Citizen Lab found that former European Parliament member Stelios Kouloglou’s phone was infected multiple times with NSO Group’s Pegasus spyware while he served on the Parliament’s PEGA committee investigating misuse of commercial spyware. The report says infections occurred in October 2022 and March 2023 and links them to the same Pegasus operator behind earlier targeting of Russian- and Belarusian-speaking journalists and opposition figures, based in part on shared targeting infrastructure and email lures.
2026.07.06
97% relevant
This article advances the same underlying event by adding the policy and accountability response: Amnesty and other civil-liberties groups are urging the EU to investigate who infected Kouloglou's iPhone, explain why PEGA Committee recommendations from May 2023 have not been implemented, and reform the EU Dual-Use Regulation governing spyware exports.
Amina Khan
2026.07.06
95% relevant
This is a direct follow-up to the same Pegasus infection of Stelios Kouloglou. It adds Access Now's call for an EU investigation and highlights Citizen Lab's finding that one infection was launched from the same Apple ID infrastructure previously tied to Pegasus targeting of Russian- and Belarusian-speaking exiled journalists in the EU.
SecurityWeek News
2026.07.03
93% relevant
This source summarizes the same Pegasus targeting of former MEP Stelios Kouloglou and adds the contextual detail that he was targeted while serving on the PEGA committee investigating Pegasus abuse, with no evidence cited of Greek government involvement.
info@thehackernews.com (The Hacker News)
2026.07.03
98% relevant
This article appears to report the same underlying event: Pegasus spyware was used to hack European Parliament member Stelios Kouloglou while he was involved in oversight of spyware abuses, reinforcing and likely summarizing Citizen Lab's findings for the same case.
2026.07.03
100% relevant
The article establishes a distinct concrete event: forensic confirmation that Pegasus infected a specific European Parliament member during the PEGA committee's spyware investigation, with new cross-linking to a broader Pegasus operator campaign.