Citizen Lab finds EU lawmaker who probed spyware was himself hacked with Pegasus
The University of Toronto’s Citizen Lab found that Stelios Kouloglou, a Greek former member of the European Parliament, was infected three times with NSO Group’s Pegasus spyware during 2022 and 2023 while in Athens and Brussels. Kouloglou sat on the parliament’s PEGA committee, set up in 2022 specifically to investigate governments’ misuse of Pegasus and similar tools against journalists, activists, and politicians.
The detail that a member of the very committee scrutinizing spyware abuse was targeted while doing that work is the substance of the story. Citizen Lab noted the infections could have exposed confidential exchanges among committee members — meaning the surveillance had the potential to reach the investigation itself, and possibly the parties it was examining. Kouloglou received Apple threat notifications after each incident and requested the forensic analysis in May; the report does not attribute the operation to a specific government.