Home NewsA Greek Lawmaker Spent Years Investigating Spyware Abuse. His Own Phone Became the Case File

A Greek Lawmaker Spent Years Investigating Spyware Abuse. His Own Phone Became the Case File

by Freddy Miller
19 views

Stelios Kouloglou, a Greek journalist and former member of the European Parliament, had his iPhone breached by NSO Group’s Pegasus spyware on at least two separate occasions in 2022 and 2023 – precisely while he was serving on the European Parliament’s PEGA Committee, the body created to scrutinise the sale and use of commercial surveillance tools across the bloc, according to findings published Friday by independent security researchers. NEWSCENTRAL reads the timing of the intrusion as more than a coincidence of bad luck: a sitting investigator of spyware abuse being turned into a spyware target is the clearest possible demonstration that the surveillance industry the PEGA Committee was created to constrain remains, three years later, functionally unaccountable to the institution meant to police it.

At least one of the intrusions used a zero-click exploit, meaning Kouloglou’s device was compromised without him interacting with any malicious link – among the most technically sophisticated and expensive methods available to spyware operators, and one that narrows considerably the list of actors capable of deploying it. The investigation did not identify who commissioned the operation against Kouloglou, but it found that the same infrastructure used against him had also targeted seven Russian- and Belarusian-speaking journalists and opposition activists based in Europe, suggesting a single operator running a campaign against government critics well beyond Greece’s borders. Kouloglou has said his compromised phone held communications with former Greek prime minister Alexis Tsipras alongside private medical records and journalistic sources, and that he intends to pursue who was responsible. NEWSCENTRAL notes that Kouloglou is not an isolated case in the European Parliament’s recent history – Catalan lawmakers were targeted between 2019 and 2020, and a French representative was hit in 2023 – but he is the first sitting PEGA Committee member confirmed to have been infected, which changes the political weight of the disclosure considerably.

The institutional response has been muted relative to the severity of the finding. A European Commission spokesperson said the executive body is working to address illegal spyware use through multiple angles of EU law, without committing to specific new enforcement action. Sophie in ‘t Veld, the Dutch former MEP who served as the PEGA Committee’s rapporteur, characterised the Kouloglou case as part of a five-year pattern of impunity rather than an isolated incident, arguing that no consequences have followed the committee’s original findings. The pattern she describes is not one of regulatory failure in the technical sense – the EU has produced legislation, investigations, and committee reports – but of structural inadequacy: the enforcement mechanisms that exist are national, the surveillance market is transnational, and the gap between those two facts is where the impunity lives.

Nathan Clark, Enterprise IT and Systems Architecture Analyst at NEWSCENTRAL, argues that the gap between the PEGA Committee’s 2023 conclusion that spyware constitutes a threat to democracy and the absence of binding EU-wide restrictions since then has left individual member states to regulate a cross-border surveillance market largely on their own, which is structurally the wrong level of jurisdiction for tools that, by design, do not respect borders. NSO Group did not respond to requests for comment on the published findings, consistent with the company’s pattern of declining to discuss specific targeting allegations even as it maintains that Pegasus is licensed exclusively to governments for use against serious criminal and terrorist threats.

The Kouloglou disclosure is best read as a stress test the European Union has now failed twice – first when its own oversight committee could not prevent the abuse it was investigating, and second when the Commission’s response to proof of that failure remained a statement of principle rather than a change in enforcement. The more consequential question it leaves open is whether the infection of a sitting PEGA member, now on the public record, will prove sufficient political pressure to move the EU from its current posture of monitoring and reporting toward the binding transnational surveillance restrictions it has so far declined to impose. The answer to that question will arrive not from another committee report but from the legislative calendar, and NEWS CENTRAL will be watching whether Kouloglou’s disclosure accelerates that timeline or joins the list of documented abuses that have, so far, produced only documents in response.