Lead story
The Spyware Investigator Who Became the Spied-Upon
If you wanted to design the most ironic cyberattack possible, you'd probably land somewhere close to this: hack a lawmaker with commercial spyware while he's sitting on the parliamentary committee investigating commercial spyware.
That's exactly what happened to Stelios Kouloglou, a former member of the European Parliament. Citizen Lab, the University of Toronto-based digital rights research group, has confirmed through forensic analysis of his device that Kouloglou was infected with NSO Group's Pegasus spyware — not once, but twice — while he was actively serving on the PEGA Committee, the EU's dedicated inquiry into spyware abuses.
What is Pegasus, and why does this matter?
Pegasus is a commercial spyware tool sold by Israeli firm NSO Group, marketed exclusively to government customers. It can silently compromise a phone — extracting messages, emails, call logs, location data, contacts, and even activating the microphone and camera — often without the target doing anything at all (so-called "zero-click" attacks). Its use against journalists, dissidents, lawyers, and politicians has been extensively documented since the Pegasus Project reporting in 2021.
The PEGA Committee was the EU's formal response to that reporting. Its mandate: investigate how member states were using tools like Pegasus, whether those uses violated EU law, and what reforms were needed. Kouloglou served on that committee. Someone with access to a government Pegasus licence decided to target him during that period.
Who did it?
Citizen Lab has not publicly attributed the attack to a specific government — that's standard practice until they have high confidence. But Pegasus is sold only to vetted nation-state customers, which means a government actor made a deliberate decision to surveil an EU parliamentarian investigating government surveillance. The circularity is almost too neat to be real.
Kouloglou's response was direct: "It is a direct attack on the rule of law." That framing matters. This isn't just a privacy violation — it's a potential attack on the integrity of a legislative oversight process.
Why it matters beyond the irony
There's a broader pattern here that's worth naming clearly. Commercial spyware vendors have long argued their tools are used only for legitimate law enforcement and national security purposes. The PEGA Committee's own findings told a different story — Pegasus was found on the phones of journalists, lawyers, and opposition politicians in Hungary and elsewhere.
Adding a sitting PEGA Committee member to that list is a data point that's hard to explain away. It also raises uncomfortable questions about whether EU member states are prepared to take meaningful action against a surveillance industry that has now, apparently, turned its tools on their own institutions.
What to watch
NSO Group has been on the US Commerce Department's Entity List since 2021, restricting American companies from doing business with it. The EU has moved more slowly. The PEGA Committee issued recommendations in 2023, but implementation has been patchy. Expect this disclosure to reignite calls for a harder EU-wide ban on commercial spyware procurement.
Australia isn't immune to these questions. The Australian Federal Police's relationship with commercial surveillance vendors has faced scrutiny, and the Attorney-General's Department has been under pressure to clarify the legal framework governing use of spyware against Australian persons. Citizen Lab has previously documented Pegasus infrastructure with links to Australian targets.
This one will have legs.
