Pegasus Hit the EU Lawmaker Investigating Pegasus

Citizen Lab finds former PEGA committee member Stelios Kouloglou was hacked with Pegasus twice while the EU Parliament was investigating that very spyware.

A surveillance camera monitoring a public space at night

For more than three years, the European Parliament’s PEGA committee existed to answer one question: how aggressively were governments across the EU using Pegasus and its commercial cousins against their own citizens? On July 3, Citizen Lab published a finding that turns the question inside out. A member of the committee itself, Greek former MEP Stelios Kouloglou, was hacked with Pegasus twice while he sat on the inquiry.

The infections happened on October 21, 2022 and on March 6 and 7, 2023. Both dates fall inside Kouloglou’s tenure as a substitute member of the Committee of Inquiry to investigate the use of Pegasus and equivalent surveillance spyware (PEGA). The committee had been established in March 2022 in the wake of the Pegasus Project consortium reporting. Kouloglou, a former investigative journalist first elected as a member of the Syriza party, was on it from the start, according to the Citizen Lab report.

What Citizen Lab found on the phone

The forensic picture is unusually clean. Citizen Lab examined Kouloglou’s iPhone, running iOS 15.5 at the time of the attacks, after Kouloglou contacted the lab in May 2026. Researchers identified infections on three dates with high confidence. The two clearest compromises are October 21, 2022 and the two-day window of March 6 to 7, 2023.

The technical fingerprint is what links the cases to a known campaign rather than to NSO Group at large. The 2022 infection pivoted through a HomeKit email lookup for the address [email protected], then triggered a Pegasus process over mobile data two minutes later. Citizen Lab calls the underlying exploit chain PWNYOURHOME: a specially crafted NSKeyedArchive delivered via HomeKit, followed by malicious content that landed in MessagesBlastDoorService. Apple patched the HomeKit flaw in iOS 16.3.1 and the related blastdoor weakness earlier, in iOS 16.1.

That same Apple ID email appears in Citizen Lab and Access Now’s May 2024 report on Pegasus targeting exiled Russian and Belarusian-speaking journalists and activists in Europe, where Citizen Lab labelled it “Email 1.” The infrastructure overlap is what makes researchers confident that the operator behind both campaigns is the same NSO Group customer, and the fact that infections landed in two jurisdictions - Greece in October 2022, Belgium in March 2023 - suggests that customer held licenses allowing it to hit multiple EU countries.

Citizen Lab is not naming a country. “We are not attributing these infections to a particular government at this time” and “We have no indications that this hacking was the work of the Greek government” are both direct quotes from the report. The lab also flags that Apple threat notifications are not real-time alerts and are typically delivered in batches, sometimes months after the targeting - which is why Kouloglou’s case sat unexamined until he reached out to Citizen Lab this spring.

What was happening at the time

The dates map precisely onto the committee’s work. According to Politico EU, the October 2022 infection coincided with PEGA preparations for research missions to Greece, Cyprus and Spain investigating government use of spyware in those countries. Kouloglou told Politico his work at the time was a period of “enormous preparation,” and that he believes the hacks were linked directly to his committee role. “Without a doubt the hacking had to do absolutely with my status as member of the PEGA Committee,” he said.

The March 2023 reinfection hit during the final drafting of PEGA’s report, while Kouloglou was travelling from Athens to Brussels for committee work. The October 2022 attack had one additional quirk that has drawn attention: it coincided with Kouloglou’s hospital admission for elective surgery and a visit from the Greek investigative journalist Thanasis Koukakis, who had previously testified in front of PEGA about being targeted himself in what Greek press have dubbed the “Greek Watergate”, in which more than 80 politicians, journalists and military officials were targeted.

Kouloglou was not the only EU figure whose phone Citizen Lab and its partners have flagged. Politico EU reports that this is “the first publicly documented case of an active member of the committee being targeted with Pegasus,” but the lab and previous investigations have previously linked Pegasus or Candiru to other sitting MEPs, including Diana Riba, Jordi Solé, Clara Ponsati, Carles Puigdemont, Nathalie Loiseau, Elena Yoncheva, and Daniel Freund. European Parliament President Roberta Metsola was also among those targeted in earlier Citizen Lab findings, according to Sophie in ‘t Veld, the former PEGA lead lawmaker.

What This Means

For readers in Brussels and elsewhere, the practical news is that the institution charged with policing spyware abuses in the EU has now confirmed that one of its own members was subjected to the same tool - the same body that has previously had to ban US AI tools from lawmakers’ devices over data sovereignty fears. That reality reframes the European Commission’s three-year inaction on PEGA’s recommendations. As Citizen Lab senior researcher John Scott-Railton told The Guardian: “This case is the ultimate irony of Europe’s spyware crisis. Someone on the very committee tasked with investigating Pegasus gets infected by it. And what has happened since? The parliament looks the other way when new European spyware abuses emerge.” He added: “I can tell you how the next chapter will go: more hacked parliamentarians. In fact, I suspect there are members voting and attending high-level meetings with no idea that their phone has been turned into a spy in their pocket.”

For EU citizens it confirms a pattern that has been visible since at least 2021: NSO Group’s flagship product continues to land on devices inside the EU, multiple operators have the capability, and no one in Brussels has used that fact to push through a moratorium, an export license veto, or a damages regime that would meaningfully deter the next buyer. As in ‘t Veld told Politico: “While we’re all obsessing with the state of democracy and the rule of law in the United States, there’s complete impunity on this.”

For anyone outside Brussels, the most actionable detail is Apple-style threat notification lag. The earliest of the three Apple alerts Kouloglou received landed in March 2023, the latest in April 2024, well after the actual infections. Citizen Lab notes that “Threat notifications from Apple and other companies are not real-time alerts.” If you have ever received one and ignored it on the assumption that the attack was old news, you may have been right. You also may not be safe now.

The Bottom Line

Citizen Lab’s report makes the EU’s spyware debate impossible to file under “foreign abuse” any longer. An MEP sitting on the committee investigating Pegasus was hacked with Pegasus, twice, while that committee was actively investigating exactly that tool, and the infections match a known campaign against exiled Russian and Belarusian journalists in Europe. Brussels now has a case study showing that the danger it says it wants to regulate is sitting in its own corridors.