An article featuring private investigator Nikos Pelekasis, originally published in the Greek newspaper TA NEA.
“A search through advertisements on the internet and in numerous publications shows that the ‘drin drin’ case was merely the tip of the iceberg. There are dozens of investigation agencies offering, for a relatively small fee, the ability to monitor almost anyone.”
The Cyber Crime Division’s investigation into the company “drin drin” — which, for €20 per month, allegedly offered companies the ability to monitor executives or engage in industrial espionage, law firms to monitor opposing parties, and shipowners to listen in on their competitors’ business plans — highlighted a major gap in the protection of mobile phone users, particularly smartphone owners.
“If monitoring software has been installed on a mobile phone, there are two ways in which the user may realise that the phone is being monitored,” private investigator Nikos Pelekasis told TA NEA.
The first involves examining the itemised bill issued by the mobile network provider and looking for possible duplicate charges.
“The monitoring software alerts the person carrying out the surveillance whenever the ‘target’ receives a call, allowing them to choose whether they want to record it. However, this process results in a message being charged to the monitored phone. Similarly, if the target sends an SMS and the person monitoring the device also wants to receive it, the message may be charged twice,” Nikos Pelekasis explained.
How Your Mobile Phone Can Be Monitored
A second indication that could raise suspicion that a phone is being monitored is unusually rapid battery drain.
According to the article, monitoring software available at the time could allow the person conducting the surveillance to remotely activate a phone and even use it as a microphone without the knowledge of the owner, who might believe that the device was switched off.
Officers from the Cyber Crime Division reportedly took detailed notes as the 33-year-old administrator of the “drin drin” website explained the system, describing situations that appeared more reminiscent of a Hollywood spy film than everyday life.
“And yet, this is a reality experienced unknowingly by thousands of Greek citizens who have no protection,” a senior Hellenic Police officer told TA NEA at the time.
According to the report, one of the applications uncovered during the investigation could even activate the phone’s camera and transmit visual material directly to the person conducting the surveillance.
Such activity could increase power consumption, meaning that reduced battery life might provide an initial indication that something unusual was happening.
The article also reported that, during certain sensitive meetings at major companies and government organisations, participants were asked to remove their phone batteries and completely disable their devices. Senior police officers quoted in the report claimed that, under certain circumstances, a compromised phone could potentially be used for monitoring and recording even when it appeared to be switched off.
Files seized from the company’s premises reportedly contained the names of approximately 2,500 individuals who had been monitored.
“This number only concerns individuals monitored on behalf of certain companies that had requested invoices because they needed to account for the expenditure in their budgets. We estimate that the actual number of people under surveillance exceeded 10,000,” Cyber Crime Division officers were quoted as saying.
Spyware Delivered to the Target’s Device
Among the clients of the “drin drin” operation, according to the article, were major publicly listed companies operating in sectors including commerce, transportation and financial services.
“Many companies provided their employees with free mobile phones but wanted to know what they were doing, where they were going, whom they were meeting and what they were saying. Many business partners also requested the same software. For this reason, they asked for the monitoring software to be installed,” the 33-year-old defendant reportedly told police.
The client base also included individuals who simply wanted to monitor their partners because they had doubts about their activities.
In such cases, according to the report, a spouse or partner would visit the 33-year-old’s office and ask him to install the software on a brand-new smartphone. The phone would then allegedly be repackaged so that it could be presented to the intended recipient as a new gift.
The 33-year-old reportedly told investigators that he had also received requests involving parents wishing to monitor the activities and communications of their minor children, families seeking a means of locating elderly relatives with health problems, and individuals seeking information for their own personal use.
The article described another method used at the time in which monitoring software could allegedly be delivered through an SMS containing the malicious code.
“It could appear to be an ordinary message, but it had been specially created by the 33-year-old to install the software. As soon as the target opened it, the monitoring began,” a Cyber Crime Division officer told TA NEA.
Another method described in the article involved transferring the software through Bluetooth, reportedly used particularly in cases involving relatives.
Once installed, the software could, according to the report, record calls, SMS and MMS messages, emails and files exchanged by the monitored user, depending on the configuration selected by the person conducting the surveillance.
The report also stated that the software could activate location services and continuously provide information about the target’s location. The person carrying out the monitoring could then select which information they wanted to record on their computer.
The Husband, the Wife and the Thieves
According to the article, the monitoring software used by the 33-year-old and reportedly by a number of private investigation companies could circumvent safeguards intended to protect citizens from unlawful interception.
Under the legal framework described by officials from the Ministry of Citizen Protection at the time, lawful telephone interception of a suspect required prosecutorial authorisation and the involvement of the competent authorities.
The software described in the investigation operated differently because the surveillance allegedly occurred through the compromised device itself rather than through the telecommunications provider.
“The software is installed on the specific device. This means that if the ‘target’ removes the SIM card from that phone and inserts it into another mobile phone, the monitoring stops,” a private investigator told TA NEA.
The software, however, could remain installed on the original device.
The article recounts a case in which this produced an unexpected result following a jewellery theft from a family home in the southern suburbs of Athens.
The husband, who had reportedly suspected his wife of going out at night, had installed monitoring software on her mobile phone. During the burglary, the thief noticed the new smartphone and decided to steal it.
When the thief inserted his own SIM card into the device, the monitoring software was reportedly activated. The husband subsequently went to the police, explained how he had identified the thief, while his wife was apparently left impressed by how quickly the Hellenic Police had managed to locate the person who had stolen her jewellery.
Revealing a Hidden Caller ID
One of the innovations attributed to the 33-year-old that reportedly impressed investigators was software he had developed himself, which allegedly allowed him to reveal within 18 seconds the telephone number of a caller whose number appeared as hidden or withheld.
Originally published in the Greek newspaper TA NEA
Article by Stelios Vradelis
About This Publication
This is an English translation of an earlier Greek-language publication and reflects the technologies, claims, investigative practices and legal circumstances described at the time of the original article.
Mobile operating systems, smartphone security, spyware capabilities, telecommunications infrastructure and the applicable legal framework have changed significantly since the article was originally published. Consequently, some of the technical methods, indicators or practices described in the original publication may no longer apply to modern smartphones or may operate differently today.
The current services provided by Nikos Pelekasis & Associates are conducted in accordance with the applicable legal and regulatory framework concerning private investigations, communications privacy, cybersecurity and personal data protection.




