Pegasus Hit Its EU Investigator

The investigation moves forward, even as the room’s secrets are peeled away.
Cumadóireacht íomhá · tobriefStelios Kouloglou was meant to be the man asking the awkward questions. A Greek journalist who became an MEP, he sat on PEGA, the European Parliament committee created to examine how EU governments were using commercial spyware against their own citizens. The committee could call officials, seek documents and write recommendations. What it could not do was force national intelligence services to open their files. That missing power now sits at the centre of the story.
Around October 2022, according to a new report from Citizen Lab, Kouloglou's iPhone was quietly infected by the very system he was investigating: NSO Group's Pegasus (The Guardian, Le Monde). It happened again in March 2023, as the committee was deep in the drafting of its report. At least one attack was zero-click: the spyware used a hidden weakness in Apple's software, unknown and unpatched at the time, to enter the phone without Kouloglou tapping a link or opening a file (The Straits Times).
Europe is increasingly good at proving that a phone was infected. It remains poor at proving who ordered the infection. That is the gap this case exposes.
What an infected phone means for a committee
Encrypted messaging is often described as a sealed envelope: Signal and similar apps protect the message while it travels. Pegasus does not need to open the envelope on the road. It waits in the room where the letter is read, after the seal has already been broken (Indian Express). Once active, it can reach messages, contacts and location data, and can turn on a phone's microphone or camera (Al Jazeera).
During the period of infection, Kouloglou was moving between Athens and Brussels, speaking to colleagues and sources, and handling committee drafts (NDTV). The chain is straightforward. If the phone is compromised, contact lists may be exposed. If contact lists are exposed, the committee's web of witnesses and whistleblowers becomes visible to the operator. If draft reports are exposed, whoever ordered the surveillance may be able to read the committee's conclusions before the public does. Public reporting has not shown what, if anything, was taken from Kouloglou's phone (The Guardian). But a committee investigating spyware cannot be fully independent if its own members' devices are open to the people it is examining.
Citizen Lab linked the operation to an already documented Pegasus campaign against exiled Russian- and Belarusian-speaking journalists and activists in Europe, which moves the case beyond a purely Greek domestic affair (The Times of Israel). The researchers did not identify any government as the operator. No evidence points to Greece as the state behind the attack (Al Jazeera).
That is the structural problem. Infection can be proved through forensic analysis. Attribution usually needs material that rarely appears by accident: purchase orders, server logs, judicial warrants, or internal records from intelligence services that have little reason to share them with a foreign parliamentary committee.
Spain and Hungary show what comes after discovery
In Spain, Barcelona's appeals court recently reopened the Pegasus case involving Catalan politicians, ordering fresh requests for information from the Spanish intelligence service after a judge had let an appeal sit for two years (elDiario.es). The pattern is familiar: confirmed infection, disputed attribution, and courts moving at a pace that suits almost nobody except those who prefer delay.
Hungary offers another version of the same problem. A senior Fidesz MP publicly acknowledged that the state had acquired Pegasus. The data-protection authority investigated, but concluded it had found no unlawful conduct. Much of the reasoning remains classified (Portfolio). A formal review without public transparency can close a file without answering the public question.
Both cases point to the same lesson now visible in Kouloglou's case at EU level. The technical forensics can do their job. Political accountability often cannot.
The tools that exist and the one that doesn't
The European Parliament says it has offered spyware-screening support to MEPs since 2022 (European Parliament via upday). The EU has adopted the Cyber Resilience Act, which sets security standards for connected products, in effect rules intended to make software and devices harder to break into (European Commission). Civil society groups have also argued that spyware vendors should face corporate responsibility obligations when their products are used against journalists and lawmakers (Business & Human Rights Resource Centre).
Those measures deal with the edges of the problem. Screening is reactive: it tells you after the event that a phone was infected. Product-safety law may make devices harder to compromise, but Pegasus is not simply a failure of engineering. It is a product sold for deliberate use by authorised buyers. Export controls depend on the exporting country enforcing them. None of these mechanisms reveals who placed the order.
Kouloglou's lawyer has announced legal action in Greece and abroad (in.gr). MEPs from several political groups have called for binding EU action against illegal spyware use (The Times of Israel).
The missing lever is not hard to describe. Europe would need independent forensic labs with cross-border authority, transparency rules forcing spyware vendors to record which government bought which licence, and judicial cooperation that moves in months rather than years. Until something like that exists, the pattern is likely to repeat. The investigator becomes the target, and the investigation continues without knowing who is reading over its shoulder.
How was this article?
Help us get better
Help us get better
Details about this article
- Model:
- claude-opus-4-6
- Generated:
- 7/4/2026, 3:34:15 AM
- Pipeline run:
- eu_pipeline_20260704_015011
- Watermark:
- SynthID (Google's invisible watermark)
- Human review:
- None before publication