The Irony of Surveillance: European Parliament Investigator Targeted by Pegasus Spyware
8 mins read

The Irony of Surveillance: European Parliament Investigator Targeted by Pegasus Spyware

In a chilling convergence of investigative oversight and digital espionage, forensic analysis has confirmed that Stelios Kouloglou, a prominent Greek politician and former member of the European Parliament, was the target of multiple Pegasus spyware infections. The compromise occurred while Kouloglou was actively serving on the European Parliament’s Committee of Inquiry to investigate the use of Pegasus and equivalent surveillance spyware, known as the PEGA Committee. This revelation, brought to light by researchers at the University of Toronto’s Citizen Lab, marks a disturbing milestone: it is the first documented instance of a sitting member of the PEGA Committee being successfully infiltrated by the very technology they were tasked with scrutinizing.

The Pegasus software, developed by the Israeli firm NSO Group, is a powerful "zero-click" exploit capable of turning a standard smartphone into a comprehensive surveillance tool. Once installed, it grants the operator full access to encrypted messages, real-time location data, private photographs, and even the device’s microphone and camera. The breach of Kouloglou’s iPhone, which occurred over several instances, suggests a calculated effort to undermine the integrity of the European Union’s legislative oversight processes.

A Chronology of Compromise

The timeline of the attacks against Kouloglou aligns with critical junctures in the PEGA Committee’s investigative agenda. According to forensic data provided by Citizen Lab, the first successful infection of Kouloglou’s device occurred on October 21, 2022. At the time, the politician was in a hospital recovering from elective surgery. Coincidentally, he was visited during his recovery by Thanasis Koukakis, a Greek investigative journalist who had himself been a target of the Predator spyware—a separate, equally potent tool utilized in what has been dubbed "Greece’s Watergate."

Following this initial infection, the PEGA Committee intensified its activities, holding a series of high-stakes hearings regarding the intersection of human rights and state-sponsored surveillance. In the weeks following the breach, Kouloglou and his colleagues traveled to Cyprus and Greece to probe local spyware scandals. A second, distinct infection of his device was logged by researchers in March 2023, a period that coincided with the committee’s finalization of its findings and sensitive negotiations regarding the regulation of the spyware industry.

While Apple sent automated notifications to Kouloglou in March 2023, August 2023, and April 2024, warning him that his device had been targeted by state-sponsored attackers, the notifications are often received after the fact. Kouloglou has stated he does not recall seeing these alerts, highlighting the difficulty even high-profile targets face in detecting modern, sophisticated digital intrusions.

The Mechanics and Market of Mercenary Spyware

Pegasus, first identified by Citizen Lab in 2016, represents the pinnacle of "mercenary spyware"—tools sold exclusively to government agencies. The software exploits previously unknown vulnerabilities in mobile operating systems, known as "zero-days," to bypass traditional security protocols. While the NSO Group maintains that it sells its software only to vetted government entities for the purpose of fighting crime and terrorism, the prevalence of the tool in the hands of actors who target political opposition, journalists, and activists has drawn intense global scrutiny.

The industry remains in a state of flux. Despite the notoriety surrounding the NSO Group, the company’s ownership structure shifted in 2025 when a consortium of United States-based investors acquired a majority stake. This change in control has not yet resulted in a significant shift in the company’s operational transparency or its refusal to comment on specific forensic findings. The broader spyware market remains largely unregulated, with numerous companies offering "interception solutions" that operate in a legal gray area, often exploiting the lack of a unified international framework for cyber-arms control.

Parliamentary Integrity Under Siege

The implications of a lawmaker being spied upon while investigating that very spying are profound. The PEGA Committee was established in response to the "Pegasus Project," an international collaborative investigation that exposed the massive scale of surveillance against thousands of individuals globally. By targeting a member of the committee, the perpetrators effectively gained a window into the legislative process, potentially accessing confidential documents, witness communications, and the internal strategy of the European Union’s inquiry.

"They did not only target an MEP; they spied on the investigation into spyware abuse itself," says Hannah Neumann, a Green MEP who served alongside Kouloglou. The sentiment is echoed by fellow committee members who view the intrusion as an existential threat to parliamentary independence. Saskia Bricmont, another member of the committee, stated that the breach constitutes a "direct attack on the rule of law," warning that such tactics discourage whistleblowers and compromise the safety of witnesses willing to testify against powerful state actors.

The Institutional Failure to Respond

Despite the clear evidence of widespread spyware abuse within the European Union, institutional responses have been sluggish. The European Parliament has introduced a "spyware screening system" for members, yet many lawmakers argue that these measures are insufficient against the rapidly evolving capabilities of firms like NSO Group and Intellexa.

Furthermore, the recommendations issued by the PEGA Committee—which included the establishment of a specialized EU-based tech lab for forensic device analysis and a dedicated task force for election security—have remained largely unimplemented. John Scott-Railton, a senior researcher at Citizen Lab, described the situation as "an embarrassment for European institutions." He argues that while the United States has begun to utilize tangible tools like sanctions, visa bans, and executive orders to combat the misuse of mercenary spyware, the European Union has failed to transform its awareness of the problem into concrete policy.

Broader Implications and Future Risks

The breach of Kouloglou’s device is not an isolated incident but part of a wider, systemic pattern. Citizen Lab researchers have observed troubling overlaps between the infrastructure used to target Kouloglou and the digital campaigns waged against Russian- and Belarusian-speaking activists and journalists. This suggests that the same or similar operators are functioning across borders with little fear of reprisal.

The emergence of artificial intelligence (AI) further compounds the danger. Experts warn that AI is poised to lower the barriers to entry for state actors, making the deployment of spyware cheaper, more frequent, and harder to detect. If the current trajectory continues, the "open spyware season on Europe’s lawmakers" predicted by Scott-Railton could become the new normal for democratic governance.

For Kouloglou, the experience has been a sobering lesson in the fragility of modern privacy. "It’s not a matter only about privacy," he notes. "It’s also a matter about justice, democracy, and the corruption fight." As he reflects on his time in the European Parliament, the realization that his personal life—including interactions with family and sensitive political discussions—was under constant surveillance by an unknown entity serves as a stark warning.

The failure to act on the recommendations of the PEGA Committee leaves European officials, journalists, and citizens in a precarious position. Without a unified, assertive strategy to regulate the spyware industry and hold the purveyors of these tools accountable, the fundamental pillars of European democracy remain vulnerable to those who treat the rule of law as an obstacle to be bypassed by a line of malicious code. The case of Stelios Kouloglou serves as a grim indicator that, in the digital age, those who watch the watchers are rarely protected from the shadows themselves.

Leave a Reply

Your email address will not be published. Required fields are marked *