In a chilling revelation that underscores the fragility of digital privacy even at the highest levels of governance, Stelios Kouloglou, a former Member of the European Parliament (MEP) and investigative journalist, has been identified as a target of high-level state surveillance. Despite never clicking on a suspicious link or falling for common phishing traps, Kouloglou’s iPhone was successfully breached by Pegasus, the notorious spyware developed by the Israeli firm NSO Group. The discovery, confirmed by the University of Toronto’s Citizen Lab, is particularly incendiary: Kouloglou was a key member of the European Parliament’s PEGA Committee, the body specifically tasked with investigating the illicit use of commercial spyware against journalists, activists, and political figures across the European Union. The finding suggests that those attempting to hold the surveillance industry accountable were themselves being watched, potentially compromising sensitive parliamentary documents and confidential deliberations. The Pegasus Paradox: Investigating the Spies The Pegasus Project, an international investigative collaboration that shook the foundations of global cybersecurity in 2021, exposed how governments worldwide were utilizing NSO Group’s software to turn personal smartphones into 24/7 surveillance devices. In response, the European Parliament established the Committee of Inquiry to investigate the use of Pegasus and equivalent surveillance spyware (PEGA). Stelios Kouloglou, a seasoned investigative journalist who served in the European Parliament from 2015 to 2024, became a deputy member of this committee in 2022. His role was critical; he was tasked with unearthing the "European dimension" of the scandal, identifying which member states were abusing their power, and drafting recommendations to prevent future human rights violations. Ironically, his work to expose the dark underbelly of the surveillance trade made him a primary target for those very systems. Chronology of a Digital Breach According to the forensic analysis released by Citizen Lab, Kouloglou’s device was compromised on two distinct occasions, both of which coincided with pivotal moments in his committee work. The First Infiltration: October 2022 The first infection occurred on October 21, 2022. At this time, the PEGA committee was in the midst of a "particularly intense" phase of its investigation, drafting a preliminary report on the various surveillance cases they had uncovered. The breach suggests that the perpetrators were not merely collecting data for general intelligence, but were actively seeking to monitor the progress, internal debates, and potential findings of the parliamentary inquiry. The Second Infiltration: March 2023 The second attack took place on March 6 and 7, 2023. During this period, Kouloglou was deeply involved in the finalization of the committee’s concluding report—a document that was expected to hold governments accountable for their illicit use of spyware. The fact that the spyware was deployed at the height of the investigation is a testament to the sophistication and audacity of the threat actor. It implies a "zero-click" capability—a method of infection where the target does not need to interact with a malicious link or file to become compromised. In these scenarios, the spyware exploits vulnerabilities in the device’s operating system to gain total control, granting the attacker access to emails, encrypted messages, photos, microphone, and camera. Supporting Data: Connecting the Dots Citizen Lab’s report provides crucial technical context that elevates this incident from a random hack to a coordinated campaign. While the researchers cannot attribute the attack to a specific NSO Group client with absolute certainty, they have established a strong link between these attacks and those carried out against seven other journalists and activists from Russia and Belarus. A Common Digital Fingerprint The forensic evidence links the attacks on Kouloglou to the same Apple ID and infrastructure used in the surveillance of these dissidents. The geographical footprint of the infections—occurring in both Belgium and Greece—suggests that the perpetrators were operating under an NSO Group license that covered multiple European jurisdictions. This raises an uncomfortable question: which state entity, or entity with state-level resources, had the authority to operate within these borders and the motive to silence or observe an EU investigator? The Broader Implications for Democracy The implications of a compromised MEP are far-reaching. When a lawmaker working on a legislative inquiry is under surveillance, the integrity of the entire democratic process is called into question. The "Chilling Effect" The fundamental danger of state-sponsored spyware is its "chilling effect." If parliamentarians, journalists, and human rights defenders know that their communications are being intercepted, they are less likely to pursue sensitive lines of inquiry, less likely to meet with whistleblowers, and less likely to engage in the candid debates necessary for legislative oversight. The compromise of Kouloglou’s phone effectively turns the investigator into a source of intelligence for the very people he was tasked with investigating. The Stagnation of Reform Perhaps most disheartening is the lack of institutional urgency following the discovery. The recommendations put forth by the PEGA Committee have largely been left to gather dust. Despite the clear evidence of widespread spyware abuse within the EU, significant legislative action has been sluggish. The political climate remains polarized. Even as the scandal involving Pegasus continues to unfold, new threats have emerged. Reports of other spyware providers, such as Paragon, being used against journalists in Europe highlight that the market for invasive surveillance is growing, not shrinking. Furthermore, in Germany, lawmakers have engaged in contentious debates regarding a bill that would grant the Federal Police the authority to use similar Trojan software for investigations. The normalization of these tools for "law enforcement" risks creating a permanent ecosystem of surveillance that can be easily repurposed for political suppression. Official Responses and Calls to Action Citizen Lab has issued a stern call to action for the European Parliament and its member states. They are urging all former members and staff of the PEGA Committee to undergo comprehensive forensic analysis of their mobile devices. The organization argues that it is the responsibility of the EU and national parliaments to conduct thorough investigations into attacks on their members and the integrity of their parliamentary processes. To date, there has been a notable silence from many of the European institutions that should be most concerned. There has been no widespread demand for a new, independent audit of parliamentary devices, nor has there been a surge in cross-border cooperation to identify the specific license holders involved in the attacks on Kouloglou. Conclusion: The Path Forward The hacking of Stelios Kouloglou is not just a breach of one man’s privacy; it is an assault on the European Union’s institutional autonomy. It exposes the reality that in the age of commercial spyware, no one—not even those writing the laws—is safe from the prying eyes of hidden actors. If the EU is to maintain its credibility as a defender of human rights and the rule of law, it must move beyond investigative committees and into the realm of enforcement. This includes: Mandatory Forensic Audits: Providing resources for all high-risk public officials to have their devices regularly screened by independent security firms. Stricter Export Controls: Tightening regulations on the sale of surveillance technology to ensure that European companies and institutions are not contributing to an industry that actively undermines democracy. Accountability for NSO Group: Increasing legal pressure on companies like NSO Group to disclose their clients and to be held liable for the misuse of their software. The case of Stelios Kouloglou is a stark reminder that digital security is not a luxury, but a requirement for a functional democracy. Without urgent action, the tools designed to protect the public will continue to be used to dismantle it, one notification at a time. Post navigation The Cost of Consumption: Germany’s Radical Push for "Sin Taxes" to Save the Healthcare System The End of the Line: Which Samsung Galaxy Devices Will Miss Out on Android 17 and One UI 9?