Spyware attack on MEP probing Pegasus abuse highlights growing cyber‑espionage threat to EU officials
Executive summary: Researchers found that the mobile device of MEP Stelios Kouloglou was infected with Pegasus spyware after he joined a European parliamentary committee investigating NSO Group’s spyware abuses. The incident shows that commercial spyware can be used to target EU lawmakers conducting oversight, raising national security and democratic oversight concerns.
Who is involved: MEP Stelios Kouloglou, NSO Group (developer of Pegasus), European Parliament committee investigating spyware abuses, and researchers who discovered the compromise.
Likely next: EU legislators may launch inquiries into spyware exports, consider stricter export controls, and EU institutions may boost cybersecurity defenses for officials.
Researchers found that the device of MEP Stelios Kouloglou was compromised after he joined a European parliamentary committee investigating NSO Group’s Pegasus spyware. The intrusion occurred while he was conducting an inquiry into spyware abuses across Europe, raising concerns about the security of EU policymakers. The revelation underscores the growing threat posed by commercial spyware to democratic institutions and may spur stricter export controls and stronger cyber‑security defenses.
Timeline
- — Probe finds former MEP investigating Pegasus was hacked with Pegasus (Politico Europe)
- — Politician who investigated spyware abuses had his phone hacked with Pegasus spyware (TechCrunch)
- — Spyware used against MEP investigating Pegasus abuses, report finds (The Guardian — Business)
Analysis — what this means
Likely next events
- EU Parliament may launch a formal inquiry into Pegasus use against lawmakers
- EU Commission may consider stricter export controls on surveillance software
- NSO Group may face sanctions or litigation from affected officials
- Increased demand for cybersecurity solutions among European institutions
Sectors affected
- Spyware and surveillance technology
- Cybersecurity services
- Defense and aerospace
- EU institutional technology procurement
Regulatory implications
- Increased oversight of private spyware vendors under EU dual‑use regulations
Historical parallels
- 2016 revelations of NSO Group’s Pegasus targeting journalists and activists
- 2020 WhatsApp lawsuit against NSO Group for exploiting a vulnerability
- 2021 EU sanctions on Chinese surveillance firms over human‑rights abuses
Key entities
Sources
- Spyware used against MEP investigating Pegasus abuses, report finds — The Guardian — Business
- Probe finds former MEP investigating Pegasus was hacked with Pegasus — Politico Europe
- Politician who investigated spyware abuses had his phone hacked with Pegasus spyware — TechCrunch