vulnerability
The MEP Investigating Pegasus Had Pegasus on His Phone
2026-07-03

There is irony, and then there is this. Stelios Kouloglou, a Greek member of the European Parliament who sat on the very committee set up to investigate commercial spyware abuse, had his phone infected with Pegasus twice while the investigation was underway. Once in October 2022, and again in March 2023, according to fresh research from Citizen Lab.
The timing is not a coincidence
The first infection landed less than a week before a run of PEGA Committee hearings and the drafting of its interim report. The second lined up neatly with the final round of negotiations over the committee's recommendations, published in May 2023. Those recommendations have largely been ignored by the European Commission since.
In other words, someone with the means to deploy one of the world's most expensive pieces of commercial spyware was reading over the shoulder of a parliamentarian at the exact moments his committee was writing about them.
Who was on the other end?
Citizen Lab believes the same Pegasus customer was behind Kouloglou's hack and a separate wave of infections targeting seven Russian and Belarusian journalists and opposition figures between 2020 and 2023. Two things link them: the same targeting email was reused across both campaigns, and only a small number of Pegasus customers hold licences to operate across multiple countries. That narrows the pool considerably.
Kouloglou himself points the finger at the Greek government, which has previously been tied to a domestic spyware scandal involving the related Predator tool. Citizen Lab is careful to say it has no evidence to support that specific attribution.
The threat notifications no one read
Here is the detail that lingers. Apple sent Kouloglou three threat notifications over the years, warning him he was being targeted by state-grade attackers. He says he never saw any of them.
By the time researchers finally got hold of the device, fifteen years of messages, photos and conversations were sitting on it. Exchanges with prime ministers, party leaders, and journalists. All of it accessible to whoever was on the other end of the infection. Kouloglou now plans to sue NSO Group, the Israeli firm behind Pegasus.
What the story actually tells us
Hannah Neumann, the German Green MEP who negotiated the committee's report, summed it up cleanly: a government spied on a parliamentarian who was investigating that exact behaviour. That is a story about state power, commercial spyware, and the astonishing brazenness of both.
It is also a quieter story about human behaviour. Threat notifications, from Apple or anyone else, only work if the person on the receiving end actually reads them. And the people most worth targeting, elected officials, senior journalists, executives with access to sensitive information, are often the least likely to slow down and check.
- Two confirmed Pegasus infections in six months, both timed to committee milestones.
- Three ignored Apple threat notifications.
- Fifteen years of data on the device.
- A committee report that Europe's executive has quietly shelved.
The technical side of Pegasus gets most of the attention, and understandably so. The zero-click delivery, the forensic gymnastics required to spot it. But the failure point here was not technical. It was a warning that arrived and went unread.