected at every stage, and that individual journalists and human rights defenders who believe they have been targeted must have access to effective support and remedies.

Any governance framework must also be judicially enforceable. Courts must be empowered to assess whether a specific deployment of spyware is proportionate, that is, whether the intrusion on the target’s right to privacy is justified by, and no greater than necessary to achieve, a legitimate objective such as counterterrorism or national security. This principle, known as proportionality, is already embedded in international law, but it has little practical force when surveillance operates in secret and without independent review. The framework must therefore require that governments obtain prior judicial authorization before deploying spyware, subject to meaningful post-deployment audit. Without these safeguards, there are currently insufficient checks on state use of these tools.

Finally, the problem demands coordinated international action. The High Level Panel recommends the creation of an international rapid-response mechanism — a shared platform through which governments can pool and verify intelligence on confirmed instances of spyware targeting. Such coordination would serve a dual purpose: protecting press freedom and enabling governments to identify and respond to the national security threat posed by foreign deployment of spyware against their own citizens and institutions.

Commercial spyware does not respect borders. A journalist tracked in Mexico City and one under surveillance in Warsaw face the same zero-click vulnerability. The legal response must be equally borderless: binding, coordinated, and enforceable across jurisdictions.

The legal tools exist. The policy roadmap is on the table. What is missing is the political will to act, and the cost of inaction grows with every unreported hack.

(Author’s note: The June Advisory Note by the High Level Panel of Legal Experts on Media Freedom is the second in a series aimed at not only the 51 member states of the Media Freedom Coalition, but the global community at large, on protecting journalists and press freedom. Previous Advisory Notes are available here.)

Filed Under

, , , , , , , , , , , , , , , , ,
Send A Letter To The Editor

DON'T MISS A THING. Stay up to date with Just Security curated newsletters: