Full Breakdown
Former EU Lawmaker Hacked with Pegasus Spyware While Overseeing Its Investigation
7/4/2026, 1:28:58 AM
Core Event: Former MEP Targeted with Pegasus Spyware
Greek journalist-turned-politician Stelios Kouloglou, serving on the European Parliament’s PEGA Committee that probes illegal spyware, had his iPhone infected with Pegasus on at least three occasions: first in October 2022, then twice in March 2023 while he was in Athens and Brussels, coinciding with his oversight work.
Scope & Technical Details: Extent of the Intrusions
Citizen Lab verified three distinct Pegasus implants on Kouloglou’s iPhone, exploiting an Apple software flaw that was unknown at the time. Apple later patched the vulnerability, and its security alerts reached the target months after each breach.
Official Responses: Institutional Reactions
The European Parliament said its IT security services constantly monitor cybersecurity threats and that screening tools have been available to MEPs since 2022. Apple confirmed the patched vulnerability and its routine security alerts. NSO Group reiterated that Pegasus is sold only to government agencies for legitimate law-enforcement purposes. Meta Platforms, which previously won a damages award against NSO, has accused the firm of breaching a court injunction.
Criticism & Opposition: Voices of Concern
Sophie in ‘t Veld, a former MEP who helped launch the PEGA Committee, warned that the hack illustrates a surveillance free-for-all where anyone can spy on anyone. Rand Hammoud of the Center for Democracy and Technology Europe said the case raises serious concerns about the integrity of democratic oversight. German MEP Hannah Neumann argued that spyware weakens democratic oversight, parliamentary independence and the rule of law.
Conflicting Reports & Gaps: Attribution Unclear
Citizen Lab could not determine who operated Pegasus in the Kouloglou cases and found no evidence implicating the Greek government. NSO Group declined comment, the European Commission did not respond, and Apple did not directly address the specific breach. The European Parliament’s statement remained limited to general security measures.
Verbatim Quotes
- “I was not expecting that a PEGA member would be spied on by Pegasus,” — Stelios Kouloglou
- “We're in a situation where anybody could spy on anyone and they're spying on citizens, they're spying on journalists, they're spying on NGOs, on lawyers, on politicians, and nobody knows who's behind it,” — Sophie in ‘t Veld
- “constantly monitor cybersecurity threats as well as potential cyberattacks against its working environment.” — European Parliament spokesperson
- “It weakens democratic oversight, parliamentary independence and the rule of law.” — Hannah Neumann
What's Next: Future Actions
The European Parliament is expected to broaden Pegasus-screening tools to all parliamentary devices and to launch a formal inquiry into the breaches. Civil-society groups call for stricter regulation of commercial spyware and greater transparency from technology firms to protect democratic processes.
