Skip to content

Pegasus hacked a PEGA committee member’s iPhone, Citizen Lab reveals

Worried woman in business attire sitting at desk with EU flags behind, looking at phone with digital unicorn hologram.

A member of the parliamentary team set up to investigate the misuse of Pegasus spyware has had their own iPhone quietly drained from the inside - an incident that exposes an unsettling, and deeply ironic, security gap at the top of the European Union (EU).

Cybersecurity specialists at Citizen Lab, based at the University of Toronto, have disclosed a particularly awkward case for Brussels. Stelios Kouloglou - a former Greek MEP and journalist - saw his personal iPhone compromised on multiple occasions.

The irony is hard to miss: he was targeted while actively serving on the PEGA committee, a European Parliament body created specifically to examine the abuses of spyware across Europe. This is the first time a member of that official committee has been publicly named as a victim.

How the iPhone “zero-click” exploit was used

To get hold of the MEP’s data, the attackers relied on a highly effective approach: a so-called “zero-click” flaw within iOS. Unlike typical scams, the target did not need to tap a suspicious link or download anything.

Instead, the spyware took advantage of a vulnerability connected to the iPhone’s smart home system to gain entry without drawing attention. Once installed, the software was able to siphon the entire device without the owner realising.

A timeline that raises serious questions

The tool used for the intrusion was Pegasus - widely regarded as the most formidable commercial spyware available. Built by the Israeli company NSO Group, it is marketed to government agencies for counter-terrorism and tackling serious organised crime.

Even so, Pegasus has been at the centre of a global scandal for years. Multiple investigations have shown that some governments have used it to monitor far less legitimate targets: political opponents, human rights campaigners, and journalists. Greece itself has been rocked by a domestic surveillance controversy dubbed the Greek Watergate.

In Kouloglou’s case, the timing of the compromises appears anything but random. Citizen Lab concluded that the first hack took place in October 2022, during a particularly tense period of hearings, as the PEGA committee was drafting its first report on surveillance in Europe.

Two more compromises followed in March 2023 - precisely as the MEP was travelling between Athens and Brussels to finalise that report. Someone clearly wanted to know every last detail of what the committee was doing.

Political inertia

Stelios Kouloglou’s anger is unsurprisingly intense. The former MEP has voiced outrage not only at the theft of professional material, but also at the loss of his most personal photos and memories. Determined to pursue the matter, he has said he intends to bring legal action against NSO Group. Belgian MEP Saskia Bricmont condemned it as “a direct attack on the rule of law”.

But the case also underlines a stark political standstill. Although the PEGA committee delivered its findings and issued strict recommendations, the EU has taken no concrete action. That is “embarrassing” for Europe, according to John Scott-Railton, a senior researcher at Citizen Lab.

Meanwhile, the United States has already acted by placing NSO Group on a blacklist. In the absence of firm legislation and a shared technological defence lab, European institutions remain particularly exposed to digital weapons.

Comments

No comments yet. Be the first to comment!

Leave a Comment