Security

Polish Senate says use of government spyware is illegal in the country

Comment

Polish Prime Minister Mateusz Morawiecki gives a speech during his visit in Krakow, Poland on 15 April, 2018. (Photo by Beata Zawrzel/NurPhoto via Getty Images)
Image Credits: Beata Zawrzel/NurPhoto via Getty Images / Getty Images

A special commission within Poland’s Senate concluded that the government’s use of spyware, like the one made by NSO Group, is illegal.

The commission announced on Thursday the conclusion of its 18-month investigation into allegations that the Polish government used NSO’s spyware, known as Pegasus, to spy on an opposition politician and other politicians around the time of the country’s 2019 elections.

“Pegasus cannot be used under Polish law,” the report read, according to a machine translation. “This is because the Polish legal system does not allow the use of programs in which acquired operational data is transferred through transmission channels uncontrolled by the relevant services, as this creates the risk of violating its integrity and does not ensure its confidentiality, as required by law.”

In other words, NSO’s spyware is not designed in a way that respects Polish law, collects too much information and cannot guarantee that that information is secured properly, according to the report.

The commission also concluded that the Polish government used Pegasus to retaliate against opposition figures, and that these surveillance operations negatively influenced the 2019 elections in the country. The commission compared these abuses with Russian government hacker activities in the 2016 elections in the United States.

Deputy Speaker of the Senate Michał Kamiński is quoted in a press release as saying that Pegasus was used to spy on politicians in the opposition, including Polish senator Krzysztof Brejza, and to influence the political process.

“It turns out that huge amounts of money,” Kamiński said, according to a machine translation, “are not spent in order to catch Russian agents, but in order to be interested in the life and views of Polish opposition politicians and influence the political process in Poland. This monstrous weapon was not used to protect citizens, but as our committee proved, it was used to persecute people who did not like the authorities.”

John Scott-Railton, a senior researcher at the internet watchdog Citizen Lab who has been investigating NSO and its customers’ abuses for years, said the fact that a European country’s government body reached these conclusions is significant because it shows there are serious problems with the use of government spyware in democratic countries too, and not just repressive regimes.

“A lot of people when they think about Pegasus they think about dictators using spyware. And of course, it’s true. But what this report basically says is, look, when Pegasus is sold to democracies, it can cause great harm to core democratic processes like elections,” Scott-Railton told TechCrunch.

Since 2016, Citizen Lab and Amnesty International have published multiple reports highlighting the abuse of NSO’s hacking tools in countries such as the United Arab Emirates, Saudi Arabia and Mexico, among many others. In the last few years, however, researchers have also found cases of abuse in European Union countries such as Poland, Hungary and Spain.

From NSO’s perspective, according to Scott-Railton, Europe has always been a good market because the company could point to it and say their tools are not abused there, given those countries’ reputations. But, as evidenced by the Polish investigation, that hasn’t always been the case. Scott-Railton said the report puts pressure on other countries in Europe and elsewhere in the West that can’t justify the use of tools like NSO’s anymore.

“It raises all these questions about countries like Germany, that are apparently continued users, and think that their use is not going to be harmful elsewhere,” Scott-Railton said. “No, their use is harmful because it legitimizes NSO and keeps them buoyed with revenue. You can’t do business with NSO and not contribute to the harm that it causes.”

A spokesperson for NSO did not respond to a request for comment Thursday.

Lukasz Olejnik, a Polish independent researcher and consultant, told TechCrunch that regulations on the use of surveillance technologies in Poland are “rather generic, if non-existent, according to some.” Olejnik also highlighted that the report considers all kinds of spyware like Pegasus to be illegal in Poland.

“The report adopts an interesting line of argumentation, claiming that it would be illegal to use any system that would operate in ways so the collected data (or the target details) left Polish jurisdiction (i.e. border), as well as any systems whose design or source code cannot be inspected and ‘accredited’,” Olejnik said.

That means, according to Olejnik, this conclusion could extend to Poland’s use of spyware made by other companies such as Hacking Team, a now-defunct spyware maker that sold its wares to the country from 2012 to 2015.

Dział Prasowy, a spokesperson for the Polish Senate, confirmed in a statement that “all spyware like Pegasus is illegal in Poland unless it has been accredited” by the country’s Internal Security Agency (ABW) or the Military Counterintelligence Service (SKW).


Do you have more information about NSO Group or another surveillance tech provider? Or information about similar hacks? We’d love to hear from you. You can contact Lorenzo Franceschi-Bicchierai securely on Signal at +1 917 257 1382, or via Wickr, Telegram and Wire @lorenzofb, or email lorenzo@techcrunch.com. You can also contact TechCrunch via SecureDrop.

Updated on September 11 with comment from Poland’s Senate.

More TechCrunch

The spam reached Bluesky by first crossing over two other decentralized networks: Mastodon and Nostr.

The ‘vote Trump’ spam that hit Bluesky in May came from decentralized rival Nostr

Welcome to TechCrunch Fintech! This week, we’re looking at the continued fallout from Synapse’s bankruptcy, how Layer wants to disrupt SMB accounting, and much more! To get a roundup of…

There’s a real appetite for a fintech alternative to QuickBooks

The company is hoping to produce electricity at $13 per megawatt hour, which would be more than 50% cheaper than traditional onshore wind.

Bill Gates-backed wind startup AirLoom is raising $12M, filings reveal

Generative AI makes stuff up. It can be biased. Sometimes it spits out toxic text. So can it be “safe”? Rick Caccia, the CEO of WitnessAI, believes it can. “Securing…

WitnessAI is building guardrails for generative AI models

It’s not often that you hear about a seed round above $10 million. H, a startup based in Paris and previously known as Holistic AI, has announced a $220 million…

French AI startup H raises $220M seed round

Hey there, Series A to B startups with $35 million or less in funding — we’ve got an exciting opportunity that’s tailor-made for your growth journey! If you’re looking to…

Boost your startup’s growth with a ScaleUp package at TC Disrupt 2024

TikTok is pulling out all the stops to prevent its impending ban in the United States. Aside from initiating legal action against the U.S. government, that means shaping up its…

As a US ban looms, TikTok announces a $1M program for socially driven creators

Microsoft wants to put its Copilot everywhere. It’s only a matter of time before Microsoft renames its annual Build developer conference to Microsoft Copilot. Hopefully, some of those upcoming events…

Microsoft’s Power Automate no-code platform adds AI flows

Build is Microsoft’s largest developer conference and of course, it’s all about AI this year. So it’s no surprise that GitHub’s Copilot, GitHub’s “AI pair programming tool,” is taking center…

GitHub Copilot gets extensions

Microsoft wants to make its brand of generative AI more useful for teams — specifically teams across corporations and large enterprise organizations. This morning at its annual Build dev conference,…

Microsoft intros a Copilot for teams

Microsoft’s big focus at this year’s Build conference is generative AI. And to that end, the tech giant announced a series of updates to its platforms for building generative AI-powered…

Microsoft upgrades its AI app-building platforms

The U.K.’s data protection watchdog has closed an almost year-long investigation of Snap’s AI chatbot, My AI — saying it’s satisfied the social media firm has addressed concerns about risks…

UK data protection watchdog ends privacy probe of Snap’s GenAI chatbot, but warns industry

U.S. cell carrier Patriot Mobile experienced a data breach that included subscribers’ personal information, including full names, email addresses, home ZIP codes and account PINs, TechCrunch has learned. Patriot Mobile,…

Conservative cell carrier Patriot Mobile hit by data breach

It’s been three years since Spotify acquired live audio startup Betty Labs, and yet the music streaming service isn’t leveraging the technology to its fullest potential — at least not…

Spotify’s ‘Listening Party’ feature falls short of expectations

Alchemist Accelerator has a new pile of AI-forward companies demoing their wares today, if you care to watch, and the program itself is making some international moves into Tokyo and…

Alchemist’s latest batch puts AI to work as accelerator expands to Tokyo, Doha

“Late Pledge” allows campaign creators to continue collecting money even after the campaign has closed.

Kickstarter now lets you pledge after a campaign closes

Stack AI’s co-founders, Antoni Rosinol and Bernardo Aceituno, were PhD students at MIT wrapping up their degrees in 2022 just as large language models were becoming more mainstream. ChatGPT would…

Stack AI wants to make it easier to build AI-fueled workflows

Pinecone, the vector database startup founded by Edo Liberty, the former head of Amazon’s AI Labs, has long been at the forefront of helping businesses augment large language models (LLMs)…

Pinecone launches its serverless vector database out of preview

Young geothermal energy wells can be like budding prodigies, each brimming with potential to outshine their peers. But like people, most decline with age. In California, for example, the amount…

Special mud helps XGS Energy get more power out of geothermal wells

Featured Article

Sonos finally made some headphones

The market play is clear from the outset: The $449 headphones are firmly targeted at an audience that would otherwise be purchasing the Bose QC Ultra or Apple AirPods Max.

6 hours ago
Sonos finally made some headphones

Adobe says the feature is up to the task, regardless of how complex of a background the object is set against.

Adobe brings Firefly AI-powered Generative Remove to Lightroom

All cars suffer when the mercury drops, but electric vehicles suffer more than most as heaters draw more power and batteries charge more slowly as the liquid electrolyte inside thickens.…

Porsche Ventures invests in battery startup South 8 to boost cold-weather EV performance

Scale AI has raised a $1 billion Series F round from a slew of big-name institutional and corporate investors including Amazon and Meta.

Data-labeling startup Scale AI raises $1B as valuation doubles to $13.8B

The new coalition, Tech Against Scams, will work together to find ways to fight back against the tools used by scammers and to better educate the public against financial scams.

Meta, Match, Coinbase and others team up to fight online fraud and crypto scams

It’s a wrap: European Union lawmakers have given the final approval to set up the bloc’s flagship, risk-based regulations for artificial intelligence.

EU Council gives final nod to set up risk-based regulations for AI

London-based fintech Vitesse has closed a $93 million Series C round of funding led by investment giant KKR.

Vitesse, a payments and treasury management platform for insurers, raises $93M to fuel US expansion

Zen Educate, an online marketplace that connects schools with teachers, has raised $37 million in a Series B round of funding. The raise comes amid a growing teacher shortage crisis…

Zen Educate raises $37M and acquires Aquinas Education as it tries to address the teacher shortage

“When I heard the released demo, I was shocked, angered and in disbelief that Mr. Altman would pursue a voice that sounded so eerily similar to mine.”

Scarlett Johansson says that OpenAI approached her to use her voice

A new self-driving truck — manufactured by Volvo and loaded with autonomous vehicle tech developed by Aurora Innovation — could be on public highways as early as this summer.  The…

Aurora and Volvo unveil self-driving truck designed for a driverless future

The European venture capital firm raised its fourth fund as fund as climate tech “comes of age.”

ETF Partners raises €285M for climate startups that will be effective quickly — not 20 years down the road