Politician Investigating Spyware Abuses Was Hacked by Pegasus
A European politician investigating spyware abuses has had his phone hacked with Pegasus spyware, reigniting controversy over government surveillance and raising concerns about attacks on the rule of law. Stelios Kouloglou, a member of the EU Parliament's PEGA committee, plans to sue NSO Group, the maker of Pegasus, for what he calls a "reckless" attack.
A
··2 min readAgent
Newsroom

Security researchers have confirmed a startling development: a European politician, actively serving on an investigatory committee probing abuses of the notorious Pegasus spyware, had his own phone hacked by the very surveillance tool he was examining. This revelation has reignited intense controversy over governments' misuse of spyware to gather intelligence on critics, journalists, and now, even their own lawmakers.
The Citizen Lab, a digital rights unit at the University of Toronto, identified the victim as Stelios Kouloglou, a Greek journalist and former politician. Kouloglou, a member of the European Parliament's PEGA committee—specifically tasked with investigating phone spyware attacks by European governments—was targeted during 2022 and 2023. This marks the first public identification of a PEGA committee member as a spyware victim, a fact that one serving European lawmaker described as a "direct attack on the rule of law," urging the European Commission to impose strict limits on spyware use across the 27-member bloc.
While attacks on lawmakers are rare, the timing and precision of targeting a committee investigator with the very spyware under his scrutiny raise serious questions. It suggests a focused effort to monitor the committee's internal operations ahead of its highly anticipated report detailing findings on spyware abuses. Citizen Lab's researchers, while not attributing the hack to a specific country, noted that the government customer used the same Pegasus-loaded email address linked to previous campaigns against journalists across Europe, implying NSO Group's authorization for cross-border snooping.
The report detailed that Kouloglou's phone was compromised in October 2022 and again at least twice in March 2023. The attacks exploited a "zero-click" vulnerability in Apple's iPhone software, meaning the spyware infiltrated his device and exfiltrated private data—including text messages, location data, and photos—without any interaction from him. The October 2022 hack coincided with intense committee discussions regarding a draft report on spyware abuses in Cyprus, Greece, Hungary, Poland, and Spain. Intriguingly, this period also found Kouloglou in the hospital for a scheduled surgery, potentially allowing operators to eavesdrop on sensitive conversations.
The subsequent hacks in March 2023 occurred as Kouloglou traveled from Athens to Brussels, amidst committee hearings and months before the finalization of their written report. Expressing his anger, Kouloglou told TechCrunch that the breach exposed not only professional exchanges but also deeply personal moments. He believes he was targeted due to his work on the PEGA committee and plans to sue NSO Group, the Israeli spyware maker, stating his actions are "for democracy, human rights, and the fight against corruption." This legal challenge comes as NSO Group faces ongoing scrutiny, including a US ban and efforts to rehabilitate its brand after being linked to human rights abuses.




