Threats · 70 days ago
The risk is no longer limited to the person under surveillance. When a phone used by someone investigating spyware abuse is compromised, the inquiry itself becomes a target: deliberations, contacts, and timing can be watched while evidence is still being collected.
Citizen Lab says Stelios Kouloglou’s phone was infected with Pegasus in October 2022 and again in March 2023 while he sat on the PEGA committee. Pegasus is zero-click spyware, so the target does not need to tap anything for the phone to become a remote monitoring device, and Citizen Lab says the same Pegasus customer may connect this case to earlier infections of journalists and opposition figures.
That pushes the blast radius from one handset to the integrity of democratic oversight. It means the people gathering facts about spyware abuse can be surveilled by the same ecosystem they are trying to expose.
4 sources covering this story
EU urged to act after Pegasus infects phone of spyware inquiry MEP
Campaigners demand investigation and long-delayed action on PEGA Committee recommendations
Risky Bulletin: EU official’s phone infected with Pegasus
A European MP’s phone was infected by Pegasus spyware, Android drops its PIN guessing limit from 1,800 attempts to 20, Alibaba bans employ [Read More
European Parliament Member Investigating Spyware Was Hacked With Pegasus
Citizen Lab says Pegasus hit Kouloglou’s iPhone in 2022 and 2023 via Apple’s HomeKit zero-click exploit, patched in iOS 16.3.1.
The Record from Recorded Future
Spyware found on phone of European Parliament member probing it
Stelios Kouloglou, formerly a member of the European Parliament's committee investigating abuses of commercial spyware, was twice infected with Pegasus while serving, researchers said.
Part of the PlainSec briefing for 2026-07-03