Skip to content

Croatia Was a Client of the Israeli Firm That Mapped Critics of Slovenia's Nuclear Plant

1 min read
Share
Croatia Was a Client of the Israeli Firm That Mapped Critics of Slovenia's Nuclear Plant

The Israeli company CyberGlobes does not break into phones. It does not need to. It simply reads everything people have published themselves - on Facebook, Instagram, TikTok, YouTube, X - and then assembles those billions of crumbs into a map of who spends time with whom, who was where, and who supported what. According to a major investigation by Israel's Haaretz and TheMarker, the firm's tools ended up in the hands of governments not known for their gentleness toward critics.

The client list is what stings. It is not only authoritarian regimes. It includes the US, Norway, Finland, Japan, the Netherlands, Lithuania, Poland, Ukraine - and Croatia. An EU member state, a neighbour, operating under the same legal framework we invoke every time we talk about European standards. Who the client in Croatia was and what the tools were used for, Haaretz does not say. It is not specified, but it is confirmed that it happened.

What it looks like in practice

One tool lets you mark an area on a map and then pull out everyone who posted to Instagram from that location within a given period. Translated: you outline a square on the day of a protest and you get a list of the participants. No court order, no device broken into, nothing resembling classic espionage. Just harvesting what all of us leave behind every day.

The ugliest case in the documents is Indonesia. According to the investigation, a state body asked for help identifying members of the LGBT community. A company employee advised the client to use local slang for gay people, to find prominent activists, analyse their profiles and check which groups they belonged to. In a country where human rights organisations have spent years documenting arrests and punishment by caning.

In Nigeria, after the August 2024 protests in which Amnesty International says at least 24 demonstrators were killed and over 1,200 people arrested, a CyberGlobes employee searched a hashtag linked to the demonstrations while dozens of protesters were already in court on charges that included treason. The Nigerian government was a client of the firm.

And one case much closer to home

European environmental activists were among the targets too. The company collected data on opponents of the planned second unit at Slovenia's nuclear power plant - a project estimated at nine to 15 billion euros. Members of Greenpeace Slovenia and their social media connections were searched. For some, friend lists were pulled as well, effectively drawing a map of the people connected to the project's opponents. Who commissioned those searches is not known.

That is the sentence worth reading twice. This is not a dictatorship on another continent. This is a neighbouring country, citizens opposing an investment worth as much as several Macedonian budgets, and their friends - people who neither protested nor signed anything, but simply appeared on somebody's list of acquaintances.

In Mozambique an employee searched for data on opposition politician Vitano Singano days after his arrest, including databases of stolen data and a facial recognition system. Singano was later released, and in July 2025 he was reportedly kidnapped off a street in Maputo and has not been seen since. The documents do not prove a link to the firm. In Rwanda the tools were used to analyse an anonymous profile critical of President Kagame - producing a list of users who had liked or shared his posts, ranked by the intensity of their support.

CyberGlobes rejects the accusations. It claims the material was stolen in a hack and that some of the documents were altered before publication. It does not say which documents are supposedly forged and offers no evidence. It says it operates lawfully and that confidentiality prevents it from commenting on who its clients are.

In 2022 Facebook announced it had removed over 200 fake profiles the company had used or bought. A source close to the company says it buys data from other firms and does not use fake accounts - but internal documents show that it did buy them, at least in the past.

There is nothing technically difficult in this story. That is exactly the point. The whole operation rests on one single thing: that we voluntarily and constantly publish our locations, dates, friends and opinions. The question is not whether somebody is collecting it - it is which government, on whose orders, and against whom.