Allied Intelligence — 2026-07-03

EU Spyware Investigation Committee Member Repeatedly Infected with Pegasus During PEGA Inquiry

BLUFUnattributed Pegasus deployment against an active PEGA Committee member exposes a structural vulnerability no EU institution has moved to close, leaving parliamentary oversight itself penetrable by the tools it seeks to regulate.

Citizen Lab forensic analysis found former MEP Stelios Kouloglou's iPhone was infected with NSO Group's Pegasus spyware via the zero-click "PWNYOURHOME" exploit, which abused a vulnerability in Apple's HomeKit software, on or around October 21, 2022, and again on March 6 and 7, 2023, while he served as a substitute member of the European Parliament's PEGA Committee investigating spyware abuse 1. Both infection windows coincided with sensitive committee activity, including hearing preparations and draft-report deliberations in October 2022 and final report drafting in March 2023 12. Citizen Lab said it found no indication the Greek government was responsible and instead traced the intrusions to attacker email [email protected], matching one used in a previously reported May 2024 campaign against Russian and Belarusian-speaking journalists and activists; this indicates a Pegasus operator with multi-country targeting authorization 12. Kouloglou never saw three Apple threat notifications warning of possible spyware targeting and only submitted his phone to Citizen Lab for analysis in May 2026; he told The Record he believes the Greek government carried out the hacks and said he intends to sue NSO Group, while NSO Group did not respond to a request for comment 2.

Analysis
Citizen Lab's forensic finding shows spyware operators can penetrate a European Parliament inquiry's internal deliberations, exposing members' sources, medical records, and diplomatic contacts to compromise. Attribution to a specific government cannot be assessed, since no disclosure-compelling mechanism, litigation, or reopened parliamentary inquiry exists to surface the operator's identity; Kouloglou's belief that Greece was responsible, given its Predator spyware scandal, is not supported by the technical findings. The link to the 2024 campaign against Russian and Belarusian journalists rests on a single shared email identifier rather than corroborating signal intelligence, a basis that supports moderate confidence rather than higher certainty. Reporting otherwise reduces to Citizen Lab's original analysis, with The Record, TechCrunch, and netzpolitik.org relaying rather than independently verifying it. The European Commission's continued inaction on PEGA's 2023 recommendations leaves untested Scott-Railton's warning that other parliamentary targets remain unidentified.
4 sources
  1. Espionage Against the European Parliament: Member of Committee Investigating Spyware Hacked with Pegasus - Citizen Lab
  2. Spyware found on phone of European Parliament member probing it - The Record
  3. Frühere Staatstrojaner-Untersuchungen der EU: Ausschussmitglied mehrfach mit Pegasus-Software infiziert - netzpolitik.org
  4. Politician who investigated spyware abuses had his phone hacked with Pegasus spyware - TechCrunch

View in full brief →

UNCLASSIFIED // OPEN SOURCE