Stelios Kouloglou, a former Greek MEP and investigative journalist, sat on the European Parliament's PEGA committee, and at the time his hobby horse was tracking down Pegasus, the smartphone spyware developed by Israeli company NSO Group.
Well, guess what? His own smartphone was infected with Pegasus too!
It was Citizen Lab, a lab tucked away at the University of Toronto, that went through his iPhone last May and found traces of 2 infections. The first in October 2022, and the in March 2023. Right when the PEGA committee was working on its report, go figure...
But before I explain everything, let me give a quick recap for those who missed the first episode. Pegasus is a tool from a private surveillance company called NSO Group. This tool is capable of installing itself on an iPhone entirely on its own, without requiring so much as a single click from the victim. No interaction, no trace, and once it's in place, this nasty piece of work siphons everything - what your microphone and cameras pick up, your messages, your location, your data... you name it. The European Parliament had set up the PEGA committee back in April 2022 precisely to understand why member states were using it to spy on journalists, lawyers, and political opponents.
So who infected Kouloglou?
Nobody has found out, and that's exactly the problem. NSO never discloses its clients' names, and the company didn't respond to requests for . Kouloglou himself points the finger at the Greek government - his own country - which is among the states called out by the committee, alongside Poland, Hungary, and Spain.
Except that Citizen Lab, the lab that carried out the analysis, wasn't able to confirm any leads and believes that other parliamentarians have been or will also be infected. And the worst part of the whole story is that nothing more comes of it...
The PEGA committee delivered its report in May 2023 with a list of recommendations - regulating spyware, creating a European technical lab, opening avenues for legal redress - and Parliament voted in favour. Great! Except that since then, the European Commission has filed all of that away in a drawer.
So those recommendations have now been gathering dust for 3 years. And Kouloglou isn't even an isolated case - there was already Nikos Androulakis, another Greek MEP, who was targeted by Predator, Pegasus's cousin. At the time, everyone cried scandal, but here we are a few years later with zero repercussions and zero change.
And while justice crawls along at a snail's pace - even though NSO got handed a crushing defeat by WhatsApp - the spyware market is thriving! Candiru, Paragon, Intellexa... For every NSO that stumbles, others are there to carve up the pie.
So what do we do, us ordinary mortals with no parliamentary immunity?
Well, for starters, if you're a journalist, an activist, or just a well-organised paranoid, enable Apple's Lockdown Mode , which has already thwarted attacks of this kind. And if you smell something fishy, know that you can have a smartphone analysed to detect signs of infection , exactly as Citizen Lab did for Kouloglou.
In short, an MEP investigating spies gets spied on, and Europe looks the other way... I've seen better ads for democracy!
Then join my community on Patreon for exclusive articles, advanced tutorials and lots of other surprises I keep for my supporters. It's thanks to you that I can keep sharing my passion after 20 years!
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
