NSO and the European Parliament: Pegasus hit the very people investigating it
6 min read
In March 2022 the European Parliament set up a committee of inquiry into the misuse of Pegasus and equivalent spyware in Europe. Among its substitute members sat Stelios Kouloglou, a Greek MEP and former investigative journalist. While the committee was at work, his iPhone was infected — at least twice — with the very same Pegasus spyware made by NSO Group that committee had been set up to investigate. This was revealed on 2 July 2026 by a forensic analysis from the Citizen Lab at the University of Toronto: confirmation, after the $167 million verdict against NSO in the WhatsApp case, that not even those who write the rules on spyware are safe from it.
The facts, in order
- 24 March 2022 – 18 July 2023: Kouloglou sits as a substitute member of PEGA, the European Parliament’s Committee of Inquiry on Pegasus and equivalent spyware, set up after the 2021 Pegasus Project revelations and an illegal wiretapping case that emerged in Greece. The committee hears more than 215 people and visits Israel, Poland, Greece, Cyprus, Hungary and Spain.
- 21 October 2022: his iPhone, running iOS 15.5, is infected with Pegasus via a zero-click vulnerability in Apple’s HomeKit software — an attack requiring no action from the victim.
- 2 March 2023: Apple sends Kouloglou the first of three threat notifications about a “state-sponsored attacker”.
- 6-7 March 2023: four days after that notification, a second infection hits the device while Kouloglou is in Brussels.
- 15 June 2023: the European Parliament’s plenary adopts, with 411 votes in favour, 97 against and 37 abstentions, the PEGA committee’s final recommendation: common rules against spyware abuse, tighter export controls, safeguards for victims.
- 29 August 2023 and 10 April 2024: the second and third Apple notifications arrive, months after the last known infection.
- May 2026: Kouloglou asks the Citizen Lab to analyse his device.
- 2 July 2026: the Citizen Lab publishes the report “Espionage Against the European Parliament”: it confirms the infections, rules out — “no evidence” — Greek government involvement, and notes that the email infrastructure used overlaps with a campaign against exiled Russian and Belarusian journalists and activists in Europe. The responsible NSO customer was authorised to operate in multiple European countries, but remains unnamed.
- 6 July 2026: 48 civil society organisations and 3 independent experts — including Amnesty International and the Citizen Lab itself — sign a joint statement demanding an independent investigation, a response “without further delay” from the European Commission to the PEGA recommendations, and stricter enforcement of the EU Dual-Use Regulation (EU) 2021/821, with a fundamental rights impact assessment.
- The reactions: German MEP Hannah Neumann, a PEGA committee member, states that “spyware doesn’t make democracies safer”; Rand Hammoud of the Center for Democracy and Technology Europe describes it as a structural failure to control commercial surveillance. Kouloglou announces his intention to sue NSO Group.
- The non-responses: NSO Group does not comment. The European Commission does not respond. Apple confirms only that it has fixed the vulnerability flagged in the report.
Nobody disputes the technical facts: the infections are confirmed by an independent forensic lab, and the same indicators already appear in other European campaigns. The real issue lies elsewhere: an institution that has been investigating spyware for three years has still not managed to stop that spyware from hitting one of its own members.
Lesson one: those who oversee surveillance become a target for surveillance
This is not an isolated case. In 2023 the “Predator Files” had already revealed that even the President of the European Parliament, Roberta Metsola, had been targeted by the Predator spyware; four Catalan MEPs had been hit by Pegasus in earlier years. The Kouloglou case confirms a principle valid for any organisation with an oversight function — compliance, internal audit, relations with authorities, whistleblowing channels: whoever supervises a risk becomes, by that very fact, a higher-value target. The security of the devices used by people in these roles cannot be standard corporate security: it needs to be treated as critical infrastructure in its own right, precisely because it is the role, not just the content, that makes them targets. It is the same principle behind our approach to designing data and AI architectures for sensitive functions: start from who will be targeted, not only from what needs protecting.
Lesson two: a notification that arrives afterwards is not a defence, it’s a post-mortem
Apple warned Kouloglou three times. Always afterwards — and in the case of the second infection, the notification arrived just four days before the device was hit again. This is the structural limit of any alert system based on after-the-fact detection: useful for forensic reconstruction, useless for stopping the damage while it happens. For an organisation handling sensitive data — negotiations, industrial secrets, national security — relying solely on operating-system vendor notifications as your only safeguard is a design flaw. What’s needed is continuous behavioural monitoring on high-risk devices, and response plans that do not assume a timely warning will come.
Lesson three: three years of unimplemented recommendations show that dual-use control on paper is not enough
In June 2023 the PEGA committee had called for common rules and stricter enforcement of export controls on dual-use technologies. Three years later, the same surveillance infrastructure hits a member of the very committee that wrote those rules. The EU’s dual-use regulation — Reg. (EU) 2021/821 — already exists and restricts the export of surveillance technologies to destinations at risk for human rights; the problem is not the rule, it’s its verifiable enforcement. The same lesson already seen in the Cellebrite and Hikvision cases applies here: a list of authorised customers does not substitute for a verifiable technical check on who uses what, where, and under which real constraints. It is the principle behind our dual-use compliance commitments: an architectural promise, not merely a contractual declaration.
What to do
- Classify as critical infrastructure the devices of anyone performing oversight, compliance, audit, or regulatory-liaison functions — not only those of senior executives.
- Do not rely solely on after-the-fact notifications from suppliers: put continuous behavioural monitoring in place on the most exposed devices.
- If you operate in dual-use fields, verify compliance with export restrictions through independent audits — the supplier’s word is not proof.
- Carry out a rights impact assessment before adopting surveillance or interception tools, even when the supplier claims to sell “only to authorised buyers”.
Do you handle sensitive negotiating, industrial or security data, and want to check how well protected your critical devices would be against an attack that no notification arrives in time to stop? Half an hour with one of our experts for an initial map of risks and safeguards.
Sources
- The Citizen Lab — Espionage Against the European Parliament: Member of Committee Investigating Spyware Hacked with Pegasus (2 July 2026)
- TechCrunch — Politician who investigated spyware abuses had his phone hacked with Pegasus spyware (2 July 2026)
- Amnesty International Security Lab — Joint Statement: Pegasus in the parliament, the EU must act now (6 July 2026)