CatalanGate

CatalanGate is a 2022 political scandal involving accusations of espionage using the NSO Group's Pegasus spyware, against figures of the Catalan independence movement. Targets of the supposed espionage included elected officials (including the four presidents of the Generalitat of Catalonia since 2010, two presidents of the Parliament of Catalonia, and MEPs), activists, lawyers, and computer scientists; in some cases, families of the main targets were also purportedly targeted.

The scandal was unleashed by the publication of an article in the New Yorker magazine, quoting studies by the University of Toronto's Citizen Lab, in which they examined the use of Pegasus spyware by different countries (Pegasus is only sold to governments who, according to Israel's own government, follow rule of law), and alleged to have found evidence of its use in phones owned by several Catalan politicians and their entourage.

The Citizen Lab report was published on April 18, 2022. The report identified up to 65 alleged victims, consummated or attempted. The number of targets exceeded previous cases of espionage studied by Citizen Lab, far surpassing those of Al Jazeera (36 victims) and El Salvador (35 victims). Citizen Lab did not definitively attribute the responsibility for the attacks to a particular perpetrator, however, it went on to state that circumstantial evidence strongly suggests the perpetrator to be the Spanish Government. The term CatalanGate was used as title of the Citizen Lab report. Despite the scandal's dissemination as CatalanGate, it also allegedly affected two prominent Basque pro-independence figures.

Background
Citizen Lab is a Canadian interdisciplinary laboratory, based at the Munk School of Global Affairs at the University of Toronto, which focuses on research, development, strategic policy and high-level legal engagement at the confluence of information and communication technologies, human rights and global security.

In April 2019, Citizen Lab worked on a case involving Pegasus infections that exploited a WhatsApp security bug that enabled infiltration of at least 1,400 terminals. Among the people alerted to the problem was the President of the Catalan Parliament, Roger Torrent. Among the politicians affected by the breach were Ernest Maragall, Anna Gabriel, and Basque leaders like Arnaldo Otegi and Jon Iñarritu.

MEP Jordi Solé started an investigation in June 2020, when he suspected that he was a victim of cell phone spying and contacted the security researcher Elies Campo, a former WhatsApp employee and collaborator of Citizen Lab.

Most of the Catalan officials affected by the surveillance belong to the Catalonia pro-independence parties.

Scandal
Collaboration between potential victims and Citizen Lab helped identify at least 65 people supposedly attacked or infected with the spyware, 63 of them with Pegasus and 4 with Candiru (two victims were targeted using both). The actual figure could be higher as Citizen Lab's tools are developed for use with iOS systems and, in Spain, Android devices predominate (80% of the total in 2021). A selection of the cases was also analyzed by Amnesty International's Tech Lab, and the results independently validated the forensic methodology used. Virtually all incidents correspond to the period between 2017 and 2020 (although Jordi Sànchez suffered an attempted infection via SMS in 2015).

In its report, Citizen Lab states that "while we do not attribute the operation to a specific government entity at this time, the circumstantial evidence shows a strong link to the Spanish government, especially given the nature of the individuals targeted, the timing of the attacks, and the fact that Spain is listed as a client of NSO Group".

Once the scandal reached Spanish parliament, government officials produced documentation to certify that 29 people were indeed subject to government surveillance, fully approved by the Supreme Court of Justice and according to legal procedure. The surveilled people included past and serving elected officials and regional authorities belonging to parties involved in the 2017 Catalan Independence referendum.

Methods of infiltration
In some cases (and as is often the case), the attack was carried out by an intermediary: infecting, or attempting to infect, the terminal of family members or people close to the target to be spied on.

Pegasus

A peculiarity of this case for Citizen Lab was the discovery of a new iOS zero-click vulnerability, which they called HOMAGE, that had not previously been seen used by NSO Group, and which was effective against some versions prior to 13.2.

Candiru

Citizen Lab identified four victims of espionage involving Candiru. Candiru spyware was used to infiltrate the targets' personal computers. The targets were sent emails containing malicious links and enticed to click on them, with their personal computers becoming infected with Candiru spyware once they clicked on the link. A total of seven such emails were identified. Some of the emails appeared to be messages from a Spanish governmental institution with public health recommendations in connection to the 2019 coronavirus epidemic.

List of victims
With the exception of four people who requested anonymity, this is the list of victims of the CatalanGate espionage case:


 * Alba Bosch (activist)
 * Albano-Dante Fachín (journalist and former member of Parliament for Catalunya Sí que es Pot)
 * Albert Batet (president of the parliamentary group Junts)
 * Albert Botran (deputy of the CUP in the Congress)
 * Andreu Van den Eynde (lawyer of Junqueras, Torrent, Romeva and Maragall)
 * Anna Gabriel (former deputy of the CUP in the Parliament)
 * Antoni Comín (Junts MEP)
 * Arià Bayé (member of the ANC)
 * Arnaldo Otegi (secretary general of EH Bildu)
 * Artur Mas (President of the Catalan government 2010-2015)
 * Carles Riera (politician, CUP)
 * David Bonvehí (president of PDeCAT)
 * David Fernández (politician, CUP)
 * David Madí (ex-Secretary of Communication of CDC)
 * Diana Riba (ERC MEP)
 * Dolors Mas (businesswoman)
 * Elías Campo (doctor) (father of Elies Campo Cid)
 * Elena Jimenez (lawyer and member of Òmnium Cultural)
 * Elies Campo Cid (ex-director of Telegram and WhatsApp)
 * Elisenda Paluzie (president of the ANC)
 * Elsa Artadi (deputy of Junts per Catalunya)
 * Ernest Maragall (president of the ERC group in the Barcelona City Council)
 * Ferran Bel (deputy in Congress for PDeCAT)
 * Gonzalo Boye (lawyer of Puigdemont, Torra and Comín)
 * Jaume Alonso-Cuevillas (lawyer and deputy of Junts)
 * Joan Matamala (businessman) (close to Carles Puigdemont)
 * Joan Ramon Casals (politician, former director of the office of President Torra)
 * Joaquim Jubert (politician)
 * Joaquim Torra (president of the Generalitat 2018-2020)
 * Jon Iñarritu (deputy of EH Bildu in the Congress)
 * Jordi Baylina (developer)
 * Jordi Bosch (ex-director of Òmnium Cultural)
 * Jordi Domingo (ANC member)
 * Jordi Sánchez (ex-president of the ANC and secretary general of Junts)
 * Jordi Solé (ERC MEP)
 * Josep Costa (politician, former vice-president of the Parliament)
 * Josep Lluís Alay (director of the Office of Carles Puigdemont)
 * Josep Maria Ganyet (businessman and professor at the UPF)
 * Josep Maria Jové (deputy of ERC in the Parliament and former secretary general of the vice-presidency of Economy)
 * Josep Rius (vice-president and spokesman of Junts, member of Parliament)
 * Laura Borràs (president of the Parliament)
 * Marc Solsona (former deputy of PDeCAT in the Parliament)
 * Marcel Mauri (former vice-president of Òmnium Cultural)
 * Marcela Topor (journalist and partner of Carles Puigdemont)
 * Maria Cinta Cid (senior consultant Hospital Clínic, professor and doctor) (mother of Elies Campo Cid)
 * Marta Pascal (secretary general of the Nationalist Party of Catalonia)
 * Marta Rovira (general secretary of ERC)
 * Meritxell Bonet (journalist and partner of Jordi Cuixart)
 * Meritxell Budó (former Minister of the Presidency)
 * Meritxell Serret (deputy of ERC in the Parliament)
 * Míriam Nogueras (deputy of Junts al Congrés)
 * Oriol Sagrera (general secretary of Enterprise and Labor, ERC)
 * Pau Escrich (developer)
 * Pere Aragonès (President of the Generalitat)
 * Pol Cruz (parliamentary assistant in the Eurochamber)
 * Roger Torrent (President of the Parliament 2018-2020, Minister of Enterprise and Labor)
 * Sergi Miquel (PDeCAT deputy in the Congress, Council for the Republic)
 * Sergi Sabrià (Director of the Office of Strategy and Communication of the government, former deputy of ERC in the Parliament)
 * Sonia Urpí (member of the ANC)
 * Xavier Vendrell (politician, ERC)
 * Xavier Vives (developer)

Press coverage
On the same day that saw the publication of CitizenLab's technical report, The New Yorker published an extensive report entitled "How democracies spy on their citizens" (of which the Catalan case occupied a seventh part) as their cover story.

Catalan government response
On April 19 (one day after the initial publication of the revelations), Carles Puigdemont and Oriol Junqueras appeared in the European Parliament to denounce the spying perpetrated upon the pro-independence leaders, an intervention that was joined by the Popular Unity Candidacy, the Catalan National Assembly, and Òmnium Cultural. John-Scott Railton, from Citizen Lab, also took part, detailing "circumstantial evidence": that agencies linked to the structure of the Spanish State would have used Pegasus and Candiru to infiltrate the cell phones of the victims for political purposes. The previous March, the European Parliament had approved the creation of a committee of inquiry called Committee to investigate the use of Pegasus surveillance spyware on the alleged use of Pegasus surveillance spyware against journalists, politicians, security agents, diplomats, lawyers, businessmen, civil society actors and other citizens in, among other countries, Hungary and Poland, and whether such use had infringed European Union law and fundamental rights. The first meeting of the committee was held the same day that Puigdemont and Junqueras denounced the spying.

Criticism
Spanish general media argued that study completely overlooked the publicly-known fact that many of those politicians had been involved in (and in some instances found guilty of) several crimes and misdemeanors, from embezzlement to sedition, and were in fact under judicially-approved government surveillance, under Spanish law. Regarding the naming of the scandal, the domain catalangate.cat was registered by Òmnium Cultural on 28 January 2022 - months before the scandal came to light. The name itself was coined by targeted politician Ernest Maragall.

On the other hand, despite the fact that third partied checked methodologies, some alleged deficiencies in the research methodology where denounced, including the fact that one of the main researcher was a Catalan developer affected by the surveillance. The right wing teachers collective like "Foro de Profesores" collective denounced that the whole scandal was essentially a publicity stunt. to discredit the Spanish government's investigations into past and continuing criminal activity by the surveilled people, and to cover earlier surveillance by the regional secessionist government of opposition politicians.