Spyware Investigator Targeted in Pegasus Phone Hack
Published:
A former Member of the European Parliament who helped investigate spyware abuse in Europe was himself repeatedly targeted with Pegasus, according to new findings from Citizen Lab, the digital rights research group at the University of Toronto.
Stelios Kouloglou, a Greek journalist and former MEP, served on the European Parliament’s PEGA committee, which was created to examine the use of Pegasus and similar surveillance tools across Europe. Researchers found that his iPhone was infected during key moments in the committee’s work.
Pegasus is powerful spyware made by the Israel-based NSO Group and sold to governments for investigations into serious crime and terrorism. Once installed, it can give attackers access to highly sensitive information on a phone, potentially including messages, calls, photos, location data, microphone activity and camera access.
Hacked During Sensitive Committee Work
Citizen Lab said Kouloglou’s device was infected on October 21, 2022, and again on March 6 and 7, 2023. Both periods overlapped with intense PEGA committee activity, including report drafting, hearings and discussions about spyware abuse in Europe.
The first compromise happened shortly before a PEGA delegation visit to Cyprus and Greece, which Kouloglou helped organize and attended. It also occurred while committee members and staff were discussing early findings, much of it through digital communications.
Privacy Risks Beyond Politics
At the time of the October infection, Kouloglou was in hospital for elective surgery. Citizen Lab noted that this raised additional privacy concerns, because spyware on his phone could potentially have exposed confidential medical information as well as political communications.
The March 2023 infections happened as Kouloglou travelled between Athens and Brussels and as the committee was working on the final version of its report. Apple later sent him several threat notifications, although he reportedly did not recall seeing them.
Who Was Behind It?
Citizen Lab did not identify which government customer used Pegasus against Kouloglou. The researchers also said they found no evidence that the Greek government was responsible, and no indication that Greece has ever been an NSO Group customer.
However, the investigation found links to another Pegasus campaign that targeted Russian and Belarusian-speaking journalists and opposition figures living in Europe. Researchers identified a shared technical marker, suggesting the same spyware operator may have been involved in both sets of attacks.
The case is significant because Kouloglou is believed to be the first member of the PEGA committee publicly identified as having been infected with Pegasus while actively serving on the inquiry into spyware abuse.
Other European politicians have previously been linked to spyware targeting, including Catalan MEPs and Greek political figures. But this case stands out because the victim was directly involved in investigating the very type of surveillance tool used against him.
For ordinary phone users, the case is a reminder that spyware is not only a problem for dissidents or political insiders. While Pegasus is highly specialized and usually aimed at high-value targets, the broader spyware industry shows how personal devices can become gateways into private lives, work conversations and sensitive records.