3 min read

When the watchdog gets watched: Pegasus inside the European Parliament's own spyware inquiry- 282

When the watchdog gets watched: Pegasus inside the European Parliament's own spyware inquiry- 282

July 7, 2026

A member of the European Parliament tasked with investigating the abuse of commercial spyware in Europe has himself been confirmed as a spyware target — hacked not once but twice, at precisely the moments his committee was doing its most sensitive work. The case, verified by the Citizen Lab, is more than another entry in a long list of spyware scandals: it is proof that Europe's own mechanism for holding the spyware industry accountable was penetrated from the inside, and that nearly three years after that mechanism issued its recommendations, nothing has been done to prevent it happening again.

The target was Stelios Kouloglou, a Greek investigative journalist and former MEP who sat on the European Parliament's PEGA Committee — the body formed specifically to investigate Pegasus and similar surveillance tools. Citizen Lab's forensic analysis confirmed his phone was infected with Pegasus, a form of spyware that requires no click or action from the victim to install itself, on three occasions: once in October 2022 and twice more in March 2023. Both windows line up precisely with the committee's internal work — the first infection landed just before a round of hearings, the second amid closed-door debate over the committee's draft findings. In other words, whoever was behind the hack had reason to want early visibility into how the investigation into spyware abuse was itself proceeding.

Infection timeline — mapping the three Pegasus infections against the PEGA Committee's own working calendar

Attribution here matters, and the investigators were careful about it. Citizen Lab found no evidence tying the operation to the Greek government, despite Greece's own well-documented spyware scandal — that earlier episode involved a different product, Intellexa's Predator, not Pegasus. Kouloglou himself believes Athens is responsible, but the forensic trail points elsewhere: researchers assess that the same Pegasus operator was previously caught targeting exiled Russian and Belarusian journalists and opposition figures between 2020 and 2023, and — critically — that the identical decoy email used against Kouloglou was reused in those earlier attacks. Because Pegasus operators are issued unique targeting infrastructure and only a subset of NSO Group's customers are licensed to hack targets across national borders, this reuse narrows the list of possible culprits considerably, even without naming one outright.

Attribution link — showing how the reused decoy email ties the Kouloglou hack to the earlier Russian/Belarusian targeting operation

The institutional damage here runs deeper than one phone. A legislature's ability to oversee state surveillance depends on its members being able to investigate without being surveilled themselves. When a sitting member of the very committee built to check spyware abuse is hacked while doing that work, it signals to every future investigator that scrutiny carries a cost — and it does so without anyone needing to admit responsibility. As one of the committee's own negotiators put it, the episode reflects a basic disregard for parliament's role in holding power to account, precisely at the moment spyware is being defended in policy circles as a legitimate security tool.

That defense is increasingly hard to sustain given the pattern. The PEGA Committee delivered its recommendations in May 2023; the European Commission has acted on essentially none of them. In the time since, Europe has cycled through one spyware controversy after another: further Pegasus infections of exiled journalists and activists in Latvia, Lithuania, and Poland; the targeting of the European Parliament's own president with Predator; the use of Italy's domestically-linked Graphite spyware against humanitarian workers and journalists; EU funds found flowing to spyware vendors; and continued export of European surveillance technology to governments with poor human rights records, despite rules meant to prevent exactly that. Taken individually, each incident might be dismissed as a one-off failure. Taken together, they describe a structural unwillingness — at the level of both national governments and EU institutions — to treat spyware proliferation as the governance problem it plainly is, largely because those same governments value what the technology gives their own intelligence and law enforcement services.

The open question for anyone tracking this space is whether an attack this close to home — a hack of the overseer by the overseen, in effect — becomes the case that finally forces a EU-wide response, or simply the next scandal in a sequence that has so far produced outrage without consequence.

Scandal pattern — the string of unaddressed spyware controversies since PEGA's May 2023 recommendation