President Accounts HACKED – Loses Millions Of Docs!

Hands typing on a laptop with digital cybersecurity graphics overlay
Photo: Comdas / Shutterstock

A spy tool built for governments quietly copied the Spanish prime minister’s phone and walked away with a trove of data.

Story Snapshot

  • Spain confirmed Pegasus spyware hit Prime Minister Pedro Sánchez’s phone in May 2021.
  • Officials called the breach illegal and external, and said large data volumes were taken.
  • Court efforts to identify the user stalled after Israel did not cooperate with requests.
  • Forensics confirmed infection; attribution remains open, years later.

What Spain Says Happened, and When

Spain’s government said Prime Minister Pedro Sánchez’s phone was infected with Pegasus in May 2021, and Defense Minister Margarita Robles was targeted soon after. The minister for the presidency, Félix Bolaños, announced the finding in a rare holiday press conference, calling the intrusions unlawful and external. He said data was extracted from both devices, which means messages, emails, photos, and audio likely moved off the phones to the operator’s servers.

Technical reports from Spain’s National Cryptological Centre backed the claim that Pegasus infected the phones and pulled data. That lab work matters because Pegasus hides deep in a phone’s core. Once inside, it can read texts, turn on the camera and microphone, and copy files without the user seeing a thing. The centre’s confirmation narrowed debate to the key questions: how much was taken, and who ran the operation.

Why The Investigation Keeps Stalling

Spain opened a criminal probe to find out who used Pegasus against its leaders. The National Court sent legal requests to Israeli authorities, because the software is developed and sold by an Israel-based company. Judges later said those requests went unanswered, which blocked next steps like getting customer records or technical logs that can show who pushed the attack and where the data went. The court has shelved the case more than once due to that lack of cooperation.

Judges have said plainly that without replies to those requests, they cannot assign authorship to any person or service. That is the attribution gap that plagues many Pegasus cases. The European Parliament has flagged similar barriers across Europe. The result is the same in country after country: investigators can prove an infection, but they cannot move from “what” to “who” because they lack the vendor’s account trail and back-end details.

How Pegasus Turns A Leader’s Phone Into A Supply Room

Pegasus is sold as a complete surveillance system to state clients. It can enter a phone through a single message or a silent push. After that, it gives the operator full access, twenty-four hours a day. Analysts and rights groups have tracked its use from Mexico to Poland. They describe a pattern: when Pegasus lands on a target phone, everything on that phone becomes harvestable, often in near real time, including secure chat content and cloud tokens that unlock backups.

That capability explains the Spanish government’s alarm about “large amounts of data” leaving Sánchez’s device. Even a few gigabytes can hold years of message threads, contact graphs, calendar files, location traces, and sensitive media. For a head of government, those files can expose negotiation strategies, personal leverage points, and private exchanges with allies. That is why this breach is more than a privacy story; it is a national-security story with diplomatic risk attached.

The Politics: Security, Secrecy, And Common Sense Limits

Officials declined to publicly name a culprit. That restraint fits the evidence. Courts could not verify which client used the tool. Some commentators point at regional rivals, but the record does not show a confirmed operator. On the facts, the stronger point is simpler and more urgent: a tool sold only to governments took data from Spain’s top officials, and the legal system cannot compel the developer’s help to trace it. That should set off alarms across allied capitals.

Common sense says two fixes are due. First, leaders need hardened devices, strict compartmentalization, and shorter data lifespans on phones. If it is not on the handset, it cannot be stolen off the handset. Second, countries that buy or face commercial spyware should demand binding rules for vendor cooperation with lawful probes, including timely, auditable disclosure of client records under court order. Sovereignty means little if a foreign mailbox decides whether your judges get answers.

Sources:

gatewayhispanic.com, reuters.com, bbc.com, elnacional.cat, lamoncloa.gob.es, upi.com, politico.eu, apnews.com, courthousenews.com