Original briefings. Zero spin.
Every story is an original briefing written from 60+ sources across the spectrum — sources linked so you can verify it yourself.
Citizen Lab Confirms Pegasus Spyware Hacked Phone of EU Politician Investigating Pegasus Spyware

What Happened
Stelios Kouloglou, a Greek journalist and former member of the European Parliament, had his iPhone compromised by Pegasus spyware in October 2022 and at least twice in March 2023. Citizen Lab — the University of Toronto's digital rights research unit — confirmed the hacks and published its findings.
At the time of each compromise, Kouloglou was serving on the European Parliament's PEGA committee, the body specifically created to investigate how European governments were abusing phone spyware. According to Citizen Lab, he is the first member of that committee to be publicly confirmed as a victim of the very surveillance technology his committee was probing.
How the Attack Worked
The attackers used a zero-click exploit, meaning Kouloglou didn't tap a link, open a file, or do anything wrong. The spyware broke in silently. It abused a security vulnerability in Apple's iPhone software related to the company's smart home features.
The flaw had been patched by Apple, but the fix wasn't installed on Kouloglou's phone yet. Once inside, the spyware could pull text messages, correspondence, location data, and photos without his knowledge.
Who Did It?
Citizen Lab did not attribute the attack to a specific country or government.
What researchers did find: the government customer used the same Pegasus-loaded email address previously linked to a separate campaign that hacked journalists across Europe. The reuse of that address implies, according to Citizen Lab, that the same NSO Group customer had authorization to deploy Pegasus across multiple European countries. But that's an inference from a technical fingerprint, not a named perpetrator.
NSO Group did not respond to TechCrunch's request for comment before publication. The European Commission also did not respond.
The October Timing
The October 2022 hack coincided with what Citizen Lab described as intense discussions over email and text message throughout October and November 2022, ahead of the delivery of a first draft describing spyware abuses focusing on Cyprus, Greece, Hungary, Poland, and Spain. The hack also lines up with the period when Kouloglou was in the hospital for a pre-scheduled surgery, which may have allowed the spyware operators to listen in to ambient audio.
Kouloglou told TechCrunch directly that the deliberate compromise of his phone was "reckless." One serving European lawmaker described the hacking as "a direct attack on the rule of law" and called on the European Commission to take concrete action by imposing strict limits on the use of spyware across the 27 member-state bloc.
The Legitimate Law Enforcement Argument
Before drawing sweeping conclusions, the strongest counterargument deserves a fair hearing. Governments across Europe — and the world — have genuine law enforcement needs that commercial spyware like Pegasus was originally designed to address. Tracking terrorists, dismantling trafficking networks, and locating kidnapping suspects are real use cases. NSO Group has consistently argued its tools are sold only to vetted government clients for lawful purposes, and that abuse by individual governments is a misuse of the product, not a flaw in the product itself.
The problem is that the pattern documented across multiple Citizen Lab investigations — journalists, opposition politicians, lawyers, EU committee members — is hard to square with "lawful interception of serious criminals." Kouloglou is not a criminal. He was running oversight. The population of confirmed Pegasus victims keeps not looking like a drug cartel.
Why This Case Is Different
Spyware attacks on elected officials aren't routine. But hacking a committee member while that committee is drafting a report on spyware abuse isn't just a privacy violation. It's potential interference with a legislative oversight function.
Citizen Lab noted that months after the October 2022 hack, Kouloglou's phone was compromised again on March 6 and 7, 2023, while he traveled from Athens to Brussels during a period of committee hearings and months prior to the committee finalizing and adopting their written draft report.
What Comes Next
One serving European lawmaker is calling on the European Commission to take concrete action by imposing strict limits on spyware use across all 27 EU member states. Kouloglou said he plans to sue NSO Group. Whether the Commission acts — and what "strict limits" would actually look like in enforcement terms — remains the unresolved question this confirmation puts squarely back on the table.
Sources used for this briefing
This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.