Politician Who Revealed Spyware Abuse Targeted by Pegasus Hack on His Phone
Absolutely! Here’s a revised version of the content while maintaining the HTML tags:
Security specialists have confirmed that the phone of a European politician was infiltrated by Pegasus spyware while he served on an investigatory committee examining the misuse of this notorious surveillance tool. This disclosure has reignited discussions regarding government abuse of spyware to monitor dissenters.
Researchers from The Citizen Lab at the University of Toronto highlight that the confirmed hacking of Greek journalist and former politician Stelios Kouloglou in 2022 and 2023 is significant as it is the first time a member of the European Parliament’s PEGA committee, tasked with investigating spyware attacks by European governments, has been publicly identified as a victim of spyware.
In an interview with TechCrunch, Kouloglou described the intentional breach of his phone as “reckless.” Another sitting European lawmaker characterized the hacking of Kouloglou’s device as a “direct assault on the rule of law” and urged the European Commission to implement robust regulations on spyware usage across the 27-member state bloc.
Although cases of spyware targeting legislators are rare, the targeting of a committee investigator by the very spyware he is scrutinizing highlights an increasing scrutiny on the committee’s endeavors, especially with an anticipated report detailing its findings. These incidents raise crucial concerns about how governments employ spyware, which is ostensibly meant for tackling serious crimes but often ends up surveilling journalists, lawmakers, and dissenters.
While not explicitly attributing the phone hacking to a specific nation, Citizen Lab noted that the government client utilized the same Pegasus-enabled email address as in a previous operation that compromised journalists’ devices across Europe. The identity of this client remains unknown, but the reuse of the email implies they had NSO Group’s authorization to deploy its Pegasus spyware in multiple European nations.
A representative from the European Commission did not respond to TechCrunch’s request for comment. NSO Group also opted not to provide any remarks regarding the Citizen Lab report prior to its publication.
In its report released on Friday, Citizen Lab confirmed that Kouloglou’s phone was breached in October 2022 and at least two additional times in March 2023 through an exploit that capitalized on a security vulnerability in Apple’s iPhone software. Although this vulnerability has been patched, Kouloglou had not yet applied the update to his device. The exploit was a “zero-click” vulnerability, allowing the spyware to infiltrate and extract data without any action from him.
This vulnerability took advantage of a previously recognized flaw in Apple’s home software used in iPhones, allowing the spyware to access personal data from Kouloglou’s phone without his knowledge, including text messages, location details, and photos.
The hacking incident in October 2022 coincided with intensive discussions conducted via email and text throughout October and November 2022, leading up to the draft of an initial report concerning spyware misuse in Cyprus, Greece, Hungary, Poland, and Spain.
Moreover, the hack occurred right when Kouloglou was in the hospital for a scheduled surgery, potentially enabling the spyware operators to intercept surrounding conversations about his healthcare and discussions with visitors.
Months later, on March 6 and 7, Citizen Lab observed that Kouloglou’s phone was compromised again by the same Pegasus operator while he was traveling from Athens to Brussels, during a period of committee hearings and just months before the committee was set to finalize its written draft report.
In a phone call, Kouloglou mentioned to TechCrunch that he was uncertain as to why he was specifically targeted, but suspected it was linked to his role in the European Parliament’s committee investigating Pegasus abuses.
He expressed outrage upon discovering the hack, stating, “You realize that all of your personal data [was taken] — not just professional exchanges or messages with ministers, but also the very private moments, both joyful and sorrowful.”
Kouloglou announced his intention to sue NSO Group, the Israeli company behind the spyware. NSO has largely been barred from operating in the United States following a Biden-era executive order prohibiting the use of spyware that violates human rights.
The spyware manufacturer confirmed last year that an unnamed American investment group had invested tens of millions of dollars into the company, likely as part of efforts to restore NSO’s tarnished reputation associated with human rights violations.
Kouloglou stated that he is sharing his experience publicly “for democracy, human rights, and the fight against corruption.”
“Corruption concerns everybody,” he emphasized.
When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.


