A prominent member of the European Parliament faced repeated cyberattacks with sophisticated hacking software while leading an official inquiry into surveillance abuses, as reported by The Guardian.
Researchers from the Citizen Lab at the University of Toronto uncovered that the mobile device belonging to Stelios Kouloglou was targeted multiple times using Pegasus spyware, which is manufactured by the Israel-based NSO Group.
Although investigators could not link the cyber espionage to a specific government entity, the technical indicators aligned closely with an earlier hacking campaign directed at exiled Russian and Belarusian journalists operating within Europe.
"When you realise your private life is scrutinised by very bad people, you become angry," Kouloglou, who is also a journalist and left parliament in 2024, said in an interview.
"It's a big issue having to do with corruption, justice and democracy."
The surveillance targeted Kouloglou due to his active role in the special European parliamentary committee known as Pega, which lawmakers established in March 2022 following global revelations regarding the Pegasus Project.
The initial infection occurred around October 21, 2022, a timeframe characterized by intense committee deliberations and the formulation of Pega's preliminary findings.
NSO did not respond to a request for comment.
This initial breach took place while Kouloglou was hospitalized for elective surgery, where he received a visit from Greek investigative journalist Thanasis Koukakis.
Koukakis had been reporting on private mercenary spyware operations following the "Greek Watergate" scandal, a political crisis involving the unlawful monitoring of over 80 public figures, journalists, and military officials in Greece.
A second cyberattack struck Kouloglou's phone between March 6 and March 7, 2023, coinciding with final report drafts and his travel from Athens to Brussels.
Citizen Lab noted that this represents the first documented case of a Pega committee member being compromised by the very technology they were tasked to investigate.
John Scott-Railton, a senior researcher at Citizen Lab, emphasized that institutional inaction has left European lawmakers exposed to ongoing digital threats.
"This case is the ultimate irony of Europe's spyware crisis. Someone on the very committee tasked with investigating Pegasus gets infected by it.
And what has happened since? The parliament looks the other way when new European spyware abuses emerge."
"I can tell you how the next chapter will go: more hacked parliamentarians.
In fact, I suspect there are members voting and attending high-level meetings with no idea that their phone has been turned into a spy in their pocket."
Technical analysis revealed the operator utilized a distinct Apple ID email across the attacks, indicating a single government client with operational licenses covering both Belgium and Greece.
Researchers revealed NSO Group spyware targeted Greek MEP Stelios Kouloglou during his investigation into European surveillance abuses.