Skip to main content
TECH_SCIENCE10 / 18 · story of the day4 min · 766 words · 19 sources

Pegasus spyware infects its EU investigator

Written by AIto brief AI · 4 July 2026, 03:50
How it was written

The investigation moves forward, even as the room’s secrets are peeled away.

Image composition · tobrief
the text · 4 min read

Stelios Kouloglou was supposed to be the one asking questions. A Greek journalist turned MEP, he sat on PEGA, the European Parliament's inquiry committee set up to investigate how EU governments were turning commercial spyware on their own citizens. The committee could summon officials, demand documents, and draft recommendations. It could not compel cooperation from national intelligence services. That gap would become the story.

Around October 2022, according to a new Citizen Lab report, Kouloglou's iPhone was silently broken into by the very tool he was investigating: NSO Group's Pegasus (The Guardian, Le Monde). The infection happened again in March 2023, during the committee's most intense drafting phase. At least one attack was zero-click: the spyware exploited a hidden flaw in Apple's software that the company had not yet discovered or patched, entering the device without the owner tapping anything (The Straits Times).

Europe can often prove a phone was infected. It still struggles to prove who gave the order. That gap is the subject of this story.

What an infected phone means for a committee

Think of encrypted messaging like a sealed envelope: apps like Signal protect the letter while it travels. Pegasus does not try to intercept the envelope in transit. It sits inside the room where the letter is read, after it has been opened (Indian Express). Once active, the spyware can access messages, contacts, location data, and can switch on the microphone or camera (Al Jazeera).

During the infection period, Kouloglou was coordinating committee work between Athens and Brussels, communicating with colleagues and sources, handling draft reports (NDTV). Follow the chain: phone compromised means contact lists exposed, which means the committee's network of whistleblowers and witnesses becomes visible to the operator. Draft reports exposed means whoever ordered the surveillance could read the committee's conclusions before they were published. Public reporting has not shown what, if anything, was copied from the phone (The Guardian). But if the body investigating spyware cannot keep its own members' devices clean, committee independence is weakened at its root.

Citizen Lab connected the operation to a previously documented Pegasus campaign targeting exiled Russian- and Belarusian-speaking journalists and activists in Europe, widening the case beyond a Greek domestic frame (The Times of Israel). The researchers did not attribute the hack to any specific government. No evidence points to Greece as the operator (Al Jazeera).

And that is the structural problem. Infection is provable. Attribution requires evidence that almost never surfaces voluntarily: government purchase orders, server logs, or judicial warrants that intelligence services are under no obligation to share with foreign committees.

Spain and Hungary show what comes after discovery

Barcelona's appeals court recently reopened the Pegasus case involving Catalan politicians, ordering fresh requests for information from Spain's intelligence service after a judge had sat on an appeal for two years (elDiario.es). Confirmed infection, contested attribution, glacial courts.

Hungary offers a different lesson. A senior Fidesz MP publicly acknowledged the state had acquired Pegasus, and the data-protection authority investigated, but concluded it found no unlawful conduct. Much of its reasoning remains classified (Portfolio). Formal review without public transparency produces formal closure without public answers.

Both cases prove the same thing Kouloglou's infection now exposes at EU level: the technical forensics work. The political accountability does not.

The tools that exist and the one that doesn't

The European Parliament says it has offered spyware-screening support to MEPs since 2022 (European Parliament via upday). The EU has passed the Cyber Resilience Act, which sets safety standards for connected products, meaning rules for making software and devices harder to break into (European Commission). Civil society groups have argued that spyware vendors should face corporate responsibility obligations when their tools are used against journalists and lawmakers (Business & Human Rights Resource Centre).

These tools patch the edges of the problem. Screening is reactive: it finds infections after the fact. Product-safety laws make devices harder to hack, but Pegasus is not an accident of bad engineering. It is deliberate misuse by authorised buyers. Export controls assume the exporting country enforces them. None of these reveal who placed the order.

Kouloglou's lawyer has announced legal action in Greece and abroad (in.gr). MEPs from several political groups have demanded binding EU action against illegal spyware use (The Times of Israel).

What would actually close the gap? Independent forensic labs with cross-border authority. Enforceable transparency rules that force spyware vendors to log which government bought which licence. Judicial cooperation that moves in months, not years. Until some version of that exists, the pattern will repeat. The investigator becomes the target. And the investigation proceeds without knowing who is reading along.

How was this article?

Help us get better

Details about this article
Model:
claude-opus-4-6
Generated:
7/4/2026, 3:34:15 AM
Pipeline run:
eu_pipeline_20260704_015011
Watermark:
SynthID (Google's invisible watermark)
Human review:
None before publication
Learn more about our methodology