A Spyware Investigator Got Spied On: Pegasus Hit an EU Lawmaker Probing Pegasus
Forensic analysis of Stelios Kouloglou's phone shows repeated Pegasus infections while he sat on the European Parliament's own spyware inquiry.

Key points
- The Citizen Lab confirmed that former Member of the European Parliament Stelios Kouloglou was infected with Pegasus spyware while serving on the EU committee investigating that exact tool.
- Pegasus is commercial spyware sold by Israeli firm NSO Group that can read messages, listen through the microphone and pull data from a target's phone.
- The infections happened while Kouloglou was actively helping lead the parliamentary inquiry known as PEGA into the abuse of such surveillance tools across Europe.
- Citizen Lab's forensic examination found the attackers could have had broad access to the device's contents.
- The case adds to a growing list of European politicians and lawyers whose phones have been hit by mercenary spyware in recent years.
A lawmaker whose job was to investigate spyware abuse in Europe was himself being spied on with the very tool he was investigating.
That's the finding from the Citizen Lab, the University of Toronto research group that studies digital surveillance. Its analysis, picked up this week by The Hacker News, shows that former Member of the European Parliament Stelios Kouloglou had his phone repeatedly infected with Pegasus. We first reported on NSO Group's tactics on 8 June 2026, when Meta caught Pegasus operators back on WhatsApp despite a court injunction.
Pegasus is commercial spyware, software sold to governments that quietly takes over a phone and turns it into a listening device. Made by Israeli company NSO Group, it can read texts, open encrypted chats, switch on the microphone and copy files, usually without the owner noticing.
Kouloglou wasn't a random target. He sat on PEGA, the European Parliament's special committee set up in 2022 to investigate exactly this kind of abuse across EU member states. The person helping write Europe's report on spyware misuse had spyware on his own phone.
How did they get onto his phone?
Citizen Lab's forensic work points to Pegasus infections that would have given attackers deep access to what was on the handset. The researchers haven't publicly named which government client of NSO Group was behind the intrusions.
That matters. Pegasus isn't sold on the open market: NSO says it licenses the tool only to vetted government agencies for serious crime and counter-terrorism work. Every confirmed case of a politician or journalist being hit therefore points back to a state customer.
Modern Pegasus attacks often use what security researchers call zero-click exploits, flaws in apps like iMessage or WhatsApp that let spyware land on a phone without the target tapping anything at all. No dodgy link to avoid. The phone receives a message and it's infected.
Standard advice like "turn on two-factor authentication" wouldn't have stopped this. Multi-factor authentication protects accounts from password guessing. It does nothing when the attacker owns the operating system on your device.
Should you worry?
For most readers, the direct risk is low. Pegasus licences reportedly cost millions and target specific high-value individuals, not the general public.
The wider point is about oversight. If a sitting European lawmaker investigating spyware can be hacked with that same spyware, the guardrails around who uses these tools clearly aren't working. That's a political problem, not a personal one.
Some practical habits do help anyone at elevated risk. Keep your phone's operating system updated the day patches arrive: Apple's Lockdown Mode and Google's Advanced Protection Program are built for people in that position and close down many of the entry points spyware relies on. Restart the phone regularly, since some spyware strains don't survive a reboot, though determined attackers will simply reinfect. Journalists, lawyers and politicians can get free forensic help from Citizen Lab or Amnesty International's Security Lab.
The PEGA committee's final report concluded that several EU governments had used commercial spyware against critics. Kouloglou's phone, it turns out, was evidence of that all along.



