A European politician investigating spyware abuses was himself hacked with Pegasus. Citizen Lab confirmed the phone of Stelios Kouloglou — a Greek journalist and former MEP — was compromised in 2022 and 2023 while he served on the European Parliament’s PEGA committee.
This is the first time a PEGA committee member has been publicly identified as a Pegasus victim. And the timing isn’t coincidental. The October 2022 hack lined up with intense discussions about the committee’s first draft report on spyware abuses in Cyprus, Greece, Hungary, Poland, and Spain.
The exploit was a zero-click bug — no interaction needed. It abused a flaw in Apple’s smart home software that had already been patched, but Kouloglou hadn’t installed the update yet. The spyware grabbed his messages, correspondence, location data, and photos.
Kouloglou was in the hospital for surgery at the time. The spyware could have recorded ambient audio — conversations with doctors, visitors, family.
The same operator hit his phone again on March 6 and 7, 2023, while he traveled from Athens to Brussels. That was during committee hearings, months before the final report was adopted.
Citizen Lab didn’t name the government responsible. But the attacking email address was reused from a previous campaign that hacked journalists across Europe. That means whoever did it had NSO Group’s authorization to use Pegasus across multiple countries.
Kouloglou told TechCrunch he plans to sue NSO. He described feeling violated. “You realize that all of your personal data [was taken] — not all the professional exchanges or messages with ministers — but also the very private things, like the happy moments and the sad moments.”
