The watchdog, hacked while watching
Stelios Kouloglou spent 2014 to 2023 as a Greek Member of the European Parliament and investigative journalist, and from 2022 sat as a substitute member on PEGA — the Parliament's own Committee of Inquiry into Pegasus and equivalent surveillance spyware. According to a Citizen Lab forensic report published July 3, 2026, his iPhone was infected with NSO Group's Pegasus spyware at least three times: on October 21, 2022, and again on March 6 and 7, 2023 — all during periods of active PEGA hearings and deliberations. The October infection landed during what TechCrunch reported were weeks of intense committee correspondence over a draft report on spyware abuse in Cyprus, Greece, Hungary, Poland and Spain. The March infections hit as Kouloglou traveled between Athens and Brussels for committee hearings.
Citizen Lab did not attribute the hack to a specific government and explicitly found "no indications that the Greek Government is responsible." But it identified a technical overlap — the same HomeKit-linked Apple ID used to deliver the exploit — with a campaign the lab documented in May 2024 against Russian and Belarusian opposition journalists living in the EU. That points to "a Pegasus customer with authorization to spy in multiple European countries," as Citizen Lab put it — meaning whoever ran this operation had reach across borders, and used it against the very committee tasked with reining in that reach.
Why this is more than one bad headline
The irony is the story: a body investigating spyware abuse was penetrated by spyware, and its confidential work product — internal deliberations, draft findings, member correspondence on which governments to name — was exposed to whoever operated the tool. Citizen Lab is direct about the stakes: the infection "could have exposed strictly confidential exchanges among PEGA Committee members and their staff, and other sensitive and confidential parliamentary proceedings." A legislative inquiry cannot function if the people conducting it are themselves surveillance targets during the inquiry.
On July 6, 2026, Access Now and more than 30 civil society organizations issued a statement — mirrored in a joint statement coordinated with EDRi — demanding an independent inquiry into the hack, a public accounting of which PEGA recommendations have actually been implemented, effective remedies for identified victims, and stronger enforcement of the EU's Dual-Use Regulation governing spyware exports. "The scourge of spyware must be urgently addressed, as it's a threat to human rights, democracy, and national security," said Natalia Krapiva, Access Now's senior tech-legal counsel. Amnesty International was blunter: "the protections that were put in place to prevent this kind of abuse are still not being implemented."
The steelman: this is exactly the failure mode critics warned about
The civil-society case here is strong and deserves to be taken on its own terms, not waved away. The PEGA Committee's own June 2023 recommendation — adopted by plenary vote after 14 months of hearings and fact-finding missions — called for EU-wide standards restricting who spyware can target, mandatory investigation of abuse allegations, an EU Tech Lab to do independent forensic work, and real remedies for victims. Three years on, none of that exists in binding form. If a sitting parliamentary investigator can be hacked mid-inquiry with no consequence and no clear accountability, the deterrent value of "we studied the problem" is close to zero. That is a legitimate governance failure, not a manufactured scandal.
Where the proportionate response actually lies
Where we'd push back is on the leap from "enforcement gap" to "ban or heavily restrict lawful-intercept tooling." Spyware capable of Pegasus-grade access is also the tool that lets EU member states investigate terrorism financing, organized crime and child exploitation networks that operate on encrypted platforms — capabilities no legislative body has proposed replacing. The 2021 Dual-Use Regulation already requires exporters to seek approval when cyber-surveillance items are likely to be used for human rights violations; the failure documented here is that this catch-all control isn't being applied with teeth, not that the underlying export framework is conceptually wrong. The fix Access Now, EDRi and Amnesty are asking for — enforce the rules on the books, investigate this specific case, publish an implementation scorecard for PEGA's recommendations — is targeted and proportionate. It does not require banning a category of security technology; it requires the European Commission to do what Parliament already told it to do in 2023.
The credibility cost of inaction compounds with each new case. A second Pegasus scandal involving the exact institution built to prevent Pegasus scandals is the strongest evidence yet that voluntary compliance and Commission foot-dragging, not the Dual-Use Regulation's design, are the problem. The Commission should publish its PEGA implementation roadmap before the next mandate, not the next scandal, forces its hand.