Spyware Targeted EU Lawmaker Investigating Pegasus Abuses, New Research Shows

While investigators could not conclusively identify which government deployed the spyware, they found technical overlaps — including a distinctive Apple ID used across the operations — linking the attacks on Kouloglou to a separate campaign against seven Russian and Belarusian journalists and activists living in exile in Europe. Researchers believe the operator responsible likely held licenses to use Pegasus in both Belgium and Greece.

Citizen Lab findings reveal former Greek MEP Stelios Kouloglou’s phone was compromised while he served on the European Parliament’s committee probing spyware misuse

A new investigation from the University of Toronto’s Citizen Lab has found that NSO Group’s Pegasus spyware was used against a member of the European Parliament on multiple occasions while he sat on the very committee formed to investigate spyware abuse across Europe.

Citizen Lab researchers determined that the device belonging to Stelios Kouloglou, a Greek journalist and former MEP, was infiltrated twice during his tenure on the European Parliament’s PEGA committee. The first breach occurred in October 2022, roughly seven months after he joined the committee, during a period of intense activity as members drafted their first report. A second breach followed in March 2023, coinciding with the finalization of that report and with Kouloglou’s travel from Athens to Brussels.

While investigators could not conclusively identify which government deployed the spyware, they found technical overlaps — including a distinctive Apple ID used across the operations — linking the attacks on Kouloglou to a separate campaign against seven Russian and Belarusian journalists and activists living in exile in Europe. Researchers believe the operator responsible likely held licenses to use Pegasus in both Belgium and Greece.

The PEGA committee was established in March 2022 in response to the Pegasus Project, a collaborative investigation led by the Guardian and international media partners that exposed how governments worldwide had used NSO Group’s spyware to target journalists, activists, and political figures — often far outside the software’s stated purpose of combating crime and terrorism.

Kouloglou’s hospitalization for elective surgery during the first attack added a striking detail to the case: he was visited there by Greek investigative journalist Thanasis Koukakis, himself a confirmed spyware target and a witness who had previously testified before the PEGA committee about Greece’s own surveillance scandal, dubbed the « Greek Watergate. »

Kouloglou, who left Parliament in 2024, described his reaction upon learning of the surveillance in personal terms, framing it as a matter of corruption, justice, and democratic accountability.

John Scott-Railton, a senior researcher at Citizen Lab, called the case a stark illustration of Europe’s ongoing failure to confront spyware abuse, warning that other members of Parliament may currently be under surveillance without their knowledge.

NSO Group did not respond to a request for comment on the findings.

This marks the first documented case of a PEGA committee member being targeted with spyware — underscoring, researchers say, the limited impact of the committee’s original recommendations and the continued exposure of European officials to surveillance tools originally marketed as safeguards against serious crime.

Source: The Guardian.

Visited 30 times, 1 visit(s) today

Soyez le premier à commenter

Laisser un commentaire

Votre adresse de messagerie ne sera pas publiée.


*