NSO Group—Pegasus spyware used to hack phone of European Parliament spyware-inquiry (PEGA) member Stelios Kouloglou, Citizen Lab found
Citizen Lab forensic analysis published July 2, 2026 found with high confidence that former Greek MEP Stelios Kouloglou's phone was infected with NSO Group's Pegasus spyware on October 21, 2022 and again on March 6-7, 2023, while he served on the European Parliament's PEGA committee investigating spyware abuses. Citizen Lab did not attribute the operation to a specific government, but linked the operator to infrastructure previously used in a campaign targeting Russian- and Belarusian-speaking journalists and activists across Europe, and found no evidence Greece was the customer.
Scoring Impact
| Topic | Direction | Relevance | Contribution |
|---|---|---|---|
| Digital Safety for Vulnerable Users | -against | secondary | -0.50 |
| Surveillance Technology | +toward | primary | -1.00 |
| User Privacy | -against | primary | -1.00 |
| Overall incident score = | -0.805 | ||
Score = avg(topic contributions) × significance (high ×1.5) × confidence (0.64)
Evidence (2 signals)
Citizen Lab forensic report confirmed Pegasus infections on PEGA committee member Kouloglou's phone
Citizen Lab published forensic findings on July 2, 2026 confirming with high confidence two Pegasus infections (October 21, 2022 and March 6-7, 2023) on the phone of former Greek MEP Stelios Kouloglou while he sat on the European Parliament's committee investigating spyware abuses. The lab linked the operator to infrastructure used against Russian- and Belarusian-speaking journalists and activists in Europe and found no evidence Greece was the customer.
TechCrunch and Politico Europe reported Citizen Lab finding that spyware-inquiry MEP was hacked with Pegasus
Independent press coverage of the Citizen Lab findings, reporting that former MEP Stelios Kouloglou, a member of the European Parliament's PEGA spyware-inquiry committee, was himself hacked with NSO Group's Pegasus spyware during his committee service.