July 4, 2026 · Privacy / Surveillance / Policy
Pegasus Hacked the Man Investigating Pegasus — and Nobody Should Be Surprised
A European lawmaker probing spyware abuses was himself surveilled with Pegasus. It's a damning sign of how oversight gets neutralized.
There’s a grim logic to it. If you’re a government using powerful spyware to silence critics and monitor opponents, the last people you’d want operating freely are the ones building the legal case against you.
That logic apparently played out in real time. According to researchers at the Citizen Lab, the University of Toronto’s digital rights unit, Greek journalist and former politician Stelios Kouloglou had his iPhone hacked with NSO Group’s Pegasus spyware during 2022 and 2023 — while he was actively serving on the European Parliament’s PEGA committee, the body specifically tasked with investigating spyware abuses by European governments. As TechCrunch reports, this makes Kouloglou the first publicly identified PEGA committee member to have been confirmed as a Pegasus victim.
The timing wasn’t coincidental. It was surgical.
The Hack Was Timed to Committee Milestones
Citizen Lab’s findings show that Kouloglou’s phone was first compromised in October 2022, a period of intense internal deliberations ahead of the committee’s first draft report detailing spyware abuses in Cyprus, Greece, Hungary, Poland, and Spain. The phone was hacked again in March 2023, just as Kouloglou traveled from Athens to Brussels for committee hearings, months before the final report was adopted.
The attack itself was a “zero-click” exploit — meaning Kouloglou didn’t have to tap a link or open a file. The spyware silently broke into his phone by abusing a vulnerability in Apple’s smart home software. It grabbed text messages, location data, photos, and other private correspondence. He didn’t know it was happening. According to TechCrunch, the October hack even coincided with a period when Kouloglou was hospitalized for a pre-scheduled surgery, potentially exposing private conversations with visitors.
Citizen Lab didn’t name the country responsible but noted that the attacker reused the same Pegasus-loaded email address tied to a prior campaign that targeted journalists across Europe — suggesting an NSO-authorized government customer operating across multiple countries.
Kouloglou told TechCrunch he believes the targeting was directly tied to his committee work. He described his reaction as anger. “You realize that all of your personal data [was taken] — not all the professional exchanges or messages with ministers — but also the very private things, like the happy moments and the sad moments,” he said. He plans to sue NSO Group and says he’s going public “for democracy, human rights, and the fight against corruption.”
One serving European lawmaker called the hack “a direct attack on the rule of law” and urged the European Commission to impose strict limits on spyware use across the EU’s 27 member states. The Commission did not respond to TechCrunch’s request for comment. Neither did NSO Group.
A Broader Pattern of Surveillance Creep
The Pegasus story doesn’t exist in isolation. The same week, privacy advocates were sounding alarms in a separate arena — this time over Elon Musk’s X platform.
According to Ars Technica, a coalition of 15 privacy and consumer protection groups, including the Electronic Frontier Foundation and the Electronic Privacy Information Center, filed comments urging the Federal Trade Commission to reject X’s bid to end its oversight order. That order — originally imposed after Twitter was found to have misused users’ contact information for ad targeting — requires X to undergo independent audits and give the FTC access to compliance documents.
X argued the order is outdated and burdensome, partly because the platform has been rebranded and restructured since Musk took over. Advocates weren’t buying it. They pointed to a data leak of 2.8 billion records last year, ongoing concerns about Grok’s data practices, and X’s decision to train its AI on hundreds of millions of user posts without meaningful consent — simply updating its terms and hoping users wouldn’t notice. Research cited in the letter found that 73 percent of X users were unaware their posts were being used to train Grok.
These two stories — Pegasus targeting an overseer, X resisting an overseer — share the same underlying dynamic. Surveillance tools and data-hungry platforms alike push back hard against accountability. The mechanisms differ; the instinct is identical.
Why This Matters Beyond the Headlines
The Kouloglou case is a stress test for the idea that democratic institutions can rein in surveillance technology. A parliamentary committee was set up precisely to investigate these abuses. One of its own members was being monitored with the very tool under investigation. That’s not a system working as intended — it’s a system being actively undermined.
Spyware like Pegasus was sold to governments on the premise of fighting serious crime. What keeps surfacing instead is its use against journalists, lawyers, opposition politicians, and now the investigators themselves. If the people tasked with oversight can’t operate without being surveilled, meaningful accountability becomes nearly impossible.
Kouloglou’s case is the first of its kind to be confirmed publicly. It almost certainly won’t be the last.