EU Spyware Investigator Hacked by Pegasus Spyware

European Parliament Investigator Targeted by Pegasus Spyware

In a shocking revelation, the University of Toronto’s Citizen Lab has reported that a member of the European Parliament’s PEGA Committee—tasked with investigating the use of Pegasus spyware—was himself infected with the very same malware. Greek politician Stelios Kouloglou, a former MEP (2015–2024) and investigative journalist, had his iPhone hacked multiple times in 2022 and 2023 while actively probing spyware abuses.

The Timeline of Infection

First Compromise: October 21, 2022

According to Citizen Lab’s forensic analysis, Kouloglou’s phone was first infected with Pegasus on October 21, 2022, while he was recovering from elective surgery in a hospital. During this time, he was visited by Greek investigative journalist Thanasis Koukakis, who had previously been targeted by spyware himself. The following week, the PEGA Committee held key hearings on spyware’s impact on human rights.

Second Infection: March 2023

Kouloglou’s device was compromised again on March 6 and 7, 2023. At that time, the committee was finalizing negotiations on its findings and questioning spyware industry companies. Hannah Neumann, a Green MEP who served on the committee, noted that the timing suggests intentional targeting of the committee’s work.

Political and Security Implications

MEP Saskia Bricmont called the targeting ‘a direct attack on the rule of law.’ Citizen Lab’s John Scott-Railton stated, ‘It’s open spyware season on Europe’s lawmakers.’ The researchers stop short of naming a specific government but note overlaps with Pegasus use against Greek journalists from August 2020 to January 2023. They found no indication of Greek government involvement.

Kouloglou expressed shock and anger, saying, ‘Me being a member of the Pegasus Committee investigating Pegasus and at the same time being hacked by Pegasus… it was something really too reckless.’ He emphasized concerns about privacy, democracy, and corruption. The European Parliament has a ‘spyware screening system’ available to all MEPs but did not directly comment on the findings.

NSO Group, the Israeli firm behind Pegasus, did not respond to requests for comment. The revelations come years after the ‘Pegasus Project’ leak exposed at least 180 journalists targeted globally. Scott-Railton warned that little has been done to address spyware abuses, calling it ‘an embarrassment for European institutions’ and noting that AI could worsen the threat by lowering costs.

Leave a Comment