The risk is no longer limited to the person under surveillance. When a phone used by someone investigating spyware abuse is compromised, the inquiry itself becomes a target: deliberations, contacts, and timing can be watched while evidence is still being collected.
Citizen Lab says Stelios Kouloglou’s phone was infected with Pegasus in October 2022 and again in March 2023 while he sat on the PEGA committee. Pegasus is zero-click spyware, so the target does not need to tap anything for the phone to become a remote monitoring device, and Citizen Lab says the same Pegasus customer may connect this case to earlier infections of journalists and opposition figures.
That pushes the blast radius from one handset to the integrity of democratic oversight. It means the people gathering facts about spyware abuse can be surveilled by the same ecosystem they are trying to expose.