Pegasus spyware has been discovered on the phones of the Spanish Prime Minister and the Defence Minister.
The Spanish Government revealed that data from devices used by both Prime Minister Pedro Sánchez and Defence Minister Margarita Robles has been extracted. The infection on Sanchez’s device took place between May and June 2021, with Robles’s phone being infected in June 2021.
At present, it is unknown which parties were behind the attack. Monitoring people’s phones requires judicial authorisation, leading the government spokesperson to claim the culprits were “illicit” and “external”.
“I don’t think now is the time to engage in supposition or conjecture about what the motivation may have been,” said Minister for the Presidency Félix Bolaños.
The breach is now being investigated by the highest Spanish criminal court, the Audiencia Nacional. Other government figures are currently having their numbers investigated to verify if they were targeted as well.
The Pegasus spyware was developed by Israeli company NSO Group and can record calls, copy messages and secretly film users. Originally designed to target criminals, the software has been used by governments to spy on dissenting voices, journalists and human rights activists.
A list released in summer last year found that over 600 politicians and government officials have been targeted, spanning more than 50 countries.
Research from telecoms research group Citizen Lab found that at least 63 people, including Catalonian politicians and government workers, had been targeted or infected with Pegasus, and another four with another piece of spyware, Candiru.
Recommended
- Who’s to blame for cryptomining emissions?
- New tech turns seawater into drinking water
- The ransomware ecosystem is showing signs of cracking
The news of the Spanish Prime Minister being hit by Pegasus follows a similar reveal from Citizen Lab from April. The group’s research found that computer systems used by UK Government bodies, including the Prime Minister’s Office and the then Foreign and Commonwealth Office (FCO) had been infected with Pegasus.
According to Citizen Lab, the infections, detected between 2020 and 2021, were linked to operators in the UAE, India, Cyprus, and Jordan.
In addition, several officials from the European Commission, including EU Justice Commissioner Didier Reynderswere, were targeted by spyware developed by the same company behind Pegasus.
The malware, ForcedEntry, was detected on officials’ devices in November 2021.
Get the latest news from DIGIT direct to your inbox
Our newsletter covers the latest technology and IT news from Scotland and beyond, as well as in-depth features and exclusive interviews with leading figures and rising stars.
To subscribe, click here.





