The 13 August 2026 X (formerly Twitter) post was sparing in the use of words. Notwithstanding, it was a marvel of saying too much without saying too much.
“My Whatsapp (sic) phone line has been hacked,” the dissident wrote matter-of-factly. “Disregard any text from it. I am working with folks at @Meta & @WhatsApp to reclaim and restore it.”
By turns chilling and sinister, the hack struck responders to Nicholas Opiyo’s social media post as an Orwellian masterpiece. After coming through money laundering charges that saw him arrested three days before Christmas of 2020, with the state losing interest in the case nine months later, Opiyo fled his native country. That was in October of 2021, weeks after the dying embers of the money laundering charges brought against him had been put out.
Many observers had found the case disquietingly flimsy, politically bizarre, and, in its naked essentialising, even sort of personal. Like your typical fly in the ointment, Opiyo was not in the habit of being made to accept highly contestable and expressly political conclusions. This so infuriated government functionaries, some observers hypothesised, adding, now it was payback.
The whole episode took a heavy toll on Opiyo, leaving him so discomfited that he fled the country without “even hav[ing] the time to bid my family goodbye.” Even as the human rights lawyer prepared to settle at a place that is impossibly idyllic, taking his residence at the Harvard Kennedy School of Government’s Carr Centre for Human Rights Policy in the United States of America (U.S.A.), he remained rooted firmly in the cross hairs. At least for the proverbial sledgehammer that has earned a reputation for if not intolerance then seeing everything as a nail.
It is early days yet for any well-credentialed authority to name names as pertaining to the hack at whose hands Opiyo recently suffered. Even so, grandees who have studiously applied themselves to the task of studying state repressions in contemporary Uganda were convinced—and still are—that telltale signs were/are there in profusion. And Opiyo must have known that his fervent promise—before fleeing into exile—to “enhance our human rights network” predisposed him to being a victim of the levers of surveillance.
Healthy appetite for spyware
When not lost to the fog of history, the portrait sketched captures the ravenous appetite that is generated for spyware during and immediately after an election cycle in Uganda. After the 2011 polls there was the secret operation codenamed Fungua Macho (‘open your eyes’) where the devices of change agents were targeted with intrusion malware. This was specifically in the shape of FinFisher’s full ‘Fintrusion suite.’
“Once infected, a person’s computer or phone can be remotely monitored in real time. Activities on the device become visible. Passwords, files, microphones and camera can be viewed and manipulated without the target’s knowledge,” disclosed Privacy International that worked with BBC Newsnight, Netzpolitik, The Citizen Lab (University of Toronto, Canada) and Claudio Guarnieri to stitch together the report entitled For God and My President: State Surveillance in Uganda.
The repressive state apparatus leaned on spyware from Gamma Group especially hard because the triumph that long-serving Ugandan president, Yoweri Museveni, scored in securing a fifth elective term was met with civil disobedience. While the walk to work protests were ultimately seen as a remarkably low-wattage act of civil disobedience, it would be understating things a bit if one came to the conclusion that the Activists for Change (A4C) pressure group didn’t keep the Government of Uganda (GoU) walking the floor nights. This after all was the age of the Arab Spring. Regimes had been taken down by seemingly innocuous actions. Take a fruit vendor’s self-immolation in Tunisia to protest against economic hardship.
“The Walk to Work movement subsided in 2012. Popular support for the movement dwindled. The A4C pressure group was declared illegal. Attempts to organise publicly were consistently intercepted and dispersed. […] Along with more heavy-handed tactics, the use of surveillance technology has chilled free speech and legitimate expressions of political dissent,” Privacy International’s 2015 report noted.
“Covert, extrajudicial surveillance projects like those documented in this report have contributed to making Uganda a less open and democratic country. This situation is likely to worsen with the eventual addition of the centralised communications monitoring centre under the intelligence services’ control,” the report adds.
Indeed, by the 2016 election cycle change agents noticed that the status quo was no better than before—if anything worse. Such were the dire straits that a grim acknowledgement of reality took root in the admission that, rather than wean itself of spyware, the state apparatus was doubling down on if not usage then purchase of the same.
“The police also attempted to procure further technologies from intrusion malware supplier and rival to Gamma Group, Hacking Team, in mid-2015. The local contact for the Hacking Team potential deal was Kin Kariisa, a business executive considered among Museveni’s close contacts, according to documentation obtained by Privacy International. Kariisa was the President’s special advisor on ICT from 2000 to 2009,” Privacy International revealed in a 2019 study entitled State of Privacy Uganda.
A case of back to the future
If change agents were gripped by a granite certainty that the GoU would be in the market for covert device-hacking malware ahead of the 2016 polls, a change of tack came less as a surprise as a troubling inevitability. The repressive state apparatus, noted the Ugandan-based civil society organisation, Unwanted Witness, drew upon “broad telecommunications monitoring, social media censorship, and network blocks.” The GoU was however pulled toward the lure of spyware when Robert Kyagulanyi Ssentamu, alias Bobi Wine, made a conscious decision to join elective politics in 2018.
Wine’s win that year in a parliamentary by-election illustrated the tectonic forces at work. By 2019 the musician-turned-politician had become the victim of a sophisticated hack. Wall Street Journal journalists Josh Chin and Liza Lin described how the hack played out in their 2022 book, Surveillance State: Inside China’s Quest to Launch a New Era of Social Control.
They write: “Apple’s security was virtually impossible to crack using traditional methods, which meant it was pointless to try to get their hands on the phone. Instead they [the intelligence officers] turned to spyware that Ugandan security forces had recently purchased from an Israeli firm.
“The spyware was modeled on Pegasus, a tool developed by a team of former Israeli intelligence operatives known as the NSO Group, that exploits flaws in iPhone security to give operators a level of control over the device normally reserved for Apple itself.”
Their body of work further adds: “The intelligence team used a text message to trick Wine into downloading the spyware on his phone. Israeli experts had flown out to Kampala to teach the intelligence officers how to use the spyware to access emails and texts, but not encrypted messages. The team spent days huddled around a computer trying to get it to work. They failed.
“For months, the police intelligence team had been sharing their command center with technicians from Huawei […] Desperate, the intelligence officers walked across the room to where the Chinese men sat and asked if they could help [….] the technicians dropped what they were doing and took control of the spyware. Within two days, they had full access to Wine’s phone.”
Big brother shows off new toys
It shouldn’t therefore come as a vulgar surprise that there was a gargantuan appetite for spyware before Ugandans went to the polls in January of 2026. For those that do not let the small oddities they notice pass by without much reflection, leaks of secret wiretap recordings of dissidents like Wine, the academic Jimmy Spire Ssentongo as well as journalists Timothy Kalyegira and Solomon Serwanjja were instructive. Big brother was, well, watching. And particularly keen on showing off his new toys.
Less publicised as those phone conversations between the aforesaid male dissidents and their female acquaintances, but no less remarkable, was how the Nation Media Group Uganda’s computer network capitulated after coming under an attack. With a few weeks left before the 2026 General Elections, black hats gained access to the media conglomerate’s computer network courtesy of the most basic of tactics—a phishing email.
A female sub-editor at the Daily Monitor newspaper, evidently off her game after coming through a Christmas feast days before, was tricked into downloading a virus. The virus was triggered when she forwarded part of her day’s work to the chief sub-editor. The trail of damage was traceable to not just the IT infrastructure of the media conglomerate’s newspaper but also radio and television.
“We have just gone through and established the scale of the damage by the malware attack. There is stuff that we have to re-digitise. It wasn’t until some people were trying to get some content that they established the extent of the damage,” a top official at the media conglomerate confessed.
Whereas the identity of who is behind the malware attack rests on a cornerstone of conjecture, it is easy to see why conjectural analysis points a figure of blame at government functionaries. Open-access data available on Sayari, Tendata and Trademo lays out how the GoU replenished its surveillance repertoire before the 2026 polls. With the aid of customs records, bills of lading and shipping manifests, to mention but three, the third-party commercial data platforms—meticulous in reviewing even the smallest details—leave little to one’s imagination. They log an unseemly number of equipment purchases made in the run-up to the 2026 polls.
The equipment logged included: automatic data processing machine storage units, portable receivers, portable automatic data processing machines, multi-channel power probes, radio communication testers, EMI test receivers, signal and spectrum analysers as well as telephone sets with either the fourth generation of cellular network technology or wireless technology.
Sayari, a US-based search engine, said of the purchases thus: “[Uganda] has not previously been reported to have procured or deployed Circles surveillance technologies—however, [Uganda] is suspected of having used NSO Group’s Pegasus spyware as recently as 2021, and recent reporting by The Citizen Lab indicates that [Uganda] has deployed telecom exploitation tools (like those developed and sold by Circles[, a subsidiary of NSO Group]) to geolocate Utel Uganda users[, a government-owned phone company].”
Tanzania’s surveillance hardware
Before Ugandans went to the polls in January of 2026, Tanzania had its moment in the sun. It arrived in October of 2025 when Samia Suluhu Hassan—the incumbent—won a commanding victory over tens of candidates in a race that shorn of Chadema’s Tundu Lissu. In the build-up to the vote, Lissu, the chairman of the centre-right party, was confined in prison after his demands for electoral reforms were deemed to be treasonable.
When rights activists within East Africa tried to rally support for Lissu as the 2025 election cycle entered the final bend, they were met with the full force of the repressive state apparatus. While some, like Martha Karua, Kenya’s former Justice minister, were deported, others, like Agather Atuhaire and Boniface Mwangi, the rights activists from Uganda and Kenya respectively, were abducted and subjected to gory acts of torture. What Atuhaire and Mwangi were subjected to is treatment that change agents in Tanzania have become accustomed to. In recent times, the aforesaid change agents have also come to learn that one can reap tremendous rewards by keeping a studied distance from their own devices.
The Citizen Lab says there is no shortage of hard evidence indicating that Tanzania uses spyware from entities like Circles to keep change agents on a short leash. The technical device exploitation is reported to help intelligence officers in the country “to intercept text messages, phone calls, and track device locations using just a phone number, without necessarily needing to hack the target phone directly.” For one, before the 2025 polls, Dodoma reached out to Circles through Magilatech Company Limited. By December 2024, a dozen shipments with data processing machines, static converters, electric conductors, electric accumulators, copper nails and monitors were sent to Tanzania from Bulgaria.
After the disputed election, which saw the incumbent poll 98 per cent, government functionaries had Oxygen Forensics Inc, a US-based company, ship in surveillance-related hardware on 6 November 2025. With hundreds, if not more, feared dead in the unrest that ensued following Samia’s landslide win, it is thought that Oxygen’s digital forensic tools pointed to Dodoma’s determination to get on to the front foot. This was insofar as quelling dissent was concerned.
Kenya’s response to Gen Z protests
In recent times, there has been an unguarded ease about the William Ruto administration that suggested a polity in every way content to suppress dissent. Ruto, Kenya’s fifth and current president, has been accused of battening down the hatches ever since mid 2024 when opposition to proposed tax hikes on essential goods during a cost-of-living crisis illuminated pain points that can sprout from the country’s youth bulge. Since then Ruto’s intelligence tsars have often been accused, with some justice, of grasping the hidden contours of targeted surveillance.
For this reason many dissidents in the East African powerhouse have remained uncomfortable in the excessively abundant supply of intrusive malware. In early 2026, a forensic investigation by The Citizen Lab established that extraction tools from Cellebrite—an Israeli digital intelligence firm—were used to bypass security features on Boniface Mwangi’s Samsung phone. That was in July of 2025. The dissident had been arrested during anti-government demonstrations. Mwangi’s phone was not returned until September of 2025, and it didn’t take him long to pick out telltale signs. The phone’s password protection had been removed en route to intelligence officers harvesting anything and everything deemed useful.
Earlier, at the backend of 2025, The Citizen Lab had also established that FlexiSPY, a sophisticated surveillanceware for iOS and Android, had been installed on the gadgets of four independent filmmakers. Nicholas Gichuki, Brian Adagala, Mark Karubiu, and Chris Wamae had in May of 2025 been arrested on allegations of, amongst others, publishing false information. This was after their documentary entitled Blood Parliament shined an uncomfortable spotlight on violent police crackdowns, some of which resulted in deaths, during the June 2024 anti-tax/anti-finance bill protests in the Kenyan capital of Nairobi. The gadgets of the filmmakers were seized by the Directorate of Criminal Investigations (DCI) during their arrests.
As the clock ticks to the polls set for next August, open-access data available on Sayari, Tendata and Trademo paints a rather grim picture. Using Wickham Bros Ltd as an intermediary, the Ruto administration has had Q Cyber Technologies ship in a vast array of NSO Group products. Rwanda, which stages its next general election in 2029, has also been confirmed to set more store on Q Cyber Technologies and its timely shipment of NSO Group products. Big brother will undoubtedly be watching, and—as dissidents like Nicholas Opiyo attest—he wields a deft knife.
