NextFin

Greek Politician Investigating Spyware Had Mobile Phone Hacked

Summarized by NextFin AI
  • The Kouloglou case highlights vulnerabilities in Europe’s spyware oversight, as a PEGA committee member was targeted while investigating spyware abuse.
  • The timing of the attacks coincided with significant legislative discussions, indicating a direct threat to the oversight process.
  • Citizen Lab's findings suggest a broader surveillance issue, affecting journalists and activists, which raises concerns about the effectiveness of current regulatory frameworks.
  • This incident underscores the need for stronger export controls and clearer standards for spyware use to protect democratic processes and civil liberties.

NextFin News - A new Citizen Lab finding has turned Greece’s spyware scandal back on the European institutions that were supposed to scrutinize it: Stelios Kouloglou, the Greek journalist and former European Parliament member who sat on the PEGA committee investigating spyware abuse, was himself targeted with Pegasus. The researchers say his device was hit in October 2022 and again in March 2023, during the same period the committee was drafting its report. That makes the case more than a personal security breach. It exposes how brittle Europe’s spyware oversight can be when the lawmakers doing the oversight are vulnerable to the same tools they are trying to constrain.

Kouloglou was first elected to the European Parliament as a Syriza member and joined PEGA in March 2022, after the committee was created to examine the use of spyware across the bloc. Citizen Lab says his mobile device was first infected on 21 October 2022, then hacked again on 6 and 7 March 2023. The researchers described that first period as a particularly intense phase of PEGA’s deliberations, including work on the committee’s first report, and said the second attack came as the panel was in final drafting discussions. The timing connects the compromise directly to a live policy process rather than to a random cyber incident.

The researchers could not attribute the attacks to a particular government operator of Pegasus. That uncertainty is important. In spyware cases, forensic evidence can identify the tool and the pattern, but not always the political chain of command behind it. Citizen Lab said the same operator likely targeted seven Russian- and Belarusian-speaking journalists and opposition activists based in Europe, and that the attack on Kouloglou bore hallmarks of a previous campaign against exiled Russian and Belarusian journalists. The result is a broader picture of surveillance activity that appears to have crossed from dissidents and reporters into the parliamentary body investigating spyware abuse itself.

The report says the first infection coincided with Kouloglou’s admission to hospital for elective surgery, where he was visited by Greek investigative journalist Thanasis Koukakis. Koukakis had already testified before PEGA about spyware abuse in Greece and was among the victims of the country’s phone-tapping scandal. That overlap matters because it shows how deeply these investigations can penetrate into personal and professional networks. Spyware is not only about reading messages. It can also reveal location, contacts and routine, which is often enough to map a person’s political and investigative circle.

The European significance is hard to miss. PEGA was created in March 2022 after a wave of revelations about Pegasus use against journalists, activists and politicians. Its mandate was to examine how spyware was being used in ways that could violate EU law. Citizen Lab said Kouloglou’s case is the first known instance of a PEGA committee member being targeted with spyware. That turns the committee into a symbol of the larger problem: Europe has oversight structures, but the surveillance market still appears capable of reaching into them.

What The Kouloglou Case Reveals About Oversight

The main lesson is not simply that one politician was hacked. It is that Europe’s anti-spyware architecture can be compromised at the point where it is supposed to be most authoritative. A committee exists, evidence is collected, hearings are held and recommendations are drafted. Yet the investigative process itself may be taking place on terrain already penetrated by the very tools under review. That is a governance failure, not just a cybersecurity failure.

It also shows why commercial spyware remains so hard to regulate. These tools are sold as instruments for crime and counterterrorism, but the practical debate has shifted toward abuse, export controls and the ability of states to use them without crossing legal lines. Once an infection occurs, forensic teams can often identify the family of spyware and reconstruct the infection window. What they cannot always do is identify the state or agency behind it. That gap leaves policymakers arguing over rules while the operational chain stays hidden.

The Kouloglou case makes that gap more visible because the target was not a private individual on the margins of public life. He was serving on a parliamentary committee devoted to documenting spyware abuse. If such a person can be targeted and the perpetrator remains unattributed, it suggests the deterrent effect of current oversight is weak. It also raises the prospect that investigators themselves can be watched, which can chill sources, witnesses and internal debate long before a report is published.

“This case is the ultimate irony of Europe’s spyware crisis. Someone on the very committee tasked with investigating Pegasus gets infected by it,” John Scott-Railton said.

That line captures the central contradiction. Europe can hold hearings, publish findings and pass resolutions, but those measures do not necessarily stop the market or expose the operators. In this case, Citizen Lab said the same operator probably also targeted seven Russian- and Belarusian-speaking journalists and opposition activists in Europe. That suggests a surveillance footprint broad enough to span political dissidents and a sitting parliamentary inquiry, which is exactly the kind of overlap that should alarm regulators.

Why The Timing Matters

The dates matter because they tie the intrusion to an active legislative process. The first infection came on 21 October 2022, about seven months after Kouloglou joined PEGA. The second came on 6 and 7 March 2023, when the committee was in final drafting discussions. This was not a historical compromise discovered in hindsight with no policy relevance. It was contemporaneous with the work of the body tasked with producing Europe’s official response to spyware abuse.

That timing also helps explain why the case resonates beyond Greece. Spyware oversight is often discussed in abstract terms: legal guardrails, transparency standards, export licensing, judicial authorization. But the Kouloglou case shows how those concepts play out in practice. If lawmakers, aides and reporters involved in an inquiry can be watched during the inquiry itself, then the idea of an insulated oversight process starts to look fragile.

Citizen Lab also said the first infection coincided with Kouloglou’s hospital admission for elective surgery and a visit from Greek investigative journalist Thanasis Koukakis. That detail is not merely dramatic. It illustrates a classic capability of advanced spyware: it can help an operator understand a target’s movement and surrounding contacts, not just the contents of messages. For lawmakers, journalists and activists, that kind of visibility can be as damaging as direct message theft because it exposes sources, schedules and personal vulnerabilities.

The institutional stakes are even clearer when viewed against PEGA’s broader mandate. The committee was established in March 2022 after the wider Pegasus scandal and was meant to assess the scope of spyware use in contravention of EU law. Citizen Lab said this is the first known case of a PEGA committee member being targeted with spyware. If Europe’s own inquiry body was penetrated while doing its work, then the debate is no longer just about whether spyware is misused. It is about whether the EU’s political institutions can keep pace with the private surveillance market at all.

For policymakers, that leaves a narrow but concrete agenda: stronger export controls, clearer standards for state procurement, more transparent disclosure when spyware is detected and tighter judicial oversight of deployment. Those steps will not solve every case, and the report does not identify the operator behind this one. But without them, the next inquiry could be just as exposed as the last.

The Outlook For Europe’s Spyware Response

The immediate question is whether European institutions treat the Citizen Lab report as a one-off scandal or as evidence that the oversight model itself needs repair. If lawmakers regard the Kouloglou case as systemic, pressure should increase for tighter rules on spyware use across member states and for better enforcement when those rules are broken.

The broader lesson is that spyware abuse now sits at the intersection of national security, civil liberties and democratic process. The commercial market for these tools is not just a technical niche; it is a political risk. Once it reaches lawmakers and journalists, the damage spills into the legitimacy of the institutions trying to regulate it.

That is why the Kouloglou finding matters well beyond one hacked phone. It suggests that Europe’s spyware problem is not only about who gets targeted, but about whether the systems designed to stop abuse are themselves already inside the blast radius. The uncomfortable part is not just that someone was hacked. It is that he was helping investigate the very industry that did it.

Explore more exclusive insights at nextfin.ai.

Insights

What are the origins of the spyware oversight system in Europe?

What technical principles underlie the operation of spyware like Pegasus?

What is the current market situation for spyware in Europe?

What feedback have users provided regarding spyware regulation in Europe?

What recent updates have emerged regarding the Kouloglou spyware case?

What policy changes are being discussed in light of the Kouloglou incident?

What are the long-term impacts of the Kouloglou case on European spyware policy?

What challenges does Europe face in regulating commercial spyware?

What are the core controversies surrounding spyware use in Europe?

How does the Kouloglou case compare to previous spyware incidents in Europe?

What similarities exist between Kouloglou's case and other political espionage cases?

What steps are being proposed to strengthen spyware oversight in Europe?

What implications does the Kouloglou case have for future legislative inquiries in Europe?

How might the surveillance market evolve in response to the Kouloglou case?

What are the potential risks of lawmakers being spied on during investigations?

What can be learned from the Kouloglou case regarding the effectiveness of current oversight measures?

What role does public perception play in the debate over spyware regulation?

What are the implications for civil liberties in relation to spyware use by governments?

Search
NextFinNextFin
NextFin.Al
No Noise, only Signal.
Open App