Key Takeaways:
- **Unprecedented Attack on Oversight:** The confirmed hacking of European politician Stelios Kouloglou, a member of the PEGA committee investigating spyware abuses, marks the first publicly identified instance of an investigator being targeted by the very tools they scrutinize. This represents a direct assault on democratic oversight and the rule of law.
- **Sophisticated, Zero-Click Espionage:** Researchers at Citizen Lab detailed a “zero-click” Pegasus attack in late 2022 and early 2023, exploiting an unpatched Apple iPhone vulnerability to covertly extract sensitive personal and professional data from Kouloglou’s device, underscoring the advanced capabilities of state-sponsored surveillance tools.
- **Urgent Call for Accountability & Regulation:** The incident reignites calls for immediate and concrete action from the European Commission to impose strict limits on spyware use across its 27 member states. It also highlights the urgent need for greater transparency and accountability from spyware vendors like NSO Group, whose products continue to be implicated in human rights abuses.
In a stark illustration of the perilous intersection between digital surveillance and democratic governance, a European politician has been confirmed as a victim of the notorious Pegasus spyware. Adding a chilling layer to the saga, this politician was actively serving on an investigatory committee specifically tasked with probing the abuses of such surveillance tools by European governments. The revelation has reignited a fierce controversy, underscoring the alarming extent to which governments may be leveraging sophisticated spyware to monitor their critics, even within the hallowed halls of legislative oversight.
An Investigator Under Surveillance: The Kouloglou Case
The confirmed phone hacking of Stelios Kouloglou, a Greek journalist and former politician, between 2022 and 2023, represents a significant escalation in the ongoing spyware crisis. Kouloglou’s unique position as a member of the European Parliament’s PEGA committee – the body dedicated to investigating phone spyware attacks by European governments – makes his case a watershed moment. According to researchers at the University of Toronto’s digital rights unit, The Citizen Lab, this is the first time a PEGA committee member has been publicly identified as a victim of spyware.
Speaking to TechCrunch, Kouloglou himself described the deliberate compromise of his phone as “reckless,” conveying a profound sense of violation. The sentiment was echoed by a serving European lawmaker who characterized the hacking as a “direct attack on the rule of law,” urging the European Commission to implement strict limits on spyware usage across the entire 27 member-state bloc.
Unmasking the Mechanics of the Attack
Citizen Lab’s detailed report sheds light on the technical sophistication of the attack. Kouloglou’s phone was first compromised in October 2022, and subsequently on at least two occasions in March 2023. The attacks exploited a security vulnerability in Apple’s iPhone software – a “zero-click” bug that allowed Pegasus to infiltrate the device and exfiltrate data without any interaction from the user. This particular flaw, though later patched by Apple, was still present on Kouloglou’s device at the time of the attacks.
The exploit leveraged a previously discovered vulnerability in Apple’s smart home software, a seemingly innocuous component of the iPhone ecosystem. Once activated, the spyware gained unfettered access to Kouloglou’s private data, including text messages, correspondence, precise location data, and even personal photographs. The silent, invisible nature of “zero-click” exploits makes them particularly insidious, leaving no trace for the victim to detect.
Timing Is Everything: A Coordinated Espionage Effort
The timing of these hacks is eerily precise and deeply suspicious. The initial compromise in October 2022 coincided directly with intense internal discussions within the PEGA committee, involving email and text message exchanges throughout October and November. These discussions were crucial to the formulation of the committee’s first draft report, which detailed extensive spyware abuses in Cyprus, Greece, Hungary, Poland, and Spain. It is plausible that the operators aimed to gain insight into the committee’s evolving findings and strategies.
Further complicating the ethical landscape, the October 2022 hack occurred while Kouloglou was hospitalized for a pre-scheduled surgery. This raises the alarming possibility that the spyware operators were able to listen in on sensitive ambient audio, potentially capturing private conversations related to his healthcare or discussions with visitors during a highly vulnerable period.
Months later, on March 6 and 7, Citizen Lab confirmed that Kouloglou’s phone was again targeted by the same Pegasus operator. This second wave of attacks occurred while Kouloglou was traveling from Athens to Brussels for committee hearings, just months before the PEGA committee finalized and adopted their comprehensive written report. The consistent targeting during critical periods of legislative work suggests a deliberate and sustained effort to monitor the committee’s progress and potentially influence its outcomes.
The Anonymous Operator and NSO Group’s Shadow
While Citizen Lab’s researchers refrained from attributing the phone hacking to a specific country, their report provided a crucial clue: the government customer responsible for the attack utilized the identical Pegasus-loaded email address that had been employed in a prior campaign targeting journalists across Europe. Though the customer’s precise identity remains unknown, the reuse of this specific attacking email address strongly implies that the customer possessed NSO Group’s explicit authorization to deploy its Pegasus spyware for surveillance operations spanning multiple European nations.
Neither a spokesperson for the European Commission nor NSO Group responded to TechCrunch’s requests for comment regarding the Citizen Lab report prior to its publication, further shrouding the incident in a veil of opacity and raising questions about accountability.
The Human Element and the Fight for Democracy
For Kouloglou, the revelation was deeply personal. “You realize that all of your personal data [was taken] — not all the professional exchanges or messages with ministers — but also the very private things, like the happy moments and the sad moments,” he shared, articulating the profound emotional toll of such an invasive breach. He expressed his conviction that he was targeted specifically due to his critical work on the European Parliament’s committee investigating Pegasus abuses.
In response to this egregious violation, Kouloglou has declared his intention to sue NSO Group, the Israeli-headquartered spyware maker. NSO Group’s products, including Pegasus, have faced widespread condemnation for their role in human rights abuses, leading to a Biden-era executive order that largely banned the U.S. government’s use of spyware capable of violating human rights. Despite this, NSO Group confirmed last year that an unnamed American investment group had injected tens of millions of dollars into the company, an investment widely seen as an attempt to rehabilitate its tarnished brand.
Kouloglou’s decision to go public with his story is not merely a personal quest for justice. It is, as he put it, “for democracy, human rights, and the fight against corruption.” He emphasized the universal nature of the threat: “Corruption concerns everybody.” His stand serves as a rallying cry for greater transparency and stricter controls in an era where digital surveillance tools, ostensibly designed for national security, are increasingly weaponized against the very foundations of open societies.
The Bottom Line: A Crisis of Trust and Sovereignty
The hacking of Stelios Kouloglou is more than an isolated incident; it’s a stark warning sign for democratic institutions worldwide. When legislators tasked with oversight become targets of the very surveillance they investigate, it signals a profound crisis of trust and an audacious challenge to national sovereignty. This event amplifies the urgent need for robust international regulations, stronger ethical frameworks for technology companies, and unwavering political will to hold both spyware vendors and their government clients accountable. Without decisive action, the unchecked proliferation and abuse of sophisticated surveillance tools threaten to erode fundamental rights, stifle dissent, and undermine the democratic processes designed to protect society itself. The fight against corruption, as Kouloglou reminds us, is indeed a concern for everybody, especially when it manifests in the digital shadows, compromising the very architects of our laws.
When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.
{content}
Source:{feed_title}

