The Digital Rights Research Institute of the University of Toronto, Canada, Citizen Lab, confirmed that Greek journalists and former members of the European Parliament, Stelios Kouloglou, had been subjected to numerous hacks of the spy software during his participation in the European Parliament's Pegasus survey. The incident once again pushed the question of whether European governments are abusing surveillance tools.

The invasion took place in the investigative advance.

This is the first time that a member of the PEGA committee of the European Parliament has been publicly identified as a victim of espionage software. The Commission investigates whether multiple European Governments have used mobile phone spy software to monitor journalists, parliamentarians and critics.

Citizen Lab reported on Friday that the iPhone of Kouloglou was attacked at least twice in October 2022 and March 2023. The attack took advantage of a security gap in the Apple iPhone software. Before the patches were installed on his mobile phone, the attackers planted them in Pegasus.

Such attacks are “zero-click” incursions, where the victim may be controlled without having to click a link or attachment. According to researchers, the attackers have access to private information such as text messages, correspondence records, location data and photographs.

Signs of cross-border activity by the same operator appear.

The report mentions that the time of the invasion in October 2022 coincided with intensive communication between the PEGA Commission around the first draft investigation. The draft covers the misuse of spy software in Cyprus, Greece, Hungary, Poland and Spain.

Citizen Lab did not directly name specific countries, but indicated that Pegasus, which was used in the attack, delivered mailboxes, in line with previous attacks against several European journalists. This means that government clients behind them are likely to use the same set of surveillance tools in several European countries.

On 6 and 7 March 2023, Kouloglou was again attacked by the same operator while travelling from Athens to Brussels. It was at the stage when the Committee held hearings and advanced its final report.

The incident triggered a new European controversy.

Kouloglou stated to TechCrunch that he believed that he was being targeted in connection with his involvement in the investigation of Pegasus abuse. He claims that he was outraged to learn that his mobile phone had been invaded, as it had been obtained not only for work, but also for a large amount of private life.

One of the current European parliamentarians referred to the matter as a “direct attack on the rule of law” and called on the European Commission to impose more severe restrictions on the use of spy software in 27 member States. The European Commission did not respond to the request for comment.

NSO Group also failed to respond before the report was released. Pegasus was developed by this Israeli company. Kouloglou says he plans to sue NSO Group.

Additional information:The United States had adopted executive orders during the Biden Government to restrict the use of commercial espionage software that might violate human rights. In recent years, NSO Group has also been under constant external pressure because its products have been used to monitor journalists, opponents and politicians.