Researchers: the iPhone of Meduza owner Galina Timchenko was infected with Pegasus in Germany, the first known case of the tool being used against a Russian
Unclear is who planted the spyware while the founder of the Meduza news outlet was in Germany — The iPhone of a prominent Russian …
Context & Ripple Effects
This report extends an established record of Pegasus compromising iPhones: Amnesty’s earlier examinations found successful infections and attempted infections among the devices it inspected, documented in its iPhone-focused Pegasus findings.
The case also sits alongside reporting that other commercial spyware tools targeted journalists, politicians, and civil-society workers on iOS, including QuaDream activity detailed by Citizen Lab and Microsoft. It matters because it brings that wider mercenary-spyware risk to the owner of a Russian news outlet while she was in Germany, without establishing who deployed it.
First-order effects
- Timchenko and Meduza face an immediate device-security and operational-security incident, including assessing what information or communications may have been exposed.
- The finding adds a documented Pegasus case involving a Russian media figure, while attribution remains unresolved.
Second-order effects
- News organizations and high-risk sources connected to Meduza have reason to treat iPhones and private communications as potentially exposed, increasing the value of forensic checks and tighter device practices.
- The case reinforces scrutiny of commercial spyware vendors and of the safeguards meant to limit use of tools that have also appeared in reported targeting of a Meta security and trust worker.
Third-order effects
- If repeated findings continue across journalists, activists, and security personnel, commercial spyware will increasingly be treated as a cross-border threat to press and civil-society infrastructure rather than a narrowly targeted law-enforcement capability.
- The recurring iOS cases strengthen demand for independent forensic research and faster platform remediation, though this incident alone cannot identify the operator or prove a broader campaign.
The trend: Mercenary spyware is becoming a persistent cross-border security risk for high-value civil-society and media targets, with mobile-device forensics central to documenting its reach.