Future Tech & AI Wonders · Jordan Lee · 3 July 2026

Pegasus hacked an EU spyware investigator — here’s why it matters

Pegasus hacked an EU spyware investigator — here’s why it matters

A government customer of NSO Group used Pegasus to hack the iPhone of Stelios Kouloglou, a politician who investigated spyware abuses on the European Parliament’s PEGA committee. Researchers say the intrusions happened in 2022 and 2023, using a “zero-click” exploit. It matters because spyware can target even the people tasked with oversight.

Key Takeaways

What happened to the politician who investigated spyware?

According to TechCrunch, security researchers confirmed that Pegasus spyware was used to hack the phone of Stelios Kouloglou, a Greek journalist and former politician. At the time, Kouloglou was serving on the European Parliament’s PEGA committee, which investigated spyware abuses by European governments.

This is the kind of story that reads like a warning label: if a committee member scrutinizing spyware can be targeted, then oversight itself becomes a potential intelligence target. For readers tracking future-facing threats to democracy, it’s a real-world example of how powerful commercial surveillance tools can intersect with politics.

Who is Stelios Kouloglou and what was he working on?

TechCrunch reports that Kouloglou was part of the PEGA committee focused on phone spyware attacks and alleged abuses. The confirmed hack, researchers said, marks the first time a member of that committee has been publicly identified as a spyware victim.

Citizen Lab’s timeline, as described by TechCrunch, places one hack in October 2022. That period coincided with what the researchers characterized as intense email and text discussions ahead of a first draft describing spyware abuses, focusing on Cyprus, Greece, Hungary, Poland, and Spain.

How did Pegasus get in—and why does “zero-click” matter?

Citizen Lab said Kouloglou was hacked in October 2022 and at least twice during March 2023 using an exploit that compromised a security vulnerability in Apple’s iPhone software. TechCrunch reported that the vulnerability had been patched, but the fix was not yet installed on Kouloglou’s phone.

The key detail is the method: a “zero-click” bug, meaning the spyware could break in and steal data without any interaction by the victim. In other words, the usual user advice—don’t click suspicious links—doesn’t necessarily help against this class of attack.

What does this mean for EU oversight and spyware rules?

The March 2023 hacks, Citizen Lab said, occurred on March 6 and 7 while Kouloglou traveled from Athens to Brussels, during a period of committee hearings and months before the committee finalized and adopted its written draft report. That timing is central to why the case has drawn attention: it potentially intersects with sensitive oversight work.

TechCrunch also reported that the operator was a government customer of NSO Group, but the specific government was not identified in the article. For the underlying research, TechCrunch points to the University of Toronto’s Citizen Lab report: The Citizen Lab.

For more on emerging technology’s real-world impact—especially where security, power, and accountability collide—see our hub: Future Tech & AI Wonders.

← Open in blast feed