www.hrw.org Bulgaria's Circles Exports Surveillance Tech to Rights Violators
Article Content
- •Bulgaria licensed Circles to export surveillance tech to countries with human rights violations.
- •Export licenses were granted for tools used in phone tracking and communication interception.
- •Human Rights Watch's findings raise concerns about the effectiveness of EU export controls.
Between 2018 and 2023, Bulgaria licensed the export of surveillance technology from Circles, a company linked to NSO Group, to various countries with histories of human rights abuses. Human Rights Watch revealed that these licenses included tools for phone tracking and communication interception, targeting nations like Azerbaijan, Serbia, and the UAE. The exported technology is believed to be used for internal repression against journalists and political dissenters. Despite the EU's regulations on dual-use technology, Bulgaria's practices raise questions about compliance and enforcement. The Bulgarian government claims the technology is intended for legitimate law enforcement use, but the evidence suggests otherwise. Circles has been implicated in the misuse of surveillance tools against civil society. The lack of accountability and oversight in the licensing process highlights significant flaws in the EU's export control framework.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (9)
Following this threat?
Track Pegasus and Circles in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical GitLab Vulnerabilities Exploited Within Hours of Disclosure On September 10, 2026, GitLab released patches for critical vulnerabilities CVE-2026-85706 and CVE-2026-87719. CVE-2026-85706, a path traversal flaw, allows unauthenticated users to read arbitrary files from GitLab servers, while CVE-2026-87719 enables credential theft via insecure deserialization. Both…
Iranian State Actors Deploy CHOSEN BRICK Spyware Against Dissidents On September 15, 2026, the UK, US, and Netherlands issued a joint advisory regarding a spyware campaign attributed to Iranian state actors targeting dissidents, activists, and journalists. The malware, known as CHOSEN BRICK, is delivered through spear-phishing attacks on messaging platforms like WhatsApp and Telegram.…