The European Union faces renewed scrutiny over surveillance practices following a groundbreaking forensic investigation that reveals a former Member of the European Parliament was targeted with sophisticated spyware while serving on a committee tasked with examining exactly those abuses. The incident underscores persistent vulnerabilities in the bloc's institutions and raises urgent questions about the protection of democratic processes.
Background on Pegasus Spyware and the PEGA Inquiry
Pegasus, developed by the Israeli firm NSO Group, is a powerful commercial surveillance tool capable of infiltrating mobile devices to access messages, calls, cameras, microphones, and location data without user interaction. Its deployment has been documented across dozens of countries, often targeting journalists, activists, and political figures. In response to widespread revelations in 2021, the European Parliament established the Committee of Inquiry to investigate the use of Pegasus and equivalent surveillance spyware, known as PEGA, in March 2022. The committee operated until July 2023, examining alleged misuse by EU member states and the adequacy of existing regulations.
The PEGA committee's work highlighted systemic issues, including the use of spyware in countries such as Poland and Hungary against opposition figures, journalists, and civil society. Its final report described the situation as "Europe’s Watergate," emphasizing that spyware abuses represented not isolated incidents but a broader challenge to fundamental rights and the rule of law across the bloc.
The Specific Case of Stelios Kouloglou
Stelios Kouloglou, a Greek investigative journalist and former MEP who served from 2015 to 2024, was a member of the PEGA committee throughout its existence. While conducting inquiries into spyware abuses—including travels to interview victims and participate in hearings—his personal iPhone was compromised multiple times with Pegasus. Forensic analysis conducted by the University of Toronto's Citizen Lab confirms infections on or around October 21, 2022, and again on March 6 and 7, 2023. These incidents occurred during periods of intense committee activity, including key hearings and the drafting of findings.
The first compromise took place while Kouloglou was in Athens recovering from surgery. Subsequent infections occurred in Brussels amid parliamentary business. Citizen Lab's report notes that the attackers could have gained access to confidential documents, internal deliberations, and personal communications, potentially compromising the integrity of the inquiry itself. This marks the first publicly documented instance of an active PEGA committee member being targeted with the very spyware under investigation.
Key Findings from the Citizen Lab Report
The Citizen Lab analysis, released in early July 2026, provides high-confidence evidence of Pegasus infections on Kouloglou's device. Researchers identified artifacts consistent with the spyware's operation and linked some activity to patterns seen in prior targeting of Russian- and Belarusian-speaking journalists and activists. No specific government operator has been attributed, and there is no indication of involvement by Greek authorities.
Apple issued threat notifications to the device in the months following the infections, though Kouloglou has no recollection of seeing them at the time. The report stresses that the timing aligns with critical phases of the PEGA committee's work, suggesting deliberate efforts to monitor or disrupt the investigation rather than random targeting.
Full details are available in the Citizen Lab report.
Photo by Hans-Peter Traunig on Unsplash
Reactions from European Parliamentarians and Institutions
MEPs have expressed outrage and concern over the revelations. Saskia Bricmont, a PEGA committee member, stated that the use of spyware violates fundamental rights and threatens the security and integrity of parliamentary work and the European Parliament as a whole. Hannah Neumann, another former committee member, described the targeting of an investigator as demonstrating "the whole absurdity of the situation."
The European Parliament has pointed to existing spyware screening systems available to MEPs and recent expansions of protections. However, calls persist for stronger measures, including better implementation of the committee's recommendations such as an EU forensic analysis lab and enhanced election security protocols.
Broader Context of Spyware Abuses in the EU
The Kouloglou case fits into a larger pattern of spyware deployment within Europe. Previous PEGA findings documented systematic use in several member states against political opponents, media, and activists. Hungary and Poland featured prominently in the committee's critique, with spyware described as integral to efforts to control dissent and influence elections.
Journalists across the EU and candidate countries have also faced targeting, with tools including Pegasus, Predator, and others. The 2021 Pegasus Project revelations exposed the global scale of NSO Group's client base, prompting the EU inquiry. Despite these exposures, abuses have continued, highlighting gaps in oversight and enforcement.
Regulatory Challenges and Export Controls
The EU's Dual-Use Regulation aims to control exports of surveillance technologies, yet implementation has faced criticism for insufficient rigor. The PEGA committee and subsequent reports have called for stricter licensing, greater transparency, and bans on certain high-risk tools. A 2026 Human Rights Watch assessment noted ongoing failures to prevent exports to rights-violating regimes.
Member states retain significant discretion, leading to uneven application. The European Commission is scheduled to evaluate the regulation further in 2026, providing an opportunity for reforms. Civil society groups advocate for a full prohibition on mercenary spyware within the EU to close loopholes.
Implications for Democracy and Parliamentary Security
The targeting of a PEGA committee member raises profound concerns about the safety of elected representatives and the confidentiality of legislative work. Access to an MEP's device could expose sensitive negotiations, witness testimonies, and draft recommendations, undermining public trust in EU institutions.
Experts warn that such incidents erode the rule of law and signal that no one is immune from surveillance. With advancing technologies like AI potentially lowering barriers for spyware operators, the risks are expected to grow. The episode also highlights the personal toll on targets, including loss of privacy in communications with family and colleagues.
Photo by Margo Evardson on Unsplash
Calls for Action and Policy Recommendations
MEPs and researchers urge immediate steps: full adoption of PEGA recommendations, enhanced device security protocols for parliamentarians, and international cooperation on sanctions against spyware vendors and users. Some advocate for an EU-wide ban on Pegasus-like tools and stronger support for forensic capabilities.
The European Parliament's existing screening tools represent a start, but broader systemic changes are needed. Civil society emphasizes transparency in export decisions and accountability for past abuses.
Future Outlook and Ongoing Developments
As the EU grapples with these revelations, the 2026 evaluation of export controls offers a critical juncture. Continued vigilance from bodies like the Citizen Lab and media investigations will likely uncover additional cases. Kouloglou and fellow MEPs stress that awareness exists; the challenge lies in translating reports into concrete protections.
The scandal serves as a stark reminder that spyware threats extend beyond external actors to the heart of European governance. Addressing it effectively will require coordinated political will across institutions and member states.
