Be bold,
back the brave
We aim to build a €100M fund to secure access to news in every European country.
Over the past few months, spyware reporting by Limelight partners followed the trail from a fake Signal warning to European public money and a Greek courtroom.

Donncha Ó Cearbhaill knew what the message was asking him to do. It appeared to come from Signal support. It warned of suspicious activity and asked him to verify his account. The instructions would have given the attackers what they needed to link his Signal account to a device they controlled.
Donncha leads Amnesty International’s Security Lab, where he investigates spyware and digital attacks against journalists, activists, and human rights defenders. In May, the attempted breach came to him. He used it as the start of an investigation.

Donncha found that the message was part of a wider phishing campaign linked to Russian government hackers. The attackers posed as Signal support staff and tried to trick users into handing over verification codes. He later identified more than 13,500 targets and a system, called ApocalypseZ, that appeared to automate the attacks.
The campaign was built on a method several intelligence services, including the Dutch, had warned about in March. Hackers linked to Russia were targeting Signal and WhatsApp users, including journalists, by using phishing and social engineering rather than malware. In Signal’s case, they posed as support staff, warned targets about suspicious activity, and asked for codes that would allow them to take over or impersonate accounts.

Spyware and account-takeover attacks have become a recurring threat to journalists and civil society groups. The Pegasus Project, a 2021 investigation coordinated by Forbidden Stories with Amnesty International, was based on a leak of more than 50,000 phone numbers selected for possible surveillance by clients of NSO Group in more than 50 countries. Around 180 journalists were among those targeted. Once a phone is infected, spyware can give an operator access to messages, photos, emails, location data, and in some cases, the microphone or camera.
But the spyware story is not only about the people targeted. It is also about the companies that build the tools, the investors that back them, and the public institutions whose money can end up supporting the industry.

Apache and Follow the Money reported that European public money was awarded to spyware companies based outside Europe, supporting an industry that is seen as threatening democracy and freedom of expression. In May, Apache reported that the European Investment Fund (EIF) would stop financing spyware companies based outside the EU and EFTA.
Civil society groups, including EDRi, welcomed the shift, while warning that the policy still left gaps. EU-based spyware companies could remain eligible for funding.
The same spyware ecosystem has also been tested in court. In 2022, Reporters United exposed the targeting with Predator spyware of journalist Thanasis Koukakis, as part of a wider scandal involving surveillance of journalists, politicians, and public figures. This February, an Athens court convicted four people linked to Intellexa, the company behind Predator spyware. They were each sentenced to 126 years and eight months in prison. The sentences have been suspended pending appeal. Thanasis’ testimony and the newsroom’s investigation were used as evidence in the trial.
//videourl//
The verdict was a rare court decision against people connected to the spyware industry in Europe. It also showed the limits of the case so far. The court addressed the people linked to the company and the tools, but did not establish who ordered the surveillance.
In March, members of the European Parliament discussed the Predatorgate convictions as part of wider concerns over rule of law, media freedom, and surveillance abuse in Greece. Parliament’s briefing noted that a prosecutor had also ordered a criminal investigation for espionage, including others who may be involved.
"Investigations don’t always see immediate impact after the first story is published"
Investigations don’t always see immediate impact after the first story is published. The first report identifies the target, the tool, or the company. Turning that reporting into accountability often takes much longer: depending on records, legal proceedings, public hearings, and pressure, which can take years to build.
The last few months showed that process in motion: a phishing message became evidence of a wider campaign, reporting on investment flows impacting EU-backed funding, and a 2022 investigation into a Greek journalist’s phone helped inform the record used in court four years later.