Full story
Pegasus hits PEGA member
Citizen Lab reported that former Member of the European Parliament Stelios Kouloglou was repeatedly infected with NSO Group’s Pegasus spyware while serving on the PEGA committee, which ran from March 2022 to July 2023.
“We found with high confidence that his device was successfully infected with Pegasus spyware on or around October 21, 2022, and again on March 6 and 7, 2023.”
The Citizen Lab report said the first infection happened on October 21, 2022, and again on March 6 and 7, 2023, during periods of intense PEGA activity including drafting of the committee’s first report and final drafting of its report.

Citizen Lab said the first infection involved a zero-click exploit targeting Apple’s HomeKit system, assessing that “the phone was hacked with thePWNYOURHOMEzero-click exploit at this point.”
The Citizen Lab report also said Kouloglou’s device was running iOS 15.5 on both infection dates, and that the attackers could have had access to “confidential documents and committee deliberations.”
Outrage and competing attributions
The Times of Israel said EU lawmakers voiced outrage in Brussels after the Citizen Lab report found Kouloglou’s phone was infected with Pegasus in 2022 and 2023 while he sat as a substitute on the European Parliament committee investigating the spyware’s use.
Belgian Green lawmaker Saskia Bricmont said she was “shocked,” urging the European Commission to “take binding measures to ban the illegal use of spyware in Europe,” while the Left group called for “strong measures” against spyware and Renew said it was “very concerned.”
The Guardian reported that Citizen Lab “could not attribute the attacks against Stelios Kouloglou to any particular government operator of Pegasus spyware,” but said the attack bore hallmarks of a previous hacking campaign against exiled Russian and Belarusian journalists and opposition activists.
In an interview, Kouloglou told The Guardian, “When you realise your private life is scrutinised by very bad people, you become angry,” framing the issue as “a big issue having to do with corruption, justice and democracy.”
What’s at stake next
Citizen Lab said the infections could have exposed “strictly confidential exchanges among PEGA Committee members and their staff,” and other sensitive parliamentary proceedings, including to parties under investigation by the committee itself.
“Whichever entity is responsible for the hacking, the infection could have exposed strictly confidential exchanges among PEGA Committee members and their staff”
The Citizen Lab report said it found no evidence linking the operation to the Greek government, while noting that infections appeared in at least two European jurisdictions, “Greece and Belgium,” and assessing that the customer likely had a license enabling infections across multiple EU jurisdictions.
Al Jazeera quoted Citizen Lab describing the case as highlighting “the serious threat that mercenary spyware poses to the integrity of democratic processes,” and said Kouloglou received Apple threat notifications after the intrusions.
Al Jazeera also reported that Rand Hammoud said the case should concern “everyone who cares about democracy, fundamental rights, and the rule of law in Europe,” and that Hannah Neumann said “Spyware doesn’t make democracies safer,” adding that it “weakens democratic oversight, parliamentary independence and the rule of law.”




