Security researchers have confirmed that a European politician's mobile phone was hacked with Pegasus spyware while he was serving on a commission of inquiry investigating the misuse of the notorious surveillance tool. This has reignited a new controversy over the government's misuse of spyware to gather information about its critics.
Researchers at the University of Toronto's Citizen Lab digital rights division said the confirmed phone hacking of Greek journalist and former politician Stelios Kouroglou in 2022-2023 marks the first time that a member of the European Parliament's PEGA committee, which is tasked with investigating phone spyware attacks by European governments, has been publicly identified as a spyware victim.
Kouroglou told TechCrunch by phone that intentionally compromising cell phones was “reckless.” One sitting European lawmaker described the hacking of Couroglou's phone as a “direct attack on the rule of law” and called on the European Commission to take concrete action, including imposing strict limits on the use of spyware across the 27-member bloc.
Spyware attacks on members of Congress are rare, but the timing and targeting of the committee's investigators with the very spyware they are investigating suggests an increased focus on the committee's internal affairs ahead of a widely anticipated report detailing its findings. The hack raises new questions about how the government uses spyware, ostensibly needed to identify serious crimes, but later discovered to have been spying on the communications of journalists, lawmakers and commentators.
Citizen Lab researchers said that while the phone hacking was not attributed to a specific country, the government customer used the same Pegasus-powered email address used in a previous campaign that hacked journalists' phones across Europe. Although the customer's identity is unknown, the reuse of the same attack email address means the customer had permission from NSO Group to use Pegasus spyware to spy on phones across multiple European countries.
A European Commission spokesperson did not respond to TechCrunch's request for comment. NSO Group also did not respond to requests for comment on the Citizen Lab report prior to publication.
Citizen Lab said in a report released Friday that Kuroglou was hacked at least twice in October 2022 and March 2023 using an exploit that compromised security vulnerabilities in Apple's iPhone software. Although the vulnerability had been patched, Kouloglou's phone did not yet have the fix installed. This exploit is a “zero-click” bug, meaning that the spyware entered and stole data without any interaction required on the user's part.
The bug exploited a previously discovered flaw in Apple's smart home software used in iPhones. This allowed the spyware to obtain personal data from Mr. Couroglou's phone, including text messages and other communications, location data, and photos, without his knowledge.
The timing of the October 2022 hack coincides with intense discussions via email and text messages in October and November 2022, prior to the submission of the first draft document describing the spyware exploits, which focused on Cyprus, Greece, Hungary, Poland and Spain.
The hack also occurred at the exact time that Mr. Couroglou was in the hospital for a scheduled surgery, which may have allowed spyware operators to listen to ambient audio discussing his health and other conversations he had with visitors at the time.
A few months later, on March 6 and 7, Citizen Lab announced that Mr. Couroglou's phone had been hacked again by the same Pegasus operator while he was traveling from Athens to Brussels, during the committee hearings and months before the committee finalized and adopted the draft report.
During the call, Kouroglou told TechCrunch that he doesn't know why he was specifically targeted, but believes it was because of his work on a European Parliament committee investigating Pegasus abuses.
He described his anger when he found out his phone had been hacked.
“All your personal data is [was taken] “It's not just all the professional interactions and messages with ministers, but also the very private things, like happy moments and sad moments,” he told TechCrunch.
Kouroglou said he plans to sue Israeli-based spyware maker NSO Group. NSO remains largely banned in the United States following a Biden administration-era executive order outlawing the government's use of spyware that could violate people's human rights.
Last year, the spyware maker admitted that an anonymous American investment group had funneled tens of millions of dollars into the company, perhaps as part of an effort to rehabilitate NSO's brand, which has suffered for enabling human rights abuses.
Couroglou said he intended to publish his story “in the interests of democracy, human rights and the fight against corruption.”
“Corruption concerns everyone,” he said.
If you buy through links in our articles, we may earn a small commission. This does not affect editorial independence.

