← BACK TO FEED
PegasusspywareEuropean ParliamentCitizen Labsurveillance

The MEP Investigating Pegasus Got Hacked With Pegasus. Yes, Really.

Citizen Lab researchers have revealed that Stelios Kouloglou, a former Member of the European Parliament who served on a committee investigating spyware abuse, had his iPhone repeatedly hacked with Pegasus spyware during his tenure in 2022 and 2023. Forensic analysis found the attacks exploited a zero-click vulnerability in Apple's HomeKit software, potentially giving attackers access to confidential documents and committee deliberations. While no specific government has been attributed responsibility, Citizen Lab identified an overlap with a separate campaign targeting Russian and Belarusian-speaking journalists and activists in Europe, suggesting a Pegasus operator licensed to conduct surveillance across multiple EU countries was likely responsible.

A new Citizen Lab report has confirmed what cynics might have predicted: a European Parliament member sitting on the committee set up to investigate Pegasus spyware abuse was himself being hacked with Pegasus spyware at the time.

Stelios Kouloglou, a Greek MEP who served on the PEGA Committee from March 2022 to July 2023, had his iPhone compromised on at least three occasions during that period. Forensic analysis of his device, conducted in May 2026, found infections on or around 21 October 2022, and again on 6 and 7 March 2023. Researchers from Citizen Lab concluded that attackers could have accessed confidential documents and internal committee deliberations during those windows.

The PEGA Committee was specifically established to probe how EU member states and third countries were deploying commercial spyware in ways that potentially violated European rights frameworks. The irony writes itself.

The attack vector appears to have been PWNYOURHOME, a zero-click exploit targeting Apple's HomeKit software. The researchers spotted a lookup for the email address [email protected] followed two minutes later by Pegasus process activity over mobile data. Apple patched the underlying vulnerability in iOS 16.3.1, though Kouloglou's phone was running iOS 15.5 at the time of both attack clusters.

Apple sent Kouloglou three mercenary spyware threat notifications: March 2023, August 2023, and April 2024. The fact that he received these alerts and that Citizen Lab later confirmed actual infections gives a reasonably clear picture of sustained, deliberate targeting.

Nobody has been formally attributed. Citizen Lab explicitly states there is no evidence pointing to the Greek government, though it did flag an overlap between the first infection and a separate campaign that targeted Russian and Belarusian-speaking journalists and opposition activists living in Europe. The same Gmail address, [email protected], appears in both cases. Since Citizen Lab treats these addresses as unique identifiers for specific Pegasus operators, the implication is that whoever compromised Kouloglou also had a hand in the journalist-targeting campaign.

The researchers further noted that NSO Group licenses Pegasus on a per-jurisdiction basis, meaning the responsible operator likely held a licence covering multiple EU countries. That narrows the suspect list considerably, even if no government has been named.

Timing adds another layer of interest. During the first infection in October 2022, Kouloglou was in hospital for surgery and had just been visited by Greek investigative journalist Thanasis Koukakis, who had himself been hacked with Intellexa's Predator spyware and had testified before the PEGA Committee a month earlier. The March 2023 infections coincided with the final drafting of the committee's first report. Whether that was coincidence or operational targeting is an open question, but it is not a reassuring one.

This is the first confirmed case of a PEGA Committee member being identified as a Pegasus target while actually serving on that committee.

The report arrives alongside two other notable Citizen Lab findings. The first revealed that Russian authorities used Cellebrite's UFED forensic tools to access the iPhone of opposition activist Andrey Pivovarov in June 2021, three months after Cellebrite publicly claimed it had cut off Russia and Belarus from its products. Authorities used the access to search for contacts associated with Open Russia and prominent opposition figures including Mikhail Khodorkovsky and Anastasiya Burakova. Burakova was subsequently targeted in a phishing campaign run by the Russian hacking group COLDRIVER, raising the obvious question of whether the Cellebrite-enabled data extraction fed directly into later targeting operations.

The second set of findings concerns telecom infrastructure abuse. Citizen Lab documented two separate surveillance campaigns exploiting structural weaknesses in global telecoms signalling, specifically SS7 and Diameter protocol vulnerabilities, to track individuals' locations without any malware needing to touch a target's device. One campaign used hidden SMS commands to silently convert phones into tracking beacons. Three telecoms providers, 019Mobile, Airtel Jersey, and Tango Networks UK, were identified as knowingly or unknowingly serving as entry and transit points for this traffic.

No malware. No obvious indicators of compromise. Just quiet, persistent location tracking that can apparently run undetected for years by routing through legitimate-looking telecoms interconnections.

Taken together, these reports sketch out a surveillance ecosystem that is considerably broader, better resourced, and more technically inventive than most public discourse acknowledges. Commercial spyware vendors, compromised telecom infrastructure, and forensic tools sold to authoritarian governments with promises that are apparently not worth the paper they are written on. The tools keep circulating. The targets keep expanding.

READ NEXT
Predatorgate Victims Sue Intellexa for €8M Over Greek Spyware ScandalPlay Ransomware Claims MyPillow Scalp — Lindell Says It's a Political Stitch-UpChina Is Bolting AI Onto Its Creaking Camera Grid. The Upgrade Is Significant.