IC Technology & Surveillance — 2026-07-08
Citizen Lab Confirms Pegasus Spyware Infected Device of MEP Investigating EU Spyware Abuses
BLUFConfirmed targeting of a sitting spyware oversight committee member demonstrates that European institutional safeguards against commercial surveillance remain performative rather than operative.
Citizen Lab reported on July 3 that the iPhone of Stelios Kouloglou, a Greek journalist and former MEP who served on the PEGA Committee investigating spyware abuses, was infected with NSO Group's Pegasus spyware on or around October 21, 2022, and again on March 6 and 7, 2023, potentially exposing attackers to confidential committee documents and deliberations 12. Access Now stated the October 2022 infection traced to the same attacker-controlled Apple ID, [email protected], used against Russian and Belarusian exiled journalists in a 2024 joint investigation, though Citizen Lab found no evidence identifying the responsible government 2. Amnesty International and more than 30 human rights organizations issued a joint statement on July 6 calling for an independent investigation into the hacking and renewed implementation of the PEGA Committee's 2023 recommendations 1.
AnalysisConfirmed reinfection of a sitting PEGA Committee member shows spyware operators reached inside the body created to constrain the industry, exposing committee deliberations and draft-report preparations to an unidentified state actor. Reporting rests on a single primary forensic investigation, amplified without independent corroboration by Access Now and Amnesty International; the shared Apple ID linking this attack to the 2024 case against exiled Russian and Belarusian journalists extends the operator's target set from civil society into sitting European officials, undercutting claims that spyware abuse in Europe is confined to isolated incidents. Low confidence attaches to any near-term accountability response, given the Greek data protection authority's failure to open formal investigations into prior
Predatorgate cases and the PEGA Committee's still-unimplemented 2023 recommendations after more than two years. The infection may instead reflect surveillance of Kouloglou's contacts, particularly his hospital visitor Thanasis Koukakis, previously targeted separately with Predator spyware, rather than a deliberate operation against the Committee itself.
3 sources
- Europe: Brazen hacking of former MEP investigating Pegasus abuses exposes painful inaction over spyware - Amnesty International
- Same government, more victims: Access Now calls for an urgent investigation into hacking of MEP
- Espionage Against the European Parliament: Member of Committee Investigating Spyware Hacked with Pegasus - The Citizen Lab
View in full brief →