EU Spyware Investigator's Phone Hacked by Pegasus Twice, Raising Alarm on Democratic Resilience

The October 2022 and March 2023 Pegasus infections occurred during high-intensity PEGA Committee work, including travel to Greece, Cyprus and Spain for preparatory investigations and then finalizing the committee's report.
TechCrunch reports that the attacker used the same Pegasus-related email address as in a prior campaign targeting journalists across Europe, suggesting a recurring NSO Group customer authorized to deploy Pegasus across multiple European countries.
The investigators stop short of attributing the hacking to a specific government, but note overlaps with a Pegasus campaign that targeted exiled Russian- and Belarusian-speaking journalists and activists in Europe, implying a broader, cross-country operator.
A serving European lawmaker described the hacking as a direct attack on the rule of law and urged the European Commission to implement stronger limits on spyware across the EU.
Pegasus can access a broad range of data on infected devices beyond emails and messages, including microphones and cameras, highlighting the extensive potential breach of privacy and parliamentary communications.
Stelios Kouloglou, a Greek journalist and former member of the European Parliament, was infected with Pegasus spyware twice while sitting on the very EU committee formed to investigate that same spyware, according to new findings from Citizen Lab. The infections happened in October 2022 and March 2023 — both during critical moments of the committee's work.
Politico described it as the first publicly documented case of an active PEGA committee member being targeted with Pegasus. The committee, known as PEGA, was created specifically to probe illegal spyware use across Europe. The revelation has rattled EU lawmakers and rights groups alike.
The first infection hit in October 2022, when the PEGA committee was conducting field investigations. Kouloglou traveled to Greece, Cyprus, and Spain for preparatory hearings around that time. The second infection came in March 2023, just as the committee was finalizing its official report on spyware abuse in Europe, according to Daily Beirut.
Pegasus is powerful spyware. Once on a phone, it can read emails and private messages. It can also silently activate the microphone and camera. That means Kouloglou's confidential parliamentary communications — and possibly the committee's deliberations — may have been exposed to whoever deployed the attack.
Investigators found a key clue: the attacker used the same Pegasus-linked email address as in an earlier campaign. That earlier campaign targeted exiled Russian- and Belarusian-speaking journalists and activists living in Europe, according to TechBuzz. This points to a single NSO Group customer operating across multiple European countries.
Researchers stopped short of blaming a specific government. But the overlapping pattern is hard to ignore. NSO Group sells Pegasus only to vetted government clients. That means a state actor authorized to deploy Pegasus across Europe likely carried out the attack.
A serving European lawmaker said the hacking was "a direct attack on the rule of law" and called on the European Commission to impose stronger limits on spyware use across the EU, according to Head Topics. Rights groups echoed that demand, saying the breach undermines democratic oversight.
Kouloglou himself said the hack likely gave attackers access to his private emails, messages, and possibly the committee's internal deliberations. He described the incident as a warning about how exposed European institutions are to surveillance tools they are still struggling to regulate.
The PEGA committee was set up after Pegasus was found on the phones of multiple European politicians and journalists, including allies of Spanish Prime Minister Pedro Sánchez. It published its final report in 2023, urging a moratorium on spyware sales. Now it emerges that the committee's own work was being watched, according to Zamin.
The case makes the core problem concrete: the EU is trying to investigate and regulate a tool that can be turned on the investigators themselves. Until binding rules are in place, experts warn, no phone used by a European official can be considered truly secure.
Publishers
36
Articles
39
Reach
75