Pegasus Leaves Few Traces, But Repeated Hits on One Journalist Reveal a Bigger Pattern
A Dominican investigative reporter’s iPhone was flagged multiple times in a Pegasus case that highlights how mobile spyware is usually proven by forensic residue, not visible alerts.
Introduction
When a phone is suspected of being watched by spyware like Pegasus, the danger is not only the intrusion itself. It is the uncertainty that follows: what was accessed, how long the access lasted, and whether the same target was watched again. In this case, the technical significance sits in the repeat pattern. Amnesty International documented multiple compromise events tied to Dominican investigative journalist Nuria Piera’s iPhone between 2020 and 2021, during a period when she was reporting on alleged corruption involving senior figures in the Dominican Republic.
That matters because Pegasus investigations rarely hinge on a loud malware alert. They depend on forensic traces, device artifacts, and careful validation. At the time of writing, public information does not fully establish the complete scope of affected users, the exact operator, or whether any data was taken from Piera’s device. The available evidence supports a risk analysis, not a definitive claim about every technical detail.
Fast Facts
- Amnesty International documented Pegasus cases involving journalists in 18 countries.
- Nuria Piera is identified as a Dominican investigative journalist.
- Her iPhone was reported compromised three times between 2020 and 2021.
- The case sits in a class of mobile spyware investigations that often rely on forensic artifacts rather than on-device alerts.
- The broader risk is not just one infection, but repeated targeting over time.
Body
Pegasus belongs to the highest end of the mobile surveillance market: stealthy, targeted, and built to avoid the kind of obvious signs users expect from ordinary malware. That is why these cases are usually assembled from backup analysis, logs, and indicator matching. In plain terms, investigators look for evidence that the phone behaved like a compromised device, even if the owner never saw a warning screen.
For journalists, that creates a hard defensive problem. A handset can become the weakest point in a secure workflow, because it carries contacts, drafts, location history, messaging apps, and access to sources. If a spyware campaign reaches the device, the risk is not limited to the phone itself. It may extend to the people and stories connected to it.
The fact that Piera’s phone was reported compromised more than once is especially important. Multiple detections over a span of months suggest either repeated targeting or repeated attack attempts, and both scenarios should concern newsroom security teams. A single clean scan is not a durable guarantee, particularly in cases involving mercenary spyware or other advanced mobile threats.
From a defensive perspective, the lesson is practical: preserve device state, keep backups when safe to do so, and treat suspected compromise as a high-priority incident rather than a routine cleanup task. Chain of custody, timestamps, device model, and operating system version can all matter later if a forensic review is needed. Just as important, public indicator checks should be treated as triage, not proof of innocence.
Conclusion
The larger lesson is that modern surveillance can be both selective and persistent, especially when the target is a reporter working near political power. Pegasus cases are difficult because the strongest evidence is often invisible to the victim, and the most important question is not only whether a phone was touched, but what that access meant for a journalist’s safety and sources. In this arena, the defender’s edge comes from disciplined forensics, not from assuming silence means security.
TECHCROOK
Portable external SSD: A compact local backup drive can help journalists and security teams preserve device copies, logs, and documents for later review. Choose a reputable model with hardware encryption if available, and keep it stored separately from daily-use devices.
WIKICROOK
- Pegasus: Advanced mobile spyware used for covert surveillance on smartphones.
- Forensic artifact: A trace left on a device that can help indicate compromise or malicious activity.
- Indicator of Compromise (IOC): A technical sign, such as a domain or file pattern, used to detect possible attack activity.
- Mobile forensics: The examination of phone data, backups, and logs to look for signs of intrusion.
- Chain of custody: The documented handling of evidence so it remains trustworthy in later review.



