Greek journalist and former MEP Stelios Kouloglou targeted while serving on committee examining spyware abuses

Image by Gibrán Aquino

Please Follow us on Truth Social, X , Youtube , Minds, Telegram, Rumble, GETTR, Gab, Instagram

Security researchers have confirmed that Greek journalist and former Member of the European Parliament Stelios Kouloglou had his iPhone infected with NSO Group’s Pegasus spyware in 2022 and 2023 while he served on the European Parliament’s PEGA committee investigating abuses of the controversial surveillance tool.

The findings, released Friday by the University of Toronto’s Citizen Lab, mark the first publicly identified case of a PEGA committee member being targeted with the very spyware the panel was tasked with scrutinizing. The revelations have reignited concerns about European governments weaponizing powerful surveillance technology against journalists, lawmakers, and critics, reported Tech Crunch.

Citizen Lab researchers said Kouloglou’s phone was hacked in October 2022 and at least twice more on March 6 and 7, 2023. The attacks exploited a zero-click vulnerability in Apple’s iOS software — a previously known flaw in the iPhone’s smart home features — allowing the spyware to infiltrate the device without any interaction from the victim. At the time of the hacks, the security patch for the vulnerability had not yet been installed on Kouloglou’s phone.

The spyware granted operators access to private data including text messages, emails, location information, photos, and ambient audio recordings. One of the October hacks occurred while Kouloglou was hospitalized for surgery, potentially enabling surveillance of his medical discussions and conversations with visitors.

The timing of the attacks aligned with key moments in the PEGA committee’s work. The October 2022 hack coincided with internal discussions and drafting of an initial report on spyware abuses in countries including Cyprus, Greece, Hungary, Poland, and Spain. The March 2023 hacks took place as Kouloglou traveled from Athens to Brussels for committee hearings, just months before the panel finalized its findings.

Citizen Lab did not attribute the attacks to a specific government but noted that the operator used the same Pegasus-linked email address previously observed in a broader campaign targeting European journalists. The reuse of the infrastructure suggests the customer had NSO Group’s authorization to deploy the spyware across multiple European countries.

Kouloglou, speaking to TechCrunch, described the hacking as “reckless” and expressed anger upon learning his personal data had been compromised.

“You realize that all of your personal data [was taken] — not all the professional exchanges or messages with ministers — but also the very private things, like the happy moments and the sad moments,” he said.

He believes he was targeted because of his role on the PEGA committee and plans to sue NSO Group, the Israeli company behind Pegasus. Kouloglou said he went public “for democracy, human rights, and the fight against corruption,” adding: “Corruption concerns everybody.”

A serving European lawmaker called the incident “a direct attack on the rule of law” and urged the European Commission to impose strict limits on spyware use across the 27-member bloc. The Commission did not respond to requests for comment. NSO Group also declined to comment on the Citizen Lab report.

While spyware infections of lawmakers remain relatively rare, the targeting of a committee member investigating the tool itself has raised fresh questions about how governments justify the use of such technology for combating serious crime while deploying it against oversight bodies, journalists, and political opponents.

NSO Group continues to face international scrutiny. The company is largely banned from U.S. government contracts under a Biden-era executive order addressing spyware linked to human rights violations. Last year, it confirmed receiving tens of millions of dollars from an unnamed American investment group in what appeared to be an effort to rehabilitate its image.

‘NO AD’ subscription for CDM!  Sign up here and support real investigative journalism and help save the republic!