European politician investigating spyware hacked with Pegasus

Security researchers confirm that a European politician was infected with Pegasus spyware while investigating surveillance technology misuse.

By Central
The Pegasus infection of a PEGA committee member highlights risks to those probing spyware abuses.
Highlights
  • Stelios Kouloglou's phone was hacked with Pegasus while he served on a European Parliament committee investigating spyware use.
  • The zero-click exploit required no target interaction, allowing silent data theft from Kouloglou's iPhone.
  • European lawmakers call for strict limits on spyware after the breach, citing a direct attack on the rule of law.

Security researchers have confirmed that a European politician was infected with the Pegasus spyware while serving on a parliamentary committee tasked with investigating the misuse of surveillance technology, reigniting debate over how governments deploy digital espionage tools against their critics. Analysts at the University of Toronto’s Citizen Lab verified that the phone of Stelios Kouloglou, a Greek journalist and former Member of the European Parliament, was compromised during 2022 and 2023—marking the first time a member of the European Parliament’s PEGA committee has been publicly identified as a victim of the very spyware the body was established to scrutinize.

Kouloglou described the breach as “reckless” and confirmed his intention to sue NSO Group, the Israeli developer of Pegasus. A serving European lawmaker characterized the intrusion as a “direct attack on the rule of law” and called on the European Commission to impose strict limits on spyware use across the 27-member bloc. The repeated targeting of a committee investigator with the exact surveillance tool under investigation suggests an intense effort to monitor the committee’s work ahead of a widely anticipated report detailing systemic spyware abuses.

Citizen Lab’s findings indicate that Kouloglou’s phone was first compromised in October 2022 and again at least twice in March 2023. The infections exploited a zero-click vulnerability in Apple’s iPhone software—a flaw that had been patched but was not yet applied to his device. A zero-click exploit requires no interaction from the target, meaning Kouloglou had no opportunity to prevent the intrusion through caution or awareness.

Timing of the Infections Points to Targeted Surveillance

The October 2022 hack coincided with intense internal discussions and the drafting of an initial report documenting spyware abuses in Cyprus, Greece, Hungary, Poland, and Spain. Notably, the infection occurred while Kouloglou was hospitalized for a scheduled surgery, raising the possibility that operators used the device’s microphone to capture ambient audio, including conversations with medical staff and visitors. The March 2023 infections occurred on March 6 and 7 as Kouloglou traveled from Athens to Brussels for committee hearings, weeks before the committee finalized its written report.

Citizen Lab researchers did not attribute the attack to a specific nation but noted that the Pegasus operator reused the same email address employed in a previous campaign targeting journalists across Europe. The reuse of this infrastructure implies that the customer had NSO Group’s authorization to operate Pegasus across multiple European jurisdictions.

What Data Was Stolen and How the Exploit Worked

The attack chain leveraged a previously discovered vulnerability in Apple’s smart home software, which permitted the spyware to extract private data without the victim’s knowledge. Compromised information included text messages, correspondence, location history, and photographs. The zero-click nature of the exploit means that no malicious link or attachment was required—the attacker gained full access silently.

Kouloglou described learning of the breach as deeply personal, noting that the stolen data included not only professional exchanges with ministers and officials but also private moments. “You realize that all of your personal data was taken—not all the professional exchanges or messages with ministers—but also the very private things, like the happy moments and the sad moments,” he said.

Broader Implications for Spyware Governance

This incident underscores a persistent pattern in which governments acquire spyware under the stated purpose of combating serious crime, only to deploy it against journalists, lawmakers, and political critics. NSO Group remains largely barred from use by U.S. government agencies following a Biden-era executive order targeting spyware that facilitates human rights abuses. An unnamed American investment group recently funneled tens of millions of dollars into the company, a move widely interpreted as part of an effort to rehabilitate NSO’s brand ahead of a potential push into the U.S. market.

The European Commission has not responded to requests for comment on the findings, and NSO Group did not address the Citizen Lab report prior to publication. Kouloglou stated he was going public “for democracy, human rights, and the fight against corruption.”

What Affected Users and Organizations Should Do Now

Individuals who suspect their devices may be under surveillance should immediately install all pending operating system and security updates, as unpatched vulnerabilities remain the primary vector for spyware infections. Enabling Lockdown Mode on Apple devices provides an additional layer of protection against zero-click exploits by severely restricting device functionality. Organizations conducting sensitive investigative or oversight work should implement device segregation policies, use end-to-end encrypted communication platforms, and deploy mobile threat detection software capable of identifying indicators of compromise consistent with commercial spyware. For any user concerned about privacy, adopting a reputable no-log VPN service on public and untrusted networks adds a critical layer of traffic protection, though it cannot prevent device-level exploits. The most effective defense remains keeping software current and treating any device that handles sensitive information as a potential target for state-sponsored surveillance.

Share This Article