A former Member of the European Parliament was repeatedly hacked with Pegasus spyware while serving on a parliamentary committee investigating the abuse of Pegasus and similar surveillance technologies, according to forensic findings published by the University of Toronto’s Citizen Lab.
Amnesty International said the targeting of Greek investigative journalist and former MEP Stelios Kouloglou exposed serious weaknesses in Europe’s response to highly invasive commercial spyware. The organization called for an independent investigation into the attack and urgent implementation of recommendations previously adopted by the European Parliament.
Former MEP’s Phone Infected During Spyware Inquiry
Citizen Lab’s forensic analysis found with high confidence that Kouloglou’s iPhone was successfully infected with NSO Group’s Pegasus spyware on or around October 21, 2022, and again on March 6 and 7, 2023.
At the time, Kouloglou was serving as a substitute member of the European Parliament’s Committee of Inquiry to investigate the use of Pegasus and equivalent surveillance spyware, widely known as the PEGA Committee.
The infections occurred during important periods of the committee’s work, including preparations for hearings, country visits and discussions surrounding its draft and final reports. Citizen Lab warned that the attackers may have gained access to confidential communications, internal documents and non-public committee deliberations.
Parliamentary Oversight May Have Been Compromised
Amnesty International said the hacking raised serious concerns about the integrity of independent parliamentary oversight in Europe.
Elina Castillo Jiménez, Advocacy and Policy Advisor at Amnesty International’s Security Lab, said the targeting demonstrated that safeguards intended to prevent spyware abuse were still not being properly implemented.
The attack is particularly significant because Kouloglou was helping investigate the same type of surveillance technology that was used to compromise his device. Amnesty warned that the case showed how spyware could interfere with the ability of elected representatives to examine possible government abuses without intimidation or unlawful surveillance.
Citizen Lab described the case as the first publicly documented infection of a PEGA Committee member with Pegasus while the committee was carrying out its inquiry. Researchers said the breach could have exposed confidential exchanges between committee members and staff, potentially including information relevant to the countries and actors under investigation.
No Government Publicly Identified as Responsible
Citizen Lab did not attribute the attacks to a specific government or Pegasus customer. The researchers also said they had found no indication that the Greek government was responsible for the infections.
However, the technical analysis identified an overlap between the first infection and an earlier Pegasus campaign that targeted Russian- and Belarusian-speaking journalists, opposition figures and activists living in exile in Europe.
Citizen Lab said the evidence suggested that a Pegasus operator authorized to conduct infections across multiple European jurisdictions may have been involved. Further investigation would be required to identify the responsible actor.
EU Accused of Failing to Address Spyware Abuses
The European Parliament’s PEGA Committee adopted recommendations in June 2023 aimed at addressing legal and regulatory gaps that allowed spyware abuse to continue.
Amnesty International said meaningful EU-wide action had still not followed nearly three years later. It argued that continued delays risked encouraging impunity among state users and companies operating within the commercial surveillance industry.
Amnesty and a coalition of civil society organizations described the hacking as a threat to the rule of law, fundamental rights and democratic oversight.
The organizations urged the European Commission to publicly report on progress toward implementing the PEGA Committee’s recommendations and publish a clear roadmap for addressing spyware abuse across the European Union.
Calls for Independent Investigation and Device Screening
Amnesty International called for an independent and impartial investigation to determine who was responsible for hacking Kouloglou’s phone and to establish the full circumstances surrounding the attacks.
Citizen Lab also recommended that former and current members of the PEGA Committee, along with their staff, submit their devices for forensic examination. Researchers warned that without comprehensive screening, it would be impossible to determine whether other committee members had also been targeted.
The European Parliament was urged to investigate surveillance threats against its members, improve spyware-screening programmes and strengthen guidance for lawmakers who receive threat notifications from technology companies.
Civil society groups also called on EU member states to provide effective remedies for victims of unlawful surveillance, including access to evidence, independent investigations and accountability for government agencies and corporate actors.
They further demanded stronger enforcement of the EU’s rules governing exports of dual-use surveillance technology and safeguards preventing European public funds from supporting companies involved in developing, selling or deploying abusive spyware.
Amnesty International warned that if an elected representative investigating surveillance abuses could not be protected from intrusive spyware, journalists, activists, human rights defenders and members of the wider public remained at serious risk.
