In a revelation that highlights the brazen nature of the global mercenary spyware industry, a new forensic analysis has confirmed that Stelios Kouloglou, a prominent Greek politician and former investigative journalist, was targeted with the notorious Pegasus spyware while serving as a member of the European Parliament’s committee dedicated to investigating that very technology. The discovery, documented by the University of Toronto’s Citizen Lab, underscores a profound breach of democratic oversight, as Kouloglou was actively probing the misuse of intrusive surveillance tools against European citizens, law enforcement officials, and business leaders at the time his own device was compromised.

The forensic report indicates that Kouloglou’s iPhone was infected multiple times between late 2022 and early 2023. This timeframe is particularly significant because it coincides with the peak of the European Parliament’s PEGA Committee activities—a special body established to investigate the proliferation of Pegasus and other equivalent spyware variants across the European Union. The irony of the situation has sent shockwaves through Brussels, marking the first confirmed instance of a PEGA Committee member being successfully targeted by the spyware they were tasked with regulating during their active tenure.

The PEGA Committee and the Context of the Hack

The PEGA Committee was established in early 2022 following the explosive revelations of the Pegasus Project, a cross-border investigative journalism initiative that exposed how the NSO Group’s software was being used by governments worldwide to monitor dissidents, journalists, and political rivals. As an MEP from 2015 to 2024, Stelios Kouloglou brought his background as an investigative journalist to the committee, traveling across Europe to interview victims and analyze the legal loopholes that allowed the spyware industry to flourish.

During the summer and fall of 2022, the committee focused heavily on high-profile cases in Greece, Poland, Hungary, and Spain. In Greece, the political landscape was already reeling from a domestic surveillance scandal often referred to as "Greece’s Watergate," involving the use of a different spyware known as Predator, developed by the firm Intellexa. Kouloglou’s role involved scrutinizing how these tools bypassed national security safeguards and infringed upon the fundamental rights of EU citizens.

The fact that Kouloglou was under surveillance while performing these duties suggests a deliberate attempt to gain insight into the committee’s internal deliberations, witness lists, and sensitive findings. "I was not expecting that," Kouloglou remarked in a recent interview, expressing a mixture of shock and indignation. "Me being a member of the Pegasus Committee investigating Pegasus and at the same time being hacked by Pegasus… it was something really too reckless."

A Chronology of Surveillance

The timeline of the attacks on Kouloglou’s device suggests a calculated effort to monitor his activities during critical junctures of the parliamentary investigation. According to Citizen Lab’s forensic analysis, the first confirmed infection occurred on October 21, 2022. At the time, Kouloglou was in the hospital recovering from elective surgery. During his recovery, he was visited by Thanasis Koukakis, a Greek investigative journalist who had previously been identified as a victim of the Predator spyware.

The timing of this initial breach was critical. Only a week later, the PEGA Committee held several high-stakes hearings regarding the impact of spyware on human rights. Shortly thereafter, the committee members, including Kouloglou, embarked on official fact-finding missions to Cyprus and Greece. The surveillance provided the perpetrators with a "front-row seat" to the investigator’s private conversations and preparations for these missions.

The second wave of infections took place on March 6 and 7, 2023. This period was equally sensitive, as the PEGA Committee was in the final stages of drafting its comprehensive report and negotiating the recommendations that would be presented to the European Parliament. Hannah Neumann, a Green MEP who served alongside Kouloglou, noted that the committee was questioning spyware companies and finalizing their findings during this window. "Looking at the dates, it’s pretty obvious that somebody was not just randomly spying on him, but really targeted the committee’s work," Neumann stated.

Further forensic evidence revealed that Apple sent Kouloglou notifications in March 2023, August 2023, and April 2024, warning him that he was likely being targeted by state-sponsored attackers. However, like many high-profile targets, Kouloglou did not immediately see or realize the gravity of these alerts amidst the high volume of digital communications typical of a parliamentarian’s life.

Technical Capabilities of Pegasus Spyware

The software used to target Kouloglou, Pegasus, is widely considered the most sophisticated mercenary spyware in the world. Developed by the Israeli firm NSO Group, it is designed to be "zero-click," meaning it can infect a device without the user needing to click a link or download a file. Once installed, Pegasus grants the operator near-total control over the smartphone.

The capabilities of the software include:

  • Microphone and Camera Activation: Operators can remotely turn on the device’s microphone and camera to record ambient sounds or take photos without the user’s knowledge.
  • Data Extraction: The spyware can bypass encryption on apps like WhatsApp, Signal, and Telegram by capturing messages as they are read or typed on the screen.
  • Location Tracking: Real-time GPS data allows for the constant monitoring of the target’s movements.
  • Access to Personal Media: Photos, videos, contact lists, and web browsing history are all accessible to the attacker.

Citizen Lab’s report did not definitively attribute the attack to a specific government. However, researchers noted a technical overlap between the infrastructure used to hack Kouloglou and the infrastructure used to target seven Russian- and Belarusian-speaking journalists and activists between 2020 and 2023. While the report found no direct evidence linking the Greek government to this specific Pegasus attack, the lack of transparency in the spyware trade makes definitive attribution difficult without state-level cooperation.

Official Responses and Political Fallout

The revelation has prompted a fierce response from members of the European Parliament. Saskia Bricmont, a member of the PEGA Committee, characterized the hack as a direct assault on the rule of law. "The use of spyware not only violates the fundamental rights of the individuals concerned, but in this case also threatens the security and integrity of parliamentary work," Bricmont said.

The European Parliament’s official spokesperson stated that the institution has implemented a "spyware screening system" available to all MEPs and has recently adopted measures to expand technical protections. However, critics argue that these measures are insufficient given the "zero-day" vulnerabilities that Pegasus exploits.

NSO Group, which has faced multiple lawsuits and was blacklisted by the U.S. Department of Commerce in 2021, did not provide a specific comment on the Kouloglou case. The company has historically maintained that its products are sold only to vetted government agencies for the purpose of fighting terrorism and serious crime. However, the recurring evidence of its use against politicians and journalists in democratic nations continues to undermine these claims. In a shift of corporate structure, a majority stake in NSO Group was acquired by U.S.-based investors in 2025, a move seen by some as an attempt to rehabilitate the firm’s reputation.

Broader Implications for Democracy and Security

The targeting of Stelios Kouloglou serves as a stark reminder of the "open season" currently existing on European lawmakers. John Scott-Railton, a senior researcher at Citizen Lab, warned that neither national parliaments nor the European Parliament are currently prepared for the scale of the threat. "Europe has a mountain of spyware abuses, and nothing has happened—it’s an embarrassment for European institutions," Scott-Railton said.

The incident highlights several critical concerns for the future of democratic governance:

  1. Integrity of Investigations: When those tasked with investigating corruption or security breaches are themselves under surveillance, the integrity of the entire oversight process is compromised.
  2. Confidentiality and Privacy: MEPs handle sensitive information involving constituents, whistleblowers, and national security. A breach of their devices exposes third parties who may be at risk.
  3. The Role of AI: Experts warn that the integration of artificial intelligence could further lower the barriers to entry for mercenary spyware, allowing for automated, large-scale surveillance at a fraction of current costs.
  4. Legislative Inaction: Despite the PEGA Committee’s exhaustive 2023 report, many of its core recommendations—including the creation of a centralized EU forensic lab and a dedicated task force for election security—have yet to be fully implemented.

As the European Union moves forward, the case of Stelios Kouloglou will likely become a rallying cry for those demanding stricter regulations on the export and use of surveillance technology. For Kouloglou, the experience has transformed a professional investigation into a deeply personal quest for justice. "It’s not a matter only about privacy," he concluded. "It’s also a matter about justice, democracy, and the corruption fight."

The failure of European institutions to protect their own members from clandestine digital intrusion remains a glaring vulnerability. Without a coordinated, trans-border response that includes legal sanctions and robust technical defenses, the mercenary spyware industry will likely continue to operate with the same recklessness that allowed it to target the very person tasked with bringing its abuses to light.

By