The EU Committee Investigating Spyware Just Got Hacked by the Spyware It Was Investigating
- Michael Routhier

- Jul 14
- 4 min read
Europe's Spyware Watchdogs Are Being Spied On

Here's a question worth sitting with before I give you the facts. If the people whose entire job is to investigate spyware abuse can't even protect their own phones from that same spyware, what does that tell you about anyone else's chances?
I want you to really consider that, because this isn't a hypothetical. It happened, it's documented, and it happened to someone whose entire professional purpose was to stop exactly this.
What Actually Happened
Stelios Kouloglou, a Greek investigative journalist who served as a member of the European Parliament from 2015 to 2024, sat on a committee called PEGA, created specifically in 2022 to investigate the illegal use of Pegasus spyware and similar tools across the European Union. His job, quite literally, was to hold this industry accountable.
Citizen Lab, the respected Toronto-based research group, later found that Kouloglou's iPhone was infected with Pegasus spyware at least three times; in October 2022 and again in early 2023, during periods that directly coincided with the committee's most sensitive work. The October 2022 infection landed while lawmakers were preparing research missions into government spyware use in Greece, Cyprus, and Spain. The 2023 infection hit while the committee was finalizing its official report.
Kouloglou didn't find out in real time. Apple sent him threat notifications about possible Pegasus breaches, but only months after each infection had already happened. By the time he knew, whoever was behind the attack may already have had access to his private emails, texts, and confidential committee deliberations.
Citizen Lab has not attributed the attacks to a specific government, but their investigation found overlaps with a previously documented Pegasus campaign that targeted exiled Russian and Belarusian journalists across Europe, suggesting the operation was likely run by an authorized NSO Group customer with permission to deploy the tool across multiple European countries.
Ask yourself; does "we don't know who did it" make this more comforting, or less?
Why Citizen Lab Called This "The Ultimate Irony"
I don't use dramatic language lightly, so when a serious research organization calls something "the ultimate irony of Europe's spyware crisis", I think it's worth taking that seriously.
The PEGA Committee existed because European governments had already been caught using Pegasus against journalists, activists, and politicians before it was even formed. It was supposed to be the answer. The accountability mechanism. And instead, the mechanism itself became a target, its own confidential proceedings potentially exposed to the very actors it was trying to investigate.
More than thirty press-freedom organizations have since called on the EU to act, describing what happened as a structural failure, not a one-off incident. That framing matters. This wasn't a fluke in an otherwise well-guarded system. This was proof that the system, as it currently exists, doesn't have the teeth to protect even its own investigators.
This isn't limited to one case, either. In Greece, victims of a separate scandal known as Predatorgate are now suing spyware firm Intellexa for one million euros each in damages, arguing the company's tools were used to violate their privacy on a mass scale.
So here's the question I keep circling back to. If the institutions built specifically to hold this industry accountable can be compromised by the industry itself, who exactly is supposed to protect the rest of us?
What This Means If You Live Outside Europe
I know some of you reading this aren't in the EU, and I don't want you to think this story doesn't apply to you. It absolutely does.
This case proves something bigger than one committee's vulnerability. It proves that even people with institutional resources, legal protection, and professional awareness of exactly what they're up against can still be compromised without knowing it for months. If that's true for a sitting Member of the European Parliament with Citizen Lab's help, it's worth asking what protection an average person actually has.
The answer isn't despair. The answer is understanding what tools exist, what they can actually do, and using them, which is exactly what I break down in the companion piece on protecting your own phone.
Before You Go
I want to know what you think. Does this story change how you view the institutions that are supposed to be protecting your privacy? Or does it just confirm something you already suspected?
Drop it in the comments below, and if you're in Europe, you're part of a growing community of readers here who are learning to check their own devices before something like this happens to them, not after.
Stay sharp. Stay loud.
➡️ Related: [The Same Spyware Family Linked to a Journalist's Murder Now Has a U.S. Government Contract]
➡️ Join thousands of Europeans learning how to check their own phones. Get the free Spyware Red Flags checklist: tech4grownups.com/spyware-checklist
➡️ Join the free Tech 4 Grown-Ups community: tech4grownups.com/community
➡️ Listen to the full podcast episode: [Your AirPods May Be Tracking You - SignalTrace and Surveillance]
Michael Routhier is the founder of Tech 4 Grown-Ups, providing honest, unfiltered digital literacy for adults 55+, and host of The Virtuous Machine, exploring the ethics and human cost of AI. Read by tech-curious readers in 50+ countries. Explore more at tech4grownups.com.
CITATIONS / SOURCES
Al Jazeera - EU Lawmaker Investigating Surveillance Hacked by Israeli Spyware: https://www.aljazeera.com/economy/2026/7/3/eu-lawmaker-investigating-surveillance-hacked-by-israeli-spyware-report-says
Politico Europe - Probe Finds Former MEP Investigating Pegasus Was Himself Hacked With Pegasus: https://www.politico.eu/article/probe-finds-former-mep-investigating-pegasus-was-himself-hacked-with-pegasus/
Business and Human Rights Centre - EU: Pegasus Spyware Allegedly Used Against MEP: https://www.business-humanrights.org/en/latest-news/eu-pegasus-spyware-allegedly-used-against-mep-investigating-spyware-abuses-r
The Hacker News - European Parliament Member Investigating Spyware Was Targeted: https://thehackernews.com/2026/07/european-parliament-member.html



Comments