NEWSAR
Multi-perspective news intelligence
SRCThe Guardian - World News
LANGEN
LEANCenter-Left
WORDS640
ENT10
FRI · 2026-07-03 · 05:00 GMTBRIEF NSR-2026-0703-89611
News/EU lawmaker investigating surveillance h/Spyware used against MEP investigating Pegasus abuses, repor…
NSR-2026-0703-89611News Report·EN·Human Rights

Spyware used against MEP investigating Pegasus abuses, report finds

Researchers at Citizen Lab have found that a former Member of the European Parliament (MEP), Stelios Kouloglou, was repeatedly targeted with NSO Group's Pegasus spyware. These attacks occurred between October 2022 and March 2023, coinciding with Kouloglou's involvement in a special European parliamentary committee investigating spyware abuses.

Stephanie KirchgaessnerThe Guardian - World NewsFiled 2026-07-03 · 05:00 GMTLean · Center-LeftRead · 3 min
Spyware used against MEP investigating Pegasus abuses, report finds
The Guardian - World NewsFIG 01
Reading time
3min
Word count
640words
Sources cited
3cited
Entities identified
10entities
Quality score
100%
§ 01

Briefing Summary

AI-generated
NEWSAR · AI

Researchers at Citizen Lab have found that a former Member of the European Parliament (MEP), Stelios Kouloglou, was repeatedly targeted with NSO Group's Pegasus spyware. These attacks occurred between October 2022 and March 2023, coinciding with Kouloglou's involvement in a special European parliamentary committee investigating spyware abuses. While Citizen Lab could not identify the specific government operator, the hacking bore similarities to a previous campaign against Russian and Belarusian journalists in Europe. The attacks occurred during critical periods of the committee's deliberations and report drafting. This marks the first known instance of a member of this specific committee being targeted with spyware, highlighting concerns about the effectiveness of the committee's recommendations.

Confidence 0.90Sources 3Claims 5Entities 10
§ 02

Article analysis

Model · rule-based
Framing
Human Rights
Political Strategy
Tone
Mixed Tone
AI-assessed
CalmNeutralAlarmist
Factuality
0.80 / 1.00
Factual
LowHigh
Sources cited
3
Well sourced
FewMany
§ 03

Key claims

5 extracted
01

This marks the first known instance of a member of the Pega committee being targeted with spyware.

factualCitizen Lab
Confidence
1.00
02

NSO Group's spyware was used against a European Parliament member investigating spyware abuses.

factualCitizen Lab
Confidence
1.00
03

The committee's recommendations regarding spyware have essentially been ignored.

factualJohn Scott-Railton
Confidence
0.90
04

The hacking coincided with Kouloglou's hospital stay and a Greek investigative journalist's work on spyware stories.

factualCitizen Lab
Confidence
0.90
05

The hacking of Stelios Kouloglou bore hallmarks of a previous campaign against exiled Russian and Belarusian journalists.

factualCitizen Lab
Confidence
0.90
§ 04

Full report

3 min read · 640 words
NSO Group’s hacking software was repeatedly used against a member of the European Parliament while he was conducting an investigation of spyware abuses in Europe, according to a new report.Researchers at the Citizen Lab at the University of Toronto said they could not attribute the attacks against Stelios Kouloglou to any particular government operator of Pegasus spyware. But their investigation found the attack against the Greek now-former MEP bore the hallmarks of a previous hacking campaign against exiled Russian and Belarusian journalists in Europe.“When you realise your private life is scrutinised by very bad people, you become angry,” Kouloglou, who is also a journalist and left parliament in 2024, said in an interview. “It’s a big issue having to do with corruption, justice and democracy.”At the heart of Citizen Lab’s new report lies Kouloglou’s work for a special European parliamentary committee known as Pega, which was established in March 2022 after the publication of the Pegasus Project by The Guardian and a consortium of media outlets.The Pegasus Project revealed how journalists, activists, politicians and other members of civil society were being targeted by governments using Pegasus, which is made by the Israel-based NSO Group and sold to governments around the world for the purposes of stopping serious crime and terror attacks. Pega’s mission in 2022 was to investigate the scope of how spyware was being used in contravention of EU law.Kouloglou, a journalist who was first elected to the European Parliament as a member of the Syriza party, joined the Pega committee in March 2022. His mobile device was first infected, Citizen Lab said, about seven months later, on 21 October 2022, in what was described as a “particularly intense period of activity” in Pega’s deliberations and investigations, including the drafting of the committee’s first report.NSO did not respond to a request for comment.The hacking coincided with Kouloglou’s admittance to a hospital for elective surgery, where he was visited by a Greek investigative journalist, Thanasis Koukakis.Koukakis was at the time working on mercenary spyware stories in Greece, following a major scandal known as the “Greek Watergate”, which involved the illegal targeting of more than 80 people in Greece, including politicians, journalists and military officials. Koukakis was among the targeted victims and had earlier testified about his experience in front of the Pega committee.Kouloglou’s device was hacked again, Citizen Lab said, on 6 and 7 March 2023, when Pega was involved in intensive discussions related to the final drafting of its report. The hacking coincided with Kouloglou travelling from Athens to Brussels.Citizen Lab said the revelations in their report marked the first time that a member of the Pega committee is known to have been targeted with spyware. And it comes as the committee’s recommendations have essentially been ignored, said John Scott-Railton, a senior researcher at Citizen Lab.skip past newsletter promotionafter newsletter promotionHe said: “This case is the ultimate irony of Europe’s spyware crisis. Someone on the very committee tasked with investigating Pegasus gets infected by it. And what has happened since? The parliament looks the other way when new European spyware abuses emerge.“I can tell you how the next chapter will go: more hacked parliamentarians. In fact, I suspect there are members voting and attending high-level meetings with no idea that their phone has been turned into a spy in their pocket.”While Citizen Lab could not pinpoint the probable government client that used the spyware against the then MEP, researchers said they believed the same operator who targeted him also targeted seven Russian and Belarusian-speaking independent journalists and opposition activists based in Europe, who were found to have been targeted or infected with Pegasus spyware.The researchers identified a unique Apple ID email used in the attacks, which suggests they were by the same government client. The client also probably had licences to operate in Belgium and Greece, Citizen Lab said.
§ 05

Entities

10 identified
§ 06

Keywords & salience

10 terms
pegasus spyware
1.00
nso group
0.90
spyware abuses
0.90
european parliament
0.80
citizen lab
0.70
mep investigation
0.70
democracy
0.60
corruption
0.50
hacking campaign
0.50
eu law
0.40
§ 07

Topic connections

Interactive graph
Network visualization showing 3 related topics
View Full Graph
Person Organization Location Event|Click node to navigate|Edge numbers = shared articles