Pegasus hacks EU politician investigating spyware abuses – Claril Noticias

Greek journalist and former MEP Stelios Kouloglou was targeted and hacked with Pegasus spyware between 2022 and 2023 while serving on a European Parliament committee investigating government abuses of the exact same surveillance tool, digital rights researchers confirmed on Friday.

The discovery, made by researchers at the University of Toronto’s digital rights unit, The Citizen Lab, marks the first time a member of the European Parliament’s PEGA committee—established specifically to investigate state-sponsored spyware attacks across Europe—has been publicly identified as a target.

A Direct Attack on the Rule of Law

Speaking to TechCrunch, Kouloglou described the deliberate breach of his device as “reckless”. The revelation has sparked outrage among European lawmakers, with one active member of parliament labelling the hacking a “direct attack on the rule of law” and urging the European Commission to intervene by enforcing strict limits on spyware use across the 27 member states.

While targeting politicians remains relatively rare, the timing of this intrusion suggests a calculated effort to monitor the committee’s internal findings. The incident raises critical questions about how democratic governments deploy powerful surveillance tools—routinely justified as national security measures—to spy on critics, journalists, and elected officials.

The Mechanics of a Zero-Click Exploit

According to the report published on Friday by The Citizen Lab, Kouloglou’s iPhone was compromised in October 2022 and at least twice in March 2023. The attacks utilised a “zero-click” exploit, meaning the spyware successfully infiltrated the device and exfiltrated private data without requiring any action or interaction from the user.

var playerInstance_jwplayer_6a7a08ceb0014 = jwplayer( “jwplayer_6a7a08ceb0014” );
playerInstance_jwplayer_6a7a08ceb0014.setup({
playlist: “https://cdn.jwplayer.com/v2/media/lv0GaEwB”,
});

The exploit weaponised a previously identified security vulnerability in Apple’s smart home software. Although Apple had released a security patch for the flaw, the update had not yet been installed on Kouloglou’s phone. Once active, the spyware granted operators unrestricted access to his private information, including text messages, location history, emails, and photos.

Strategic Timing and Eavesdropping Risks

The timeline of the intrusions points to highly strategic targeting. The October 2022 hack coincided with intense internal communications ahead of the committee’s first draft report, which focused heavily on spyware abuses in Cyprus, Greece, Hungary, Poland, and Spain.

Furthermore, this initial breach occurred while Kouloglou was hospitalised for a scheduled surgical procedure. Researchers note this timing could have allowed the spyware operators to activate the device’s microphone to capture ambient audio, potentially recording sensitive healthcare discussions or private conversations with hospital visitors.

Months later, on 6 and 7 March 2023, the same Pegasus operator compromised Kouloglou’s device again as he travelled from Athens to Brussels. This second wave of attacks occurred during critical committee hearings, shortly before the final draft report was officially adopted.

Tracing the Anonymous Perpetrator

While The Citizen Lab did not attribute the campaign to a specific nation, researchers revealed that the operator used the same Pegasus-associated email address identified in previous hacking campaigns targeting European journalists. The reuse of this specific digital infrastructure strongly suggests the client had explicit authorisation from NSO Group to conduct surveillance operations across multiple European jurisdictions.

Neither the European Commission nor NSO Group responded to requests for comment regarding the findings prior to the report’s publication.

Legal Action and the Fight for Democracy

Kouloglou admitted he was unaware of why he was singled out, but strongly believes his role on the PEGA committee made him a target. He expressed deep violation upon learning his personal space had been invaded.

“You realise that all of your personal data [was taken] — not just professional exchanges or messages with ministers — but also the very private things, like the happy moments and the sad moments,” he told TechCrunch.

In response, Kouloglou confirmed plans to launch legal action against NSO Group, the Israeli developer behind Pegasus. NSO Group remains blacklisted in the United States under a Biden administration executive order restricting the use of commercial spyware linked to human rights violations. Despite financial struggles, the company reportedly secured tens of millions of dollars from an unnamed American investment group last year in an attempt to rehabilitate its brand.

Kouloglou emphasised that his decision to go public is a stand for broader democratic principles. “Corruption concerns everybody,” he stated, framing his legal fight as an essential battle for human rights and transparency.

By Claril

Leave a Reply

Your email address will not be published. Required fields are marked *