Back Internazionale.It Researchers say EU lawmaker who investigated surveillance was hacked by Israeli spyware
July 3 (Reuters) - A former member of the European Parliament who served on a committee investigating abusive surveillance was himself hacked using an Israeli-made spy tool, a Canadian tech watchdog group said on Friday.
Citizen Lab said in a report that the phone of Stelios Kouloglou, a Greek television journalist-turned-lawmaker, was hacked at least three times between October 2022 and March 2023 using Pegasus spyware, a tool distributed by the Israeli company NSO Group.
At the time of the targeting, Kouloglou was serving on the European Parliament’s PEGA Committee, which was set up in 2022 to examine the use of illegal phone hacking across the European Union. The committee focused mainly on the use of Pegasus and similar tools, finding that governments across the EU likely used spyware, “in one way or another, some legitimate, some illegitimate.”
Kouloglou said he was astonished at the audacity of whoever was behind the hacking.
“I was not expecting that a PEGA member would be spied on by Pegasus,” he told Reuters. “I was not expecting that they would be as reckless as that.”
NSO did not return messages seeking .
In a statement to Reuters, the European Parliament did not directly address Kouloglou’s case but said its IT security services “constantly monitor cybersecurity threats as well as potential cyberattacks against its working environment.”
It said spyware screening tools had been available to all lawmakers since 2022 and that a report adopted last month called for their extension to all devices used for parliamentary business.
The European Commission, the European Union’s executive branch, did not immediately return messages seeking .
NSO has said its spy tools are used to police serious crime and to protect national security, but the company has repeatedly been accused of facilitating intrusive surveillance of journalists, political opponents, civil rights activists and religious figures around the world.
NSO was blacklisted by the U.S. government in 2021 over human rights and national security concerns. Last year, WhatsApp owner Meta Platforms won a $168 million damages award against NSO for unlawfully hacking the platform, although the award was significantly reduced. Last month, Meta accused NSO of violating the court’s injunction on targeting its services and filed for a contempt order.
Citizen Lab said it believed that Kouloglou had been hacked through a vulnerability in Apple software that was not known at the time. It said Kouloglou received repeated warnings state- hacking attempts from Apple in 2023 and 2024.
Citizen Lab did not identify who actually used Pegasus to target the former lawmaker, but it linked some of the hacking activity to earlier discoveries that Pegasus was used to spy on Russian- and Belarusian-speaking journalists and activists in exile.
Apple did not directly address questions Kouloglu, but said the vulnerability referred to in the Citizen Lab report had since been patched and that it regularly issued alerts to hacking targets.
Sophie in ‘t Veld, a former EU lawmaker who championed the PEGA committee’s creation, said the hacking of Kouloglou’s phone showed how the spread of mercenary spyware had created a surveillance free-for-all.
“We’re in a situation where anybody could spy on anyone and they’re spying on citizens, they’re spying on journalists, they’re spying on NGOs, on lawyers, on politicians, and nobody knows who’s behind it,” she said.
(Reporting by Raphael Satter; Editing by Edmund Klamann)
3 luglio (Reuters) - Un ex membro del Parlamento europeo, che faceva parte di una commissione incaricata di indagare su casi di sorveglianza abusiva, è stato a sua volta vittima di un attacco informatico perpetrato tramite uno strumento di spionaggio di fabbricazione israeliana, ha affermato venerdì un’organizzazione canadese di monitoraggio del settore tecnologico.
Citizen Lab ha dichiarato in un rapporto che il telefono di Stelios Kouloglou, giornalista televisivo greco diventato parlamentare, è stato hackerato almeno tre volte tra ottobre 2022 e marzo 2023 utilizzando lo spyware Pegasus, uno strumento distribuito dalla società israeliana NSO Group.
Al momento degli attacchi, Kouloglou faceva parte della commissione PEGA del Parlamento europeo, istituita nel 2022 per esaminare l’uso di intercettazioni telefoniche illegali in tutta l’Unione europea. La commissione si è concentrata principalmente sull’uso di Pegasus e di strumenti simili, scoprendo che i governi dell’Unione europea probabilmente utilizzavano spyware, «in un modo o nell’altro, in alcuni casi in modo legittimo, in altri illegittimo».
Kouloglou si è detto sbalordito dall’audacia di chiunque ci fosse dietro l’attacco informatico.
«Non mi aspettavo che un membro della commissione PEGA venisse spiato da Pegasus», ha dichiarato a Reuters. «Non mi aspettavo che fossero così sconsiderati».
NSO non ha risposto alle richieste di commento.
In una dichiarazione rilasciata a Reuters, il Parlamento europeo non ha affrontato direttamente il caso di Kouloglou, ma ha affermato che i propri servizi di sicurezza informatica «monitorano costantemente le minacce alla sicurezza informatica e i potenziali attacchi informatici contro il proprio ambiente di lavoro».
Ha precisato che gli strumenti di screening degli spyware sono a disposizione di tutti i parlamentari dal 2022 e che una relazione adottata il mese scorso ne ha sollecitato l’estensione a tutti i dispositivi utilizzati per l’attività parlamentare.
La Commissione europea, l’organo esecutivo dell’Unione europea, non ha risposto immediatamente alle richieste di commento.
NSO ha affermato che i propri strumenti di spionaggio vengono utilizzati per contrastare reati gravi e per proteggere la sicurezza nazionale, ma l’azienda è stata ripetutamente accusata di facilitare la sorveglianza invasiva di giornalisti, oppositori politici, attivisti per i diritti civili e figure religiose in tutto il mondo.
Nel 2021 NSO è stata inserita nella lista nera dal governo degli Stati Uniti a causa di preoccupazioni relative ai diritti umani e alla sicurezza nazionale. L’anno scorso, Meta Platforms, proprietaria di WhatsApp, ha ottenuto un risarcimento danni di 168 milioni di dollari a carico di NSO per aver hackerato illegalmente la piattaforma, sebbene l’importo sia stato notevolmente ridotto. Il mese scorso, Meta ha accusato NSO di aver violato l’ingiunzione del tribunale relativa al targeting dei propri servizi e ha presentato istanza per un’ordinanza di oltraggio alla corte.
Il Citizen Lab ha affermato di ritenere che Kouloglou sia stato vittima di un attacco informatico sfruttando una vulnerabilità nel software Apple all’epoca non nota. Ha aggiunto che Kouloglou ha ricevuto ripetuti avvertimenti da parte di Apple nel 2023 e nel 2024 riguardo a tentativi di hacking sponsorizzati dallo Stato.
Il Citizen Lab non ha identificato chi abbia effettivamente utilizzato Pegasus per prendere di mira l’ex parlamentare, ma ha collegato alcune delle attività di hacking a precedenti scoperte secondo cui Pegasus era stato utilizzato per spiare giornalisti e attivisti di lingua russa e bielorussa in esilio.
Apple non ha risposto direttamente alle domande su Kouloglou, ma ha affermato che la vulnerabilità citata nel rapporto del Citizen Lab è stata nel frattempo corretta e che invia regolarmente avvisi alle persone prese di mira dagli attacchi informatici.
Sophie in ‘t Veld, ex eurodeputata dell’Unione europea che ha sostenuto la creazione della commissione PEGA, ha affermato che l’attacco hacker al telefono di Kouloglou dimostra come la diffusione di spyware mercenario abbia creato una situazione di sorveglianza senza regole.
«Ci troviamo in una situazione in cui chiunque potrebbe spiare chiunque altro: si spiano i cittadini, i giornalisti, le ONG, gli avvocati, i politici, e nessuno sa chi ci sia dietro», ha affermato.
(Reporter Raphael Satter; editor Edmund Klamann)
Scrivici per correzioni o suggerimenti: [email protected]
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
