Citizen Lab says Pegasus spyware infected European Parliament member Stelios Kouloglou during committee probe into spyware abuse

Citizen Lab found that former European Parliament member Stelios Kouloglou’s phone was infected multiple times with NSO Group’s Pegasus spyware while he served on the Parliament’s PEGA committee investigating misuse of commercial spyware. The report says infections occurred in October 2022 and March 2023 and links them to the same Pegasus operator behind earlier targeting of Russian- and Belarusian-speaking journalists and opposition figures, based in part on shared targeting infrastructure and email lures.
Why it matters: This is a high-impact surveillance story because it suggests a lawmaker investigating spyware abuse was himself secretly monitored. It raises urgent concerns for politicians, journalists, and activists using iPhones who may have received Apple threat notifications and should seek forensic review if they are at elevated risk.

Sources

EU urged to act after Pegasus infects phone of spyware inquiry MEP
2026.07.06 97% relevant
This article advances the same underlying event by adding the policy and accountability response: Amnesty and other civil-liberties groups are urging the EU to investigate who infected Kouloglou's iPhone, explain why PEGA Committee recommendations from May 2023 have not been implemented, and reform the EU Dual-Use Regulation governing spyware exports.
Same government, more victims: Access Now calls for an urgent investigation into hacking of MEP
Amina Khan 2026.07.06 95% relevant
This is a direct follow-up to the same Pegasus infection of Stelios Kouloglou. It adds Access Now's call for an EU investigation and highlights Citizen Lab's finding that one infection was launched from the same Apple ID infrastructure previously tied to Pegasus targeting of Russian- and Belarusian-speaking exiled journalists in the EU.
In Other News: Canadian Hacker Jailed, Open Source Zero-Days, Two Sentenced for ATM Jackpotting
SecurityWeek News 2026.07.03 93% relevant
This source summarizes the same Pegasus targeting of former MEP Stelios Kouloglou and adds the contextual detail that he was targeted while serving on the PEGA committee investigating Pegasus abuse, with no evidence cited of Greek government involvement.
European Parliament Member Investigating Spyware Was Hacked With Pegasus
info@thehackernews.com (The Hacker News) 2026.07.03 98% relevant
This article appears to report the same underlying event: Pegasus spyware was used to hack European Parliament member Stelios Kouloglou while he was involved in oversight of spyware abuses, reinforcing and likely summarizing Citizen Lab's findings for the same case.
Spyware found on phone of European Parliament member probing it
2026.07.03 100% relevant
The article establishes a distinct concrete event: forensic confirmation that Pegasus infected a specific European Parliament member during the PEGA committee's spyware investigation, with new cross-linking to a broader Pegasus operator campaign.
← Back to all stories