A former Member of the European Parliament who helped investigate the misuse of Pegasus spyware has now been confirmed as one of its victims. Security researchers from Citizen Lab revealed that Greek journalist and former lawmaker Stelios Kouloglou was secretly infected with Pegasus while serving on the European Parliament’s PEGA Committee. The committee was created to investigate the misuse of commercial spyware across Europe.

european-parliament-pega-committee-investigation

According to the forensic investigation, Kouloglou’s iPhone was infected with Pegasus at least three times between October 2022 and March 2023. These attacks happened while the PEGA Committee was actively holding hearings, meeting experts, and collecting evidence about spyware abuse. Researchers believe the spyware could have accessed confidential committee discussions and other sensitive parliamentary information.

Citizen Lab said the infections happened during some of the committee’s most important activities. One of the first infections occurred while Kouloglou was recovering in a hospital after surgery. Around the same period, he met investigative journalist Thanasis Koukakis, who had previously been targeted with spyware. Additional infections were discovered during March 2023, when the committee was finalizing its findings and recommendations.

pegasus-spyware-iphone-cyber-surveillance-attack

Pegasus is one of the world’s most advanced spyware tools and is developed by the Israeli cyber company NSO Group. It can secretly access messages, emails, photos, contacts, microphones, cameras, and location data without the victim noticing. In Kouloglou’s case, researchers found that the attacks used a zero-click exploit, allowing the spyware to infect the device without requiring him to click any malicious link.

Citizen Lab said it has not identified the government or organization responsible for the attacks. The researchers also stated that they found no evidence linking the Greek government to the infections. However, they discovered similarities between this operation and an earlier Pegasus campaign that targeted Russian- and Belarusian-speaking journalists and activists living in Europe, suggesting the same Pegasus customer may have been involved.

apple-iphone-pegasus-spyware-security-update

Apple had also warned Kouloglou several times that his iPhone was likely being targeted by sophisticated spyware. He reportedly received threat notifications in March 2023, August 2023, and April 2024. After examining the device, Citizen Lab confirmed that Pegasus had successfully infected it during his time on the PEGA Committee. The findings make this the first publicly confirmed case of a PEGA Committee member being hacked while investigating spyware abuse.

The discovery has raised fresh concerns about the security of European institutions and the safety of lawmakers investigating surveillance technology. Experts warned that if confidential parliamentary work can be accessed through spyware, it could affect democratic processes and expose sensitive political discussions. Several current and former lawmakers described the incident as a serious attack on democratic institutions and the rule of law.

cybersecurity-spyware-digital-threat-warning

Kouloglou said he was shocked and angry after learning that the same spyware his committee was investigating had secretly infected his own phone. He said the incident was not only a violation of his personal privacy but also a threat to democracy, transparency, and public trust. The case has renewed calls for stronger regulation of commercial spyware and better protections for journalists, politicians, and human rights defenders against unlawful digital surveillance.

Stay alert, and keep your security measures updated!

Source: Follow cybersecurity88 on X and LinkedIn for the latest cybersecurity news