Threats

Pegasus Spyware Targets European Parliament Member

July 4, 2026 00:03 · 12 min read
Pegasus Spyware Targets European Parliament Member

A phone belonging to a former member of the European Parliament, Stelios Kouloglou, was targeted and infected with Pegasus spyware multiple times during his tenure on the parliamentary committee probing the technology’s misuse.

Pegasus Spyware Infections

According to a report released by digital forensic researchers at the Citizen Lab, Kouloglou’s phone was infected with Pegasus, a powerful zero-click spyware, in October 2022 and again in March 2023. At the time of the infections, the PEGA Committee, which included Kouloglou, was conducting sensitive work relating to its planned recommendations for tackling rampant abuse of commercial spyware in Europe.

Committee's Recommendations Ignored

The PEGA Committee released its recommendations in May 2023, but the European Commission has largely ignored them. Citizen Lab researcher John Scott-Railton, along with dozens of politicians and experts, have called this inaction “inexcusable.” Scott-Railton warned that the lack of action will lead to more hacked members of parliament, stating, “I know what the next chapter of this story is — it's going to be more hacked members of parliament, and I would bet that there are members of the European Parliament today walking around with no idea that their phone in their pocket has been turned into a spy.”

Kouloglou, also a longtime investigative reporter, believes the Greek government is responsible for the hacks, although the Citizen Lab said it has no indications that this is true. Greece has long been embroiled in a spyware scandal, but the technology used in those hacks was manufactured by Intellexa and not the NSO Group, the company behind Pegasus.

Link to Other Incidents

The Citizen Lab believes the same Pegasus customer is responsible for both the 2022 Kouloglou incident and a series of spyware infections that the organization revealed in a May 2024 report. The latter incidents were attacks on devices belonging to seven Russian and Belarusian-speaking journalists and opposition figures between August 2020 and January 2023. The same email used against Kouloglou was deployed in the Belarusian and Russian attacks during the same time frame, indicating that the government behind the Kouloglou hack is almost definitely responsible for the Belarusian and Russian hacks.

Threat to Democracy

While phones belonging to members of the European Parliament have been infected with spyware in the past, the fact that this hack impacted a member of the committee investigating Pegasus underscores how spyware is a threat to democracy. Hannah Neumann, a representative of the Green Party from Germany and negotiator on the PEGA Committee, stated, “It shows a total disregard for Parliamentarians’ role to scrutinize and, as such, for European democracy.” Neumann has been frustrated by the Commission’s inaction on spyware and fears that even this episode won’t lead to an implementation of her committee’s proposed reforms.

Kouloglou plans to sue NSO, the company behind Pegasus, citing the significant invasion of his privacy. He noted that his phone contained 15 years of personal data, including photos, messages, and communications with prime ministers, political party leaders, and journalists.

The incident highlights the need for urgent action to address the misuse of commercial spyware and protect the privacy and security of individuals, particularly those in positions of power and influence.

“It's totally absurd that nothing's being done, but still there is this fake notion of spyware contributing to security, when in fact it undermines security,” Neumann said.

Source: The Record

Source: The Record

Powered by ZeroBot

Protect your website from bots, scrapers, and automated threats.

Try ZeroBot Free