IC Technology & Surveillance — 2026-07-06
Citizen Lab Confirms Pegasus Spyware Infected EU Parliament Member Investigating Spyware Abuse
BLUFConfirmed Pegasus infections of a sitting PEGA Committee member's device mean spyware operators had real-time visibility into the EU body designed to regulate them, functionally neutralizing its oversight capacity.
Citizen Lab found that the iPhone of former Greek MEP Stelios Kouloglou was infected with Pegasus spyware twice, on October 21, 2022 and March 6-7, 2023, both via the zero-click "PWNYOURHOME" exploit delivered through Apple's HomeKit 12. Kouloglou served on the European Parliament's PEGA Committee, formed in 2022 to investigate Pegasus abuse in the EU; the first intrusion hit while he was hospitalized in Athens days before major PEGA hearings on spyware, and the second struck during final drafting of the committee's report while he was in Brussels 2. Apple sent Kouloglou three separate threat notifications, in March 2023, August 2023, and April 2024, months after each intrusion, and Citizen Lab found no evidence implicating the Greek government while linking the likely operator to a campaign that also targeted Russian and Belarusian-speaking opposition figures elsewhere in Europe 2. Citizen Lab said the intrusions could have exposed confidential PEGA Committee communications and Kouloglou's medical information, including to parties under the committee's own investigation 2.
Analysis
Citizen Lab's forensic report, the sole primary source behind multi-outlet pickup, shows spyware operators reached inside the very committee built to constrain them, exposing PEGA deliberations, member sources, and Kouloglou's medical records to parties the panel was investigating. Failure to attribute the intrusions leaves Parliament's oversight mechanism without a target for accountability even as its findings gain credibility, and a detection lag of months between each intrusion and Apple's notification suggests other targeted parliamentarians may remain unaware absent forensic review. A Pegasus client government other than Greece, rather than Athens itself, more plausibly sits behind the operation, monitoring the body probing its own conduct. The disclosure has already prompted PEGA member Hannah Neumann to demand a formal European Parliament investigation into the breaches.
3 sources
- European Parliament Member Investigating Spyware Was Hacked With Pegasus - The Hacker News
- EU lawmaker investigating surveillance hacked by Israeli spyware, report says - Al Jazeera
- Espionage Against the European Parliament: Member of Committee Investigating Spyware Hacked with Pegasus - The Citizen Lab
View in full brief →