Skip to main content
TECH_SCIENCE10 / 18 · story of the day4 min · 915 words · 19 sources

Pegasus Hits Its EU Investigator

Written by AIto brief AI · 4 ta’ Lulju 2026, 03:50
How it was written

The investigation moves forward, even as the room’s secrets are peeled away.

Image composition · tobrief
the text · 4 min read

Stelios Kouloglou was meant to be asking the questions. A Greek journalist who became an MEP, he sat on PEGA, the European Parliament committee created to examine how EU governments were using commercial spyware against their own citizens. It could call officials, request documents and write recommendations. It could not force national intelligence services to open their files. That missing power is where the whole story sits.

Around October 2022, according to a new Citizen Lab report, Kouloglou's iPhone was silently infected by the same tool he was investigating: NSO Group's Pegasus (The Guardian, Le Monde). It happened again in March 2023, when the committee was deep in the drafting of its report. At least one attack was zero-click: Pegasus used a hidden flaw in Apple's software, not yet found or fixed by the company, to enter the phone without Kouloglou pressing a link or opening a file (The Straits Times).

Europe is getting better at proving that a phone was infected. It is still poor at proving who ordered it. That gap matters in Malta too, where surveillance, state secrecy and institutional accountability are not abstract Brussels themes.

What an infected phone means for a committee

Encrypted messaging is often described as a sealed envelope: apps such as Signal protect the message while it travels. Pegasus does not need to intercept the envelope on the way. It enters the room where the envelope is opened (Indian Express). Once active, it can read messages, access contacts and location data, and switch on the microphone or camera (Al Jazeera).

During the infection period, Kouloglou was coordinating committee work between Athens and Brussels, speaking to colleagues and sources, and handling draft reports (NDTV). If the phone was compromised, contact lists may have been exposed. That would make the committee's network of whistleblowers and witnesses visible to whoever operated the spyware. If draft reports were exposed, the person or authority behind the surveillance could have seen the committee's conclusions before publication.

Public reporting has not shown what, if anything, was copied from the phone (The Guardian). But the institutional damage does not depend only on proving extraction. If the body investigating spyware cannot protect the devices of its own members, its independence is weakened at the point where it most needs confidence.

Citizen Lab linked the operation to a previously documented Pegasus campaign against exiled Russian- and Belarusian-speaking journalists and activists in Europe, which takes the case beyond a purely Greek domestic frame (The Times of Israel). The researchers did not identify any specific government as the operator. No evidence points to Greece as the operator (Al Jazeera).

That is the structural problem. Infection can be proved. Attribution usually requires evidence that intelligence services do not hand over willingly: purchase orders, server logs, judicial warrants, internal authorisations. A European Parliament committee can ask. It cannot raid an intelligence archive in Athens, Madrid or Budapest.

Spain and Hungary show what comes after discovery

Barcelona's appeals court recently reopened the Pegasus case involving Catalan politicians, ordering fresh requests for information from Spain's intelligence service after a judge had sat on an appeal for two years (elDiario.es). The pattern is familiar: confirmed infection, disputed attribution, courts that move too slowly for political accountability.

Hungary offers another version. A senior Fidesz MP publicly acknowledged that the state had acquired Pegasus. The data-protection authority investigated, then said it had found no unlawful conduct. Much of its reasoning remains classified (Portfolio). A formal review without public transparency produces closure on paper, not answers.

Both cases show what Kouloglou's infection now exposes at EU level. The technical forensics can work. The political accountability often does not.

The tools that exist and the one that doesn't

The European Parliament says it has offered spyware-screening support to MEPs since 2022 (European Parliament via upday). The EU has passed the Cyber Resilience Act, which sets safety standards for connected products, making software and devices harder to break into (European Commission). Civil society groups have argued that spyware vendors should face corporate responsibility obligations when their tools are used against journalists and lawmakers (Business & Human Rights Resource Centre).

These measures deal with the edges of the problem. Screening is reactive: it finds infections after the fact. Product-safety rules make devices harder to hack, but Pegasus is not a normal software failure. It is a tool sold to authorised buyers and then used in ways that democratic systems struggle to police. Export controls depend on the exporting country enforcing them. None of these mechanisms tells the public who placed the order.

For Maltese readers, the weakness is easy to recognise. After Daphne Caruana Galizia's assassination and the public inquiry that found the state bore responsibility, the question of who can investigate power when power controls key information is not theoretical. The same logic runs through spyware cases: if the evidence needed for accountability sits inside the institution being questioned, oversight becomes a test of political will, not just legal design.

Kouloglou's lawyer has announced legal action in Greece and abroad (in.gr). MEPs from several political groups have demanded binding EU action against illegal spyware use (The Times of Israel).

What would close the gap is not another statement of concern. It would require independent forensic labs with cross-border authority, transparency rules forcing spyware vendors to log which government bought which licence, and judicial cooperation that moves in months rather than years. Until then, the pattern is clear. The investigator becomes the target. The investigation continues, without knowing who is reading along.

How was this article?

Help us get better

Details about this article
Model:
claude-opus-4-6
Generated:
7/4/2026, 3:34:15 AM
Pipeline run:
eu_pipeline_20260704_015011
Watermark:
SynthID (Google's invisible watermark)
Human review:
None before publication
Learn more about our methodology