European Politician Hacked with Pegasus While Investigating Spyware Abuses, Reigniting Calls for Stricter EU Regulation

The digital realm of European politics has been profoundly shaken by the confirmed hacking of a prominent European politician, Stelios Kouloglou, with the notorious Pegasus spyware. This breach occurred precisely while Kouloglou served on a parliamentary committee explicitly tasked with investigating the very abuses of such surveillance tools, triggering a fresh wave of controversy and urgent calls for concrete action against the misuse of spyware by governments across the continent.

The Breach and the Investigator: A Targeted Attack

Security researchers at The Citizen Lab, a digital rights unit based at the University of Toronto’s Munk School of Global Affairs & Public Policy, revealed the confirmed phone hacking of Stelios Kouloglou, a Greek journalist and former Member of the European Parliament (MEP). The attacks, occurring in 2022 and 2023, represent a chilling milestone: Kouloglou is the first publicly identified victim of sophisticated spyware from the European Parliament’s PEGA committee. This committee, formally known as the Committee of Inquiry to investigate the use of Pegasus and equivalent surveillance spyware, was established in March 2022 to probe widespread allegations of state-sponsored spyware attacks by European governments against their own citizens, including journalists, lawyers, and opposition figures.

Kouloglou, in a candid conversation, described the deliberate compromise of his phone as "reckless," underscoring the profound violation of privacy and trust. The timing and target selection are particularly egregious, suggesting a direct attempt to infiltrate or disrupt the very body charged with uncovering and addressing such illicit surveillance practices. One serving European lawmaker, speaking on condition of anonymity due to the sensitivity of the matter, condemned the hacking as a "direct attack on the rule of law," urging the European Commission to implement robust measures, including strict limits on spyware usage within the 27-member bloc.

Pegasus: A Global Controversy and its European Footprint

The Pegasus spyware, developed by the Israeli firm NSO Group, has been at the center of a global human rights storm for years. Marketed as a tool for governments to combat serious crime and terrorism, its advanced capabilities have repeatedly been found to be exploited for political surveillance, targeting dissidents, journalists, human rights defenders, and political opponents worldwide. Pegasus is infamous for its "zero-click" exploit capabilities, meaning it can infiltrate a device and exfiltrate vast amounts of data—including messages, calls, photos, location data, and even activate microphones and cameras—without any interaction from the target. This level of invasiveness makes it an exceptionally potent and dangerous tool when wielded irresponsibly.

The European Parliament’s PEGA committee itself was a direct response to a series of escalating scandals across Europe. In countries like Hungary, Poland, Spain, and Greece, reports surfaced detailing the use of Pegasus and similar spyware against figures ranging from opposition politicians and independent journalists to government critics and even family members of ruling party officials. For instance, in Poland, investigations revealed that Pegasus was used against prominent opposition figures, including a senator and a lawyer involved in politically sensitive cases. In Spain, dozens of Catalan politicians and activists, as well as the Prime Minister, were allegedly targeted. Greece, Kouloglou’s home country, has also been embroiled in its own "Watergate" scandal, with journalists and politicians reportedly under surveillance, leading to significant political fallout and questions about democratic accountability. The very existence of the PEGA committee highlights the widespread concern within the EU regarding the erosion of fundamental rights and democratic principles due to unchecked surveillance.

Chronology of a Calculated Breach

The timeline of Kouloglou’s targeting paints a picture of deliberate and opportunistic surveillance, meticulously detailed in Citizen Lab’s report published on a Friday.

  • March 2022: The European Parliament formally establishes the PEGA committee following widespread revelations of spyware abuses across the continent. Stelios Kouloglou is appointed as a member, bringing his journalistic background and critical perspective to the investigation.
  • October 2022: Kouloglou’s iPhone is first compromised with Pegasus spyware. This period was critical for the PEGA committee, coinciding with intense internal discussions, email exchanges, and text message communications as members prepared the initial draft of their report. This first draft was specifically focusing on findings related to spyware abuses in Cyprus, Greece, Hungary, Poland, and Spain – precisely the core of the committee’s mandate. Intriguingly, this hack occurred while Kouloglou was hospitalized for a pre-scheduled surgery. The exploit, a zero-click vulnerability, would have allowed operators to potentially monitor ambient audio, capturing sensitive conversations related to his healthcare or discussions with visitors, alongside all digital data. The vulnerability exploited was a previously discovered flaw in Apple’s smart home software, patched but not yet installed on Kouloglou’s device at the time of the attack.
  • November 2022: The PEGA committee continues its intensive work, with discussions and drafting of its initial findings ongoing. Any information gleaned from Kouloglou’s device during the October hack would have provided invaluable, illicit intelligence on the committee’s strategic direction, evidence collection, and preliminary conclusions.
  • March 6-7, 2023: Kouloglou’s phone is hacked again by the same Pegasus operator. These attacks occurred while he was traveling from Athens to Brussels, a period marked by further committee hearings and months before the committee would finalize and adopt its comprehensive written report. The repeated targeting underscores the persistent interest in the committee’s internal workings and deliberations as it moved closer to presenting its official findings.
  • Late 2023 / Early 2024: Citizen Lab conducts its forensic analysis, confirming the presence and activity of Pegasus spyware on Kouloglou’s device during the specified periods.
  • Present: Citizen Lab publicly releases its report, identifying Kouloglou as a victim and reigniting the debate over spyware regulation. Kouloglou announces his intention to sue NSO Group.

Technical Nuances and Attribution Challenges

The technical details of the attack highlight the sophisticated nature of Pegasus. The exploit utilized a "zero-click" vulnerability, meaning it required no interaction from the target, such as clicking a malicious link. Instead, the spyware silently infiltrated Kouloglou’s iPhone by exploiting a specific, previously discovered flaw in Apple’s smart home software. This flaw, though patched by Apple, had not yet been installed on Kouloglou’s device, creating a window of opportunity for the attackers. Such vulnerabilities are highly prized by state-sponsored actors and private surveillance firms due to their stealth and effectiveness.

While Citizen Lab’s researchers did not definitively attribute the attack to a specific country, they provided a crucial clue: the government customer responsible for hacking Kouloglou used the exact same Pegasus-loaded email address that had been employed in a prior campaign targeting journalists across Europe. This reuse of an attacking infrastructure is highly significant. It implies that the customer not only possessed NSO Group’s authorization to deploy Pegasus but also had the operational flexibility to use it across multiple European countries, suggesting a broad remit or an expansive target list. The identity of this customer remains undisclosed, but the pattern points towards a state actor with significant resources and a clear interest in monitoring individuals involved in sensitive European political and journalistic activities.

Reactions and the Call for Concrete Action

Stelios Kouloglou expressed profound anger upon learning of the hack. "You realize that all of your personal data was taken – not all the professional exchanges or messages with ministers – but also the very private things, like the happy moments and the sad moments," he conveyed, articulating the deep sense of violation that victims of such invasive surveillance experience. His personal revelation underscores the dual impact of these attacks: they compromise official duties while simultaneously invading the most intimate aspects of an individual’s life. Driven by a commitment to democratic principles, Kouloglou declared his intention to sue NSO Group, emphasizing his actions are "for democracy, human rights, and the fight against corruption." He stressed that "corruption concerns everybody," framing the fight against spyware abuse as a fundamental battle for societal integrity.

The broader political reaction within Europe has been one of renewed urgency and condemnation. The sentiment among many lawmakers is that an attack on a member of a parliamentary investigative committee is an attack on the legislative process itself, a direct affront to the separation of powers and the foundational principles of a democratic state. The call from the anonymous European lawmaker for the European Commission to impose "strict limits on the use of spyware across the 27 member-state bloc" reflects a growing consensus that self-regulation by governments and spyware vendors has failed.

However, official responses from key entities have been notably absent or non-committal. A spokesperson for the European Commission did not respond to TechCrunch’s request for comment on the Citizen Lab report. Similarly, NSO Group, the developer of Pegasus, also declined to comment prior to publication. This silence from both the regulatory body and the company at the heart of the controversy itself, while not an admission of guilt, can be interpreted by critics as a lack of accountability and an unwillingness to engage transparently with the serious allegations. NSO Group has faced increasing international pressure, including being blacklisted by the U.S. government under a Biden-era executive order that outlawed the use of spyware that could violate human rights. Despite this, the company has reportedly received tens of millions of dollars from an unnamed American investment group, an effort seen by many as an attempt to rehabilitate its beleaguered brand and potentially re-enter lucrative markets, including the U.S.

Broader Implications for EU Democracy and Digital Sovereignty

The hacking of Stelios Kouloglou carries far-reaching implications for the future of democratic governance, digital security, and human rights within the European Union.

  1. Erosion of Trust and Democratic Oversight: When a committee tasked with investigating abuses is itself targeted, it fundamentally undermines public trust in democratic institutions and the ability of elected representatives to perform their duties without fear of illicit surveillance. It creates a chilling effect, potentially deterring others from participating in sensitive investigations.
  2. Threat to Legislative Independence: The PEGA committee was established to ensure accountability for governments’ use of powerful surveillance tools. The attack on Kouloglou directly challenges the independence of the legislative branch and its ability to hold the executive accountable, thus threatening the delicate balance of power crucial for a healthy democracy.
  3. Digital Sovereignty and Security: The incident highlights Europe’s vulnerability to sophisticated cyber-attacks, even when originating from within its own borders or authorized by EU member states. It underscores the urgent need for a cohesive EU-wide strategy for digital security, stronger encryption standards, and robust protection for critical infrastructure and key personnel.
  4. The Dual-Use Dilemma: The Pegasus case exemplifies the persistent ethical dilemma surrounding "dual-use" technologies – tools that have legitimate applications (like fighting crime) but can also be misused for malicious purposes. The challenge for the EU is to devise a regulatory framework that permits necessary security functions while preventing abuses that infringe on fundamental rights.
  5. Accountability of Spyware Vendors: NSO Group’s continued operation and attempts at rehabilitation, despite its documented involvement in human rights abuses, raise questions about the effectiveness of existing international and national regulations. Kouloglou’s planned lawsuit, along with others, represents a growing push for greater legal accountability for companies that enable such surveillance.
  6. Precedent for Future Investigations: If attacks on parliamentary investigators go unaddressed with concrete penalties, it sets a dangerous precedent, suggesting that such tactics are an acceptable risk for those seeking to suppress oversight. This could lead to a further weakening of democratic checks and balances.

In conclusion, the confirmed Pegasus hack of Stelios Kouloglou is not merely an isolated incident but a stark symptom of a deeper crisis facing European democracies. It is a direct challenge to the rule of law, the integrity of legislative processes, and the fundamental rights of privacy and freedom of expression. As the EU grapples with the fallout, the imperative for comprehensive, stringent, and enforceable regulations on the development, sale, and use of surveillance technologies has never been more urgent. Without decisive action, the very foundations of European democratic governance risk being eroded by the insidious creep of unaccountable digital surveillance.

Related Posts

I tried out OpenAI’s new AI keypad — which will be fun for some coders and slightly mystifying to everyone else

This debut marks a significant strategic pivot for the leading AI research and deployment company, traditionally known for its groundbreaking software and language models. Developed in collaboration with specialty keyboard…

Why Cognition bought Poke: AI personality is becoming a competitive advantage

The burgeoning landscape of artificial intelligence witnessed a significant strategic maneuver with the acquisition of The Interaction Company of California, the innovator behind the popular AI assistant Poke, by Cognition,…

You Missed

Japan’s Luxury Sector Shines as Jewellery Sales Soar 19% Amidst Inflationary Pressures and Yen Depreciation

Japan’s Luxury Sector Shines as Jewellery Sales Soar 19% Amidst Inflationary Pressures and Yen Depreciation

The APOE2 Gene Variant Offers Enhanced Neuronal Protection Against DNA Damage and Cellular Senescence, Unlocking New Avenues for Alzheimer’s Research

The APOE2 Gene Variant Offers Enhanced Neuronal Protection Against DNA Damage and Cellular Senescence, Unlocking New Avenues for Alzheimer’s Research

The Hidden Environmental Cost of the Puffer Jacket: Unpacking the Footprint of a Cold-Weather Staple

The Hidden Environmental Cost of the Puffer Jacket: Unpacking the Footprint of a Cold-Weather Staple

The Evolution of Modern Storage: A Comprehensive Guide to High-End Sideboards and Credenzas in Interior Design

The Evolution of Modern Storage: A Comprehensive Guide to High-End Sideboards and Credenzas in Interior Design

Volker Türk Becomes First UN Human Rights Chief to Secure Two Full Terms Amidst Significant International Division

Volker Türk Becomes First UN Human Rights Chief to Secure Two Full Terms Amidst Significant International Division

Ralph W. Hemecker, Acclaimed Television Director and Showrunner, Dies at 65

Ralph W. Hemecker, Acclaimed Television Director and Showrunner, Dies at 65