The Committee Investigating Spyware Got Spied On With Spyware
Stelios Kouloglou sat on the European Parliament's PEGA Committee — the body set up specifically to investigate how Pegasus spyware was being misused across Europe. According to a new Citizen Lab report, his iPhone was infected with Pegasus at least three times while he served on that very committee.
Pegasus is a commercial surveillance tool made by Israeli firm NSO Group. Once on a phone, it can silently read messages, listen through the microphone, access documents, and monitor calls. The attacker used a zero-click exploit (a method requiring no action from the target — no tap, no link, nothing) in Apple's HomeKit smart home software, codenamed PWNYOURHOME. Kouloglou's phone was running iOS 15.5 at the time of each infection; Apple patched the exploit in iOS 16.3.1.
The infections occurred on October 21, 2022, and again on March 6 and 7, 2023 — the second set coinciding with final drafting discussions for the committee's report. Citizen Lab found evidence that confidential documents and committee deliberations may have been exposed.
No government has been formally attributed. However, Citizen Lab noted an overlap between the first infection and a separate campaign targeting Russian and Belarusian-speaking journalists and activists in Europe, suggesting a single Pegasus operator with reach across multiple EU countries.
Kouloglou received Apple's mercenary spyware threat notifications on three separate occasions. He is the first confirmed PEGA Committee member publicly identified as a Pegasus target while serving.
What you should do: Enable Lockdown Mode on your iPhone if you are a journalist, activist, or work in any politically sensitive role. Go to Settings → Privacy & Security → Lockdown Mode. It restricts some functionality but blocks the class of exploits used here.
Sources

