Members of the European Parliament (MEPs) have raised urgent concerns regarding the allocation of European Union funds to companies that develop commercial spyware. A coalition of 39 MEPs has formally demanded explanations from senior European Commission officials after investigative reports revealed that millions of euros in EU subsidies have been directed to spyware vendors. These companies, including Intellexa, Cy4Gate, Verint, and Cognyte, have been linked to unlawful surveillance activities targeting journalists, human rights defenders, and political figures both within the EU and in countries with poor human rights records. The MEPs' letter specifically references findings from the investigative outlet Follow the Money, which documented how state-owned entities and EU programs, such as the European Defense Fund and Horizon 2020, have provided substantial financial support to these firms. For instance, Cy4Gate reportedly received at least €3.8 million from EU sources over a four-year period ending in 2024, with the company claiming the funds were for research and development in cybersecurity technologies for both civilian and defense applications. Additional funding examples include €1.3 million from Spain’s public Centre for the Development Of Industrial Technology to Mollitiam Industries, and €1.74 million from Horizon 2020 to projects involving Innova, a supplier of surveillance tools to Italian prosecutors. The European Regional Development Fund and the European Social Fund also contributed to Innova and Movia, the latter developing the Spider spyware. The MEPs argue that these funding practices raise serious questions about the governance, transparency, and accountability of EU financial mechanisms. They highlight the contradiction between the EU’s stated commitment to democracy and human rights and its indirect support for technologies that undermine these values. The letter was addressed to key European Commission officials responsible for technology, democracy, and budget oversight, demanding a thorough review and immediate action to prevent further subsidization of spyware companies. The issue has gained urgency as several MEPs have themselves been targeted by mercenary spyware, prompting the European Parliament to implement proactive device checks for its members. The controversy follows a series of scandals in countries such as Italy, Greece, Poland, Hungary, and Spain, where spyware has been used in politically sensitive surveillance operations. The MEPs also referenced recommendations from the PEGA inquiry, which previously called for stricter controls on surveillance technology. The ongoing revelations have intensified calls for greater oversight and reform of EU funding programs to ensure they do not enable the erosion of fundamental rights. The situation underscores the complex intersection of technology development, public funding, and civil liberties within the European Union. The European Commission is now under significant pressure to clarify its position and implement safeguards against the misuse of EU resources. The debate is expected to continue as more details emerge about the extent of EU involvement in supporting the spyware industry. The outcome of this inquiry could have far-reaching implications for EU policy on technology, security, and human rights.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
EU authorities acknowledged that substantial European funding had gone to commercial spyware manufacturers. This marked an official response to earlier parliamentary demands for transparency over public money benefiting the spyware industry.
A group of 39 Members of the European Parliament sent a letter to senior European Commission officials demanding explanations about EU and member-state public funds allegedly benefiting commercial spyware companies. They called for transparency on grants, contracts, due diligence, risk assessments, and implementation of prior PEGA recommendations, while urging a review of subsidies since 2015 and exclusion of spyware vendors from future funding.
In 2023, the European Parliament's PEGA inquiry concluded that spyware abuse constituted a severe EU-wide scandal. It issued recommendations to restrict and regulate the use of spyware.
An investigation by Lighthouse Reports and partner media found that Italian surveillance firms Tykelab and RCS Lab were selling spyware and mobile hacking capabilities inside and outside the EU. The report said their tools enabled global phone tracking and full remote access to devices, and had been used in multiple regions including Europe, Africa, Latin America, and southeast Asia.
The European Parliament launched the PEGA inquiry in 2022 after reports that EU governments had used NSO Group's Pegasus spyware. The inquiry was established to investigate spyware abuse and its implications across the EU.
6 references tracked. Mallory keeps watching after this page renders.
heise.de
Open sourcego.theregister.com
Open sourcetherecord.media
Open sourcetherecord.media
Open sourceeuobserver.com
Open sourceeuroparl.europa.eu
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.