Pegasus Spyware Used to Hack EU Lawmaker Investigating Spyware Abuse
MEP Leading Spyware Probe Targeted by Pegasus Hack
New research from the Citizen Lab shows that Stelios Kouloglou, a former Member of the European Parliament, had his phone repeatedly compromised with Pegasus spyware — while he was sitting on the very committee set up to investigate abuses of tools like it.
Citizen Lab investigators John Scott-Railton, Bill Marczak, Bahr Abdul Razzak, Kate Pundyk, Siena Anstis, and Ron Deibert examined Kouloglou's device and concluded that whoever carried out the intrusion may have gained access to sensitive committee materials and internal discussions.
No government has been formally tied to the attacks so far, and Citizen Lab found nothing pointing to Greek state involvement. What the researchers did find was a technical link between the earlier of the two intrusions and a prior operation aimed at Russian- and Belarusian-speaking journalists and activists living in exile across Europe. That overlap suggests the operator behind the hack held a Pegasus license permitting surveillance across several European countries — which narrows, but doesn't pin down, who might be responsible.
A watchdog on the committee, watched himself
Kouloglou served on Parliament's Committee of Inquiry into the use of Pegasus and comparable spyware (known as PEGA) from March 2022 through July 2023. The committee itself was launched in March 2022 to examine how EU member states — and others — were deploying commercial spyware, and whether that use violated Europeans' fundamental rights.
According to Citizen Lab's forensic review of an iPhone backup collected in May 2026, Kouloglou's device was infected with Pegasus on or around October 21, 2022, and hit again on March 6–7, 2023. The researchers traced the first breach to a lookup of a HomeKit-linked email address, followed within minutes by Pegasus activity on the device's mobile connection — consistent with PWNYOURHOME, a zero-click exploit targeting Apple's smart-home software that Apple patched in iOS 16.3.1. The March 2023 intrusion is believed to have used the same exploit chain. In both cases, Kouloglou's phone was still running iOS 15.5, the version vulnerable to the attack.
Apple separately warned Kouloglou three times that he'd been targeted by mercenary spyware — in March and August 2023, and again in April 2024.
Timing that raises eyebrows
The first breach happened while Kouloglou was hospitalized for a scheduled surgery, during which he was visited by Greek investigative journalist Thanasis Koukakis. Koukakis had his own phone hacked with Intellexa's Predator spyware and had appeared before the PEGA Committee to testify about it just a month earlier.
The second infection, in March 2023, landed as the committee was deep in negotiations over its final report and holding a string of hearings — roughly two months before that report was formally adopted.
This is the first known case of a sitting PEGA Committee member being confirmed as a Pegasus target during their tenure.
Tracing the operator
Citizen Lab linked the October 2022 attack to the campaign against Russian and Belarusian exile journalists through a shared piece of infrastructure: an email address associated with the intrusion. Researchers noted that, based on how Pegasus infection infrastructure was typically structured at the time, addresses like this one tend to be tied to a single specific operator — though they couldn't confirm whether the March 2023 breach came from that same operator or a different one. Either way, the pattern points to an NSO Group customer whose license covers multiple EU jurisdictions, which helps narrow the pool of likely suspects.
The case adds to mounting evidence that spyware marketed for fighting terrorism and serious crime keeps turning up in operations against journalists, politicians, and government critics instead.
Part of a broader patterns
This report follows closely on the heels of another Citizen Lab finding: Russian authorities reportedly used Cellebrite's UFED forensic extraction tools to unlock the iPhone of jailed opposition figure Andrey Pivovarov in June 2021 — three months after Cellebrite publicly said it would cut off Russia and Belarus. Investigators reportedly searched Pivovarov's phone for connections to figures like Open Russia founder Mikhail Khodorkovsky and human rights lawyer Anastasiya Burakova. Several of the people named in that search, Burakova included, later became targets of a phishing campaign run by the Russia-linked hacking group COLDRIVER, suggesting the earlier device search may have fed into follow-on surveillance of Kremlin opponents abroad.
Citizen Lab also disclosed in April a pair of ongoing surveillance operations exploiting long-standing weaknesses in global telecom networks to track people's physical locations — without ever needing to install malware on a target's phone, making the activity especially hard to spot. One method used specially crafted text messages carrying hidden commands to turn a handset into a tracking device; the other exploited flaws in the SS7 and Diameter signaling protocols to locate targets remotely. Both campaigns reportedly routed traffic through three telecom providers — 019Mobile, Airtel Jersey (part of the Sure Group), and Tango Networks U.K. — which the report describes as access points that let surveillance traffic blend into legitimate interconnection networks while obscuring who's really behind it.