Back Heise.De Member of the special committee on Pegasus: EU MEP attacked with spyware
While the European Parliament has been investigating the illegal use of Pegasus spyware in the member states, the smartphone of a member of the special committee was itself repeatedly infected with it. This was made public by the University of Toronto's Citizen Lab, which specializes in analyzing such spyware attacks. According to the lab, the attacks targeted Stelios Kouloglou from Greece, who sat in the European Parliament for the left-wing Syriza party. From March 24, 2022, to July 18, 2023, he was a substitute member of the inquiry committee, and his mobile phone was successfully infected with Pegasus spyware on October 21, 2022, and again on March 6 and 7, 2023, according to the analysis report. Who is behind it remains unclear.
The investigation was initiated in spring 2022 after it became known the year that Pegasus spyware had been used to spy on government officials, opposition politicians, journalists, and human rights activists in Hungary, Poland, Spain, and France. In the course of their work, the MEPs questioned, among others, the Chief Compliance Officer of the Israeli spyware manufacturer NSO. However, due to the numerous rights that the special committee lacks compared to, for example, a parliamentary inquiry committee in the Bundestag, it remained without answers. After a year, the European Parliament adopted a recommendation to curb the misuse of state Trojans in the EU. Later, urgent calls for consequences were made.
Kouloglou, who was involved in the investigation, informed Citizen Lab possible attacks in May of this year. Traces were then found during a forensic analysis of his iPhone. According to the analysis, the device was first infected with a zero-click exploit, meaning the MEP did not even have to click on a misleading link. At the time of the attacks, the MEP, who had worked as a journalist before and during his term, had spoken out in numerous articles and interviews the misuse of spyware. Before Kouloglou, other MEPs had already been attacked with Pegasus, but no member of the inquiry committee. Whether others were affected cannot be determined without analyzing their devices.
Whoever is behind the attack potentially had access to strictly confidential committee communications. Citizen Lab does not attribute the attack to any state actor. While the expert group recalls a Pegasus surveillance scandal in Greece, it assures, “we have no indications that this hacking was the work of the Greek government.” Instead, they have indications that the attacks were commissioned by an NSO customer who also attacked independent and opposition journalists from Russia and Belarus in Europe. Since the MEP was attacked in two EU member states, it is also plausible that those responsible had acquired a license for it.
This article was originally published in German . It was translated with technical assistance and editorially reviewed before publication.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
