A Shocking Revelation: Spyware Oversights Exposed Within European Parliament’s Own Ranks
In a disturbing turn of events, researchers from the University of Toronto’s Citizen Lab have revealed that one of the members of the European Parliament’s PEGA Committee was infected with NSO Group’s Pegasus spyware. Stelios Kouloglou, a Greek journalist and substitute member of the committee, had his phone compromised not once but twice by the malicious software.
The investigation, published last Friday, sheds light on how easily spyware can infect even those tasked with investigating its misuse. The Citizen Lab team found evidence of Pegasus infections on Kouloglou’s phone in October 2022 and March 2023, coinciding with critical moments in the committee’s work on their final report.
Kouloglou himself was surprised to learn that his phone had been compromised, having run security tests before joining the committee. However, for another member of the PEGA Committee, Hannah Neumann from Germany, this incident was not entirely unexpected. She noted that many members were anticipating potential hacks during the committee’s work and acknowledged that the European Parliament’s internal IT security measures may not have been sufficient to prevent such an event.
The irony of a PEGA Committee member being targeted with Pegasus is stark. Ron Deibert, founder and director of Citizen Lab, pointed out that someone likely wanted to breach parliamentary privilege and uncover sensitive information about the committee’s work. This case highlights the risks posed by unregulated spyware industries to democratic processes.
Kouloglou plans to pursue legal action against NSO Group, which has not responded to a request for comment. Neumann emphasized the importance of regularly checking devices and taking steps to prevent such incidents in the future. She also underscored the need for member states and the European Commission to implement the PEGA Committee’s recommendations, which were drafted but never enacted.
The PEGA Committee was established to investigate spyware abuses across the European Union following revelations about government use of NSO Group’s Pegasus technology. The fact that one of their own members fell victim to this very spyware raises questions about the effectiveness of existing measures and underscores the need for greater vigilance in protecting parliamentary privilege.
For security-conscious individuals, including lawmakers, this incident serves as a stark reminder of the importance of robust cybersecurity practices. Regular device checks, secure communication channels, and adherence to best practices can help prevent such incidents from occurring in the future.
Source: CyberScoop — 2026-07-03