Policy & Regulation
Spyware investigator hacked with Pegasus spyware
Security researchers confirmed that former European politician Stelios Kouloglou was hacked with Pegasus spyware while serving on a committee investigating the tool's abuse.
Security researchers at The Citizen Lab, a digital rights unit at the University of Toronto, have confirmed that Greek journalist and former politician Stelios Kouloglou had his phone hacked with Pegasus spyware. The hacking occurred while Kouloglou was serving on the European Parliament’s PEGA committee, a legislative body tasked with investigating spyware abuses. This marks the first time a member of this specific committee has been publicly identified as a target of the surveillance tool, which is manufactured by NSO Group, an Israeli-headquartered spyware maker.
According to The Citizen Lab, the compromise of Kouloglou’s phone involved a zero-click exploit—a bug that allows spyware to compromise a device without any user interaction. The exploit targeted a security vulnerability in Apple’s iPhone software. The researchers confirmed that Kouloglou was hacked in October 2022 and at least twice in March 2023, specifically on March 6 and 7. These dates coincided with intense committee discussions and hearings, as well as Kouloglou’s travel from Athens to Brussels, just months before the committee finalized its draft report on spyware abuses across Europe, including in Cyprus, Greece, Hungary, Poland, and Spain. The identity of the NSO Group customer responsible for the hack remains unknown.
Kouloglou described the deliberate compromise of his phone as reckless. Kouloglou, a former politician, stated, “You realize that all of your personal data [was taken] — not all the professional exchanges or messages with ministers — but also the very private things, like the happy moments and the sad moments.” He asserted that he plans to sue NSO Group, framing his decision as an effort to support democracy, human rights, and the fight against corruption. Meanwhile, one serving European lawmaker characterized the hacking of Kouloglou’s phone as a direct attack on the rule of law and called on the European Commission to take action.
The incident highlights the ongoing struggle to regulate surveillance tools across the 27 member-state bloc, where critics argue such technologies violate people’s human rights. NSO Group remains largely banned from use in the United States following an executive order targeting spyware that could violate human rights. However, NSO Group reported that an unnamed American investment group likely funneled tens of millions of dollars into the company, an investment likely intended to rehabilitate the spyware maker’s brand.
Why it matters
The hacking of a lawmaker tasked with investigating spyware abuses underscores the persistent difficulty of regulating surveillance tools, even when they are deployed against the very officials probing their misuse.