A shocking report from the Citizen Lab has unveiled that Stelios Kouloglou, a former Member of the European Parliament (MEP), had his mobile device repeatedly compromised with the infamous Pegasus spyware. This occurred during his tenure on a parliamentary committee specifically tasked with investigating the widespread abuse of commercial surveillance tools across the European Union, casting a stark shadow over the integrity of legislative oversight and democratic processes within the bloc. The revelation underscores the audacity and pervasive nature of sophisticated state-sponsored hacking operations, even when directed at individuals actively working to expose such illicit activities.
The Unsettling Discovery: A Legislator Under Surveillance
The forensic analysis, meticulously conducted by the Citizen Lab – a renowned interdisciplinary laboratory based at the University of Toronto’s Munk School of Global Affairs & Public Policy – confirmed multiple instances of Pegasus infection on Kouloglou’s device. According to researchers John Scott-Railton, Bill Marczak, Bahr Abdul Razzak, Kate Pundyk, Siena Anstis, and Ron Deibert, the attackers gained potential access to highly confidential documents and sensitive deliberations of the committee. This access could have profoundly compromised the committee’s work and exposed strategies for countering commercial spyware, effectively turning the investigator into the investigated.
The Citizen Lab’s findings, published in a detailed report, highlight the severe implications for privacy, human rights, and the rule of law. While the report has not attributed the infections to a specific government, nor is there direct evidence linking the Greek government to the activity, the Canadian research group identified a significant overlap between the initial infection and a prior campaign. This earlier operation notoriously targeted Russian and Belarusian-speaking exiled journalists and activists residing in Europe, suggesting a sophisticated Pegasus customer with authorization to conduct surveillance across multiple European jurisdictions is likely responsible.
The PEGA Committee: Investigating the Unseen Threat
Stelios Kouloglou served as a crucial member of the European Parliament’s "Committee of Inquiry to investigate the use of Pegasus and equivalent surveillance spyware," widely known as the PEGA Committee, from March 24, 2022, to July 18, 2023. This specialized committee was formally established on March 10, 2022, with a critical mandate: to thoroughly investigate alleged misuses of commercial spyware offerings under EU law. Its primary objective was to gather comprehensive information on the extent to which member states and other countries were deploying such intrusive tools in contravention of the region’s enshrined rights and freedoms. The very existence of this committee was a direct response to mounting evidence and public outcry over the rampant use of Pegasus and similar tools against journalists, opposition figures, lawyers, and human rights defenders globally and within the EU.
The irony of a PEGA Committee member falling victim to the very technology he was tasked to investigate is not lost on observers. It serves as a chilling testament to the formidable capabilities of these surveillance tools and the brazenness of their operators. The committee’s work, which involved extensive hearings, fact-finding missions, and the drafting of policy recommendations, aimed to establish robust safeguards against such abuses. The hacking of one of its members suggests an attempt to undermine these efforts or gather intelligence on the committee’s internal workings and conclusions.
A Chronology of Compromise and Critical Junctures
The forensic analysis of artifacts collected from Kouloglou’s iPhone in May 2026 revealed a precise timeline of compromise. The device was first infected with Pegasus spyware on or around October 21, 2022. A second wave of infections was observed on March 6 and 7, 2023. These dates are particularly significant when viewed against Kouloglou’s activities and the PEGA Committee’s schedule.

The technical specifics of the initial attack provide critical insights. On October 21, 2022, at approximately 10:16 AM, a lookup for a HomeKit email address, "rauharepo888[@]gmail.com," was detected. Merely two minutes later, a Pegasus process began utilizing mobile data, indicating successful exploitation. The Citizen Lab assessed that a sophisticated zero-click exploit within Apple’s smart home software, internally codenamed PWNYOURHOME, was leveraged to deliver the spyware. This vulnerability allowed the attackers to gain control of the device without any interaction from the user, highlighting the advanced nature of Pegasus and its exploit chain. Apple subsequently patched this critical vulnerability in iOS 16.3.1, but Kouloglou’s device was running iOS 15.5 at both times of the observed infections. The subsequent Pegasus activity in March 2023 is also believed to have weaponized the same exploit, suggesting a consistent attack vector.
Further analysis of Kouloglou’s phone revealed that he received Apple threat notifications regarding mercenary spyware targeting on three separate occasions: March 2, 2023; August 29, 2023; and April 10, 2024. These notifications, issued by Apple to users they believe have been targeted by state-sponsored attackers, served as crucial alerts, although they came after the initial compromises.
The timing of the first successful hack in October 2022 holds particular resonance. During this period, Kouloglou was admitted to a hospital for elective surgery. Notably, he received a visit from Greek investigative journalist Thanasis Koukakis, himself a prominent victim of Intellexa’s Predator spyware. Koukakis had previously testified before the PEGA Committee just a month prior to this hospital visit, sharing his harrowing experience of being targeted. The convergence of these events raises serious questions about the attackers’ motives and their potential interest in Koukakis’s interactions with a key committee member.
The second infection in March 2023 also aligns with a critical phase of the PEGA Committee’s work. This period coincided with intense internal discussions related to the final drafting process of the committee’s report, followed by a series of pivotal PEGA hearings. The incident occurred merely two months before the official adoption of the first PEGA Committee report, a landmark document detailing the committee’s findings and recommendations. The timing strongly suggests an intelligence-gathering operation aimed at influencing or preempting the committee’s conclusions.
This case marks an unprecedented moment: the first publicly identified instance of a PEGA Committee member becoming a direct victim of Pegasus spyware while actively serving on the committee. It elevates the issue of commercial spyware abuse from a theoretical threat to a direct assault on the legislative body itself.
Pegasus Spyware: A Tool of Unchecked Power
Pegasus, developed by the Israeli NSO Group, is widely regarded as one of the most powerful and invasive pieces of spyware ever created. Marketed ostensibly to governments for combating serious crimes like terrorism and child sexual abuse, its actual use has frequently deviated into targeting journalists, human rights defenders, lawyers, politicians, and dissidents. Once installed, Pegasus can transform a smartphone into a comprehensive surveillance device, capable of accessing messages, calls, contacts, calendar information, emails, and even remotely activating the device’s camera and microphone without the user’s knowledge. Its zero-click capabilities mean it can infect a device without any interaction from the target, making it incredibly difficult to detect and defend against.
The NSO Group maintains that its technology is sold only to vetted government clients and that it includes human rights safeguards. However, numerous investigations by organizations like the Citizen Lab and Amnesty International have consistently documented widespread abuse, leading to significant international condemnation, sanctions against NSO Group, and legal challenges. The company’s licensing model, which often allows clients to deploy Pegasus in multiple jurisdictions, further complicates attribution and accountability, as demonstrated in Kouloglou’s case.
Attribution Challenges and the "[email protected]" Link
The challenge of attributing the attacks on Kouloglou to a specific state actor remains. However, the Citizen Lab’s identification of the recurring email address "rauharepo888[@]gmail.com" provides a crucial investigative lead. This email address was also observed in the previous campaign targeting Russian and Belarusian-speaking independent journalists and opposition activists in Europe. The Citizen Lab researchers believe that such specific email addresses are unique to particular Pegasus operators. While they cannot definitively state whether the second infection in 2023 was linked to the same operator or a different one, the repeated use of this unique identifier strongly suggests a common origin for at least the first attack.

This connection implies that the Pegasus customer responsible likely possessed a license enabling infections across multiple EU jurisdictions. This significantly narrows the list of potential Pegasus operators, pointing towards a sophisticated actor with broad operational reach. The inherent difficulty in pinpointing the exact government client underscores the opaque nature of the commercial surveillance industry and the need for greater transparency and accountability.
Broader Implications for European Democracy and Digital Rights
The targeting of an MEP, especially one engaged in investigating surveillance abuses, carries profound implications for the integrity of democratic institutions and the protection of fundamental rights within the European Union.
Firstly, it represents a direct assault on the legislative process. If those tasked with creating policies to safeguard citizens from surveillance are themselves vulnerable, it erodes public trust and undermines the efficacy of democratic oversight.
Secondly, it highlights the continued and pervasive threat posed by commercial spyware. Despite numerous exposés and calls for stricter regulation, these powerful tools continue to be deployed against individuals who pose no threat of serious crime but are engaged in legitimate political, journalistic, or human rights work.
Thirdly, the case reinforces concerns about the rule of law and national sovereignty. If a Pegasus customer, potentially a foreign government or even another EU member state, can operate with impunity across multiple European countries to surveil legislators, it challenges the very foundation of European cooperation and mutual trust.
A Pattern of Sophisticated Surveillance: Echoes of Other Citizen Lab Findings
Kouloglou’s case is not an isolated incident but rather fits into a broader pattern of sophisticated digital surveillance campaigns uncovered by the Citizen Lab. Just days prior to this report, the Citizen Lab revealed that Russian authorities had used Cellebrite’s UFED forensic tools to break into the iPhone of detained opposition activist Andrey Pivovarov in June 2021. This occurred three months after Cellebrite publicly announced it would cease offering its tools and services to Russia and Belarus. The authorities systematically searched Pivovarov’s devices for key organizations and contacts, including high-profile opposition figures, raising concerns about corporate responsibility and the flow of surveillance technology to authoritarian regimes. The subsequent targeting of some of these individuals, like Anastasiya Burakova, by the Russian hacking group COLDRIVER, suggests that forensic analysis tools might facilitate further reconnaissance and targeting.
Furthermore, in April, the Citizen Lab uncovered two distinct, long-running spying campaigns that exploited well-known weaknesses in the global telecommunications infrastructure to track individuals’ locations. These attacks were particularly insidious as they did not require malware deployment, making them exceedingly stealthy and difficult to detect. One campaign employed special text messages with malicious hidden SMS commands to transform devices into "covert tracking beacons." The second relied on vulnerabilities in Signaling System No. 7 (SS7) and Diameter signaling protocols to track an individual’s whereabouts without ever needing access to their device.
These campaigns abused three specific telecom providers – 019Mobile, Airtel Jersey (part of Sure Group), and Tango Networks U.K. – which acted as "surveillance entry and transit points" within the telecommunications ecosystem. These providers allowed malicious traffic to flow through trusted signaling interconnections, granting threat actors access while masking their true identities. The Citizen Lab’s findings exposed how suspected commercial surveillance vendors exploit the global telecom interconnect ecosystem, leverage private operator networks, and conduct covert location tracking operations that can persist undetected for years. These broader revelations underscore the multi-faceted nature of modern surveillance, ranging from highly intrusive spyware like Pegasus to stealthy network-level tracking, all contributing to an increasingly precarious digital environment for individuals, especially those in positions of power or dissent.
The Path Forward: Regulation and Safeguards
The repeated targeting of Stelios Kouloglou, a legislator investigating surveillance abuse, serves as a powerful call to action for the European Union and the international community. It necessitates a renewed focus on robust regulatory frameworks for commercial spyware, stricter export controls, and enhanced accountability mechanisms for both vendors and user states. The EU’s proposed European Media Freedom Act and other digital legislation offer potential avenues for strengthening protections, but their effective implementation and enforcement will be critical.
Moreover, the incident highlights the urgent need for enhanced cybersecurity measures for public officials and institutions. As surveillance capabilities become more sophisticated, so too must the defenses designed to protect democratic processes and the individuals upholding them. Without decisive action, the chilling effect of such pervasive surveillance risks undermining trust, stifling dissent, and ultimately eroding the very foundations of open and democratic societies.
