Pegasus Spyware Infects Phone of EU Spyware Investigator

Researchers find Pegasus spyware on the phone of a European Parliament member leading the investigation into mercenary spyware abuse.

By Central
Stelios Kouloglou’s phone was infected with Pegasus spyware during critical phases of the EU spyware inquiry.
Highlights
  • The spyware infection targeted an MEP actively investigating mercenary spyware abuse in the European Parliament.
  • Citizen Lab found technical overlaps linking the infection to broader campaigns targeting journalists and activists.
  • Apple sent threat notifications to Kouloglou, but he did not recall seeing them at the time.

The Pegasus spyware infected the phone of Stelios Kouloglou, a Greek Member of the European Parliament who served on the committee investigating spyware abuse, in what researchers describe as a direct attack on the oversight process itself. The findings, released by the University of Toronto’s Citizen Lab, reveal that Kouloglou’s device was compromised on at least two separate occasions in 2022 and 2023, periods that coincided with critical phases of the European Parliament’s PEGA Committee inquiry into mercenary spyware.

Spyware Targeted the Investigator, Not Just the Politician

Citizen Lab’s forensic analysis determined that Kouloglou’s phone was first infected with Pegasus on October 21, 2022, while he was recovering from elective surgery in a hospital. On that day, he received a visit from Greek investigative journalist Thanasis Koukakis, who had previously been targeted with Predator spyware. The following week, the PEGA Committee held key hearings on the human rights impact of surveillance technology.

A second infection occurred on March 6 and 7, 2023, as the committee was finalizing its report and negotiating recommendations. The timing strongly suggests the attackers aimed not merely at a politician, but at the investigative work of the committee itself. “They did not only target an MEP, they spied on the investigation into spyware abuse itself,” said Hannah Neumann, a Green MEP who served on the committee.

Pegasus Infections Linked to Broader Campaigns

Citizen Lab stopped short of attributing the attacks to any specific government, noting specifically that it found no evidence of Greek government involvement. However, researchers identified technical overlaps between the compromise of Kouloglou’s device and the targeting of seven Russian- and Belarusian-speaking journalists and activists between August 2020 and January 2023, suggesting a coordinated campaign infrastructure.

The infections occurred despite Apple sending threat notifications to Kouloglou in March 2023, August 2023, and April 2024. These alerts, which are not issued in real time, warned that his device was likely being targeted with mercenary spyware. Kouloglou told WIRED he does not recall seeing the notifications.

Why This Attack Signals a Deeper Problem

The targeting of a sitting MEP actively investigating spyware abuse underscores the brazenness of the commercial surveillance industry and the actors who deploy it. Kouloglou expressed anger at the violation, noting that private communications with family, friends, and colleagues had been monitored. “It’s not a matter only about privacy, it’s also a matter about justice, democracy and the corruption fight,” he said.

Citizen Lab researcher John Scott-Railton described Europe’s response to the widespread abuse as an embarrassment. “Europe has a mountain of spyware abuses, and nothing has happened,” he said, warning that advancements in artificial intelligence will lower the barriers to deploying mercenary spyware, making the threat even more acute. He contrasted European inaction with progress in the United States, which has used sanctions, visa bans, and executive orders to curb spyware proliferation.

European Parliament Response and Lingering Gaps

The European Parliament declined to comment directly on the findings but pointed to a “spyware screening system” available to all MEPs and noted recently adopted measures to expand protections. However, Kouloglou and other lawmakers remain concerned that other committee members may have also been compromised.

Key recommendations from the PEGA Committee, including the creation of an EU-based forensic analysis lab and a dedicated spyware taskforce for elections, have not been implemented years after the committee completed its report. “There is no lack of awareness of the problems that come with mercenary spyware,” Neumann said. “There is no lack of recommendations on how to fix it. It’s just a matter of, can you please now do it?”

What Affected Individuals Should Do Now

For anyone concerned about the risk of mercenary spyware, the first step is to enable lockdown mode on your smartphone, a feature available on modern iOS and Android devices that significantly reduces the attack surface against zero-click exploits. Ensure automatic updates are active for both your operating system and all applications. If you receive a threat notification from Apple or Google, take it seriously—contact your organization’s security team or a digital security helpline immediately. For journalists, activists, and public figures operating in high-risk environments, consider using a reputable no-log VPN service when connecting to public Wi-Fi networks to reduce the risk of network-based surveillance. Regularly review your device for unusual behavior, such as unexpected reboots, battery drain, or suspicious activity in your messaging apps.

Share This Article