NSO Group's Pegasus hacking software was repeatedly used against a member of the European Parliament while he was conducting an investigation into spyware abuses in Europe, according to a new report from the Citizen Lab at the University of Toronto.
Targeting of Stelios Kouloglou
Researchers said they could not attribute the attacks against Stelios Kouloglou, a Greek former MEP and journalist, to any particular government operator of Pegasus. However, their investigation found the attack bore the hallmarks of a previous hacking campaign against exiled Russian and Belarusian journalists in Europe.
"When you realise your private life is scrutinised by very bad people, you become angry," Kouloglou said in an interview. "It's a big issue having to do with corruption, justice and democracy."
Kouloglou's Role in the Pega Committee
At the heart of Citizen Lab's report is Kouloglou's work for the special European parliamentary committee known as Pega, established in March 2022 after the Pegasus Project by the Guardian and a consortium of media outlets. The Pegasus Project revealed how journalists, activists, politicians, and others were targeted by governments using Pegasus, made by Israel-based NSO Group and sold for stopping serious crime and terror attacks. Pega's mission was to investigate spyware use contravening EU law.
Kouloglou, first elected as a Syriza party member, joined the Pega committee in March 2022. His mobile device was first infected about seven months later, on 21 October 2022, during a "particularly intense period of activity" in Pega's deliberations, including drafting the committee's first report. NSO did not respond to a request for comment.
Hacking Incidents and Connections
The hacking coincided with Kouloglou's hospital admission for elective surgery, where he was visited by Greek investigative journalist Thanasis Koukakis. Koukakis was working on mercenary spyware stories in Greece following the "Greek Watergate" scandal, involving illegal targeting of over 80 people, including politicians, journalists, and military officials. Koukakis, a targeted victim, had testified before the Pega committee.
Kouloglou's device was hacked again on 6 and 7 March 2023, when Pega was in intensive discussions on the final report. The hacking coincided with his travel from Athens to Brussels.
Significance and Aftermath
Citizen Lab said this marks the first time a Pega committee member is known to have been targeted with spyware. The committee's recommendations have essentially been ignored, said John Scott-Railton, a senior researcher at Citizen Lab.
"This case is the ultimate irony of Europe's spyware crisis. Someone on the very committee tasked with investigating Pegasus gets infected by it. And what has happened since? The parliament looks the other way when new European spyware abuses emerge," Scott-Railton said. "I can tell you how the next chapter will go: more hacked parliamentarians. In fact, I suspect there are members voting and attending high-level meetings with no idea that their phone has been turned into a spy in their pocket."
Operator Attribution
While Citizen Lab could not pinpoint the probable government client, researchers believe the same operator who targeted Kouloglou also targeted seven Russian and Belarusian-speaking independent journalists and opposition activists based in Europe. The researchers identified a unique Apple ID email used in the attacks, suggesting they were by the same government client. The client likely had licences to operate in Belgium and Greece, Citizen Lab said.



