Israel Israel NSO Group Pegasus surveillance policy

Israel's Spyware Export Licensing Regime Failed Its Own Stress Test in Brussels

Pegasus hit an MEP investigating Pegasus abuse — proof Israel's export-control paperwork isn't matched by enforcement.

Pegasus in the Committee That Investigated Pegasus People of Internet Research · Israel 2 Confirmed Pegasus infections Kouloglou's iPhone was hacked in O… 6 PEGA fact-finding countries Poland, Hungary, Greece, Cyprus, S… 0 succeeded Court bids to revoke NSO license Israeli courts have declined to fo… peopleofinternet.com
Pegasus in the Committee That Investig… People of Internet Research · Israel 2 Confirmed Pegasus infections 6 PEGA fact-finding countries 0 succeeded Court bids to revoke NSO licen… peopleofinternet.com

Key Takeaways

A Watchdog, Hacked by What It Was Watching

The Citizen Lab published forensic findings on July 3, 2026 showing that Stelios Kouloglou — a Greek investigative journalist and, at the time, a substitute member of the European Parliament's Committee of Inquiry on Pegasus (PEGA) — had his iPhone infected with NSO Group's Pegasus spyware twice: on or around October 21, 2022, while hospitalized in Greece, and again on March 6–7, 2023, while traveling between Athens and Brussels. Both attacks used a zero-click exploit chain ("PWNYOURHOME") that abused Apple's HomeKit messaging pathway, requiring no action from Kouloglou at all.

The timing is the story. Kouloglou sat on the very committee tasked with investigating illegitimate Pegasus deployments inside the EU — the panel that, after fact-finding missions to Poland, Hungary, Greece, Cyprus, Spain and Israel, found illegal or improper spyware use in at least four member states. Citizen Lab's analysis concludes the infections "would have likely captured non-public information about committee activities," landing during hospital visits and during travel windows tied to hearings and report drafting. A body created to hold the spyware industry accountable was, for a stretch of its own investigation, running the industry's flagship product in its member's pocket.

Crucially, Citizen Lab does not attribute the attacks to a specific government, and explicitly states it found "no indications that the Greek Government is responsible." The researchers instead flag infrastructure overlap with a separate Pegasus operation targeting Russian- and Belarusian-speaking exiled journalists in Europe — pointing to "a Pegasus customer with authorization to spy in multiple European countries." In plain terms: whoever did this was operating a copy of Pegasus that NSO Group had, per Israeli law, licensed for export.

The Case for the Current Regime

Israel's defenders of the status quo have a real argument, and it deserves stating plainly before it's rebutted. Under the 2007 Defense Export Control Law, NSO's sales require case-by-case authorization from the Defense Export Control Agency (DECA) inside the Ministry of Defense, tied to Wassenaar Arrangement dual-use and munitions-list categories, with buyer governments required to sign an End User Declaration restricting use to terrorism and serious-crime investigation. DECA has tightened that declaration over time. And when Amnesty International sued in Tel Aviv District Court in 2020 to force NSO's license revoked, the court declined — expressing confidence in the "thorough and sensitive process" the Defense Ministry uses to grant and monitor licenses, according to reporting on the ruling. Israel is also one of the only jurisdictions in the world that runs any formal end-use licensing regime for offensive cyber exports at all; Chinese, Russian and gray-market vendors selling comparable capability face essentially no equivalent friction. A blunt effort to shut Israeli cyber-arms exporters down entirely would not shrink the spyware market — it would hand it to suppliers with no licensing regime whatsoever.

Why the Kouloglou Case Breaks That Argument

The problem is that the Kouloglou infections are exactly the failure mode the licensing system exists to prevent, and it didn't. If Citizen Lab's read is correct — a licensed customer "authorized to spy in multiple European countries" — then this wasn't a rogue actor circumventing DECA's process. It was, in effect, the process's own output, used against the legislature examining that process's adequacy. Ron Deibert, Citizen Lab's director, put it starkly: someone "likely wanted to breach parliamentary privilege and find out what was going on in that committee," calling the unregulated mercenary spyware industry "poisonous to democratic processes." PEGA committee member Hannah Neumann was blunter still, asking how much more evidence member states and the European Commission need before implementing the committee's own recommendations — adopted by the European Parliament on June 15, 2023, and still largely sitting on paper three years later.

Those recommendations were not radical. They called for strict enforcement of existing EU export control rules, coordination with third countries including Israel and the United States, EU-wide legal standards limiting who lawful spyware can target, and an independent EU Tech Lab to conduct technical audits of suspected abuse. None of that requires banning offensive cyber tools outright — legitimate counterterrorism and serious-crime lawful intercept is a real and defensible use case, and Israel's licensing framework, imperfect as it is, remains more accountable than the alternative of no framework at all.

The Proportionate Fix

What this case demonstrates is a gap between licensing on paper and enforcement in practice — and that gap is where the policy work should go. Israel should extend its End User Declaration regime to include verifiable post-sale field audits, not just pre-sale paperwork, with results reportable to a body like the EU Tech Lab. The European Parliament and Commission should stop treating the 2023 PEGA recommendations as a shelf document and actually legislate the spyware-use standards and remedies for victims that MEPs already voted for. Neither step requires dismantling a legitimate industry. Both are the difference between an export-control regime that looks rigorous and one that has actually been tested — and, in this instance, found wanting.

Sources & Citations

  1. Citizen Lab: Espionage Against the European Parliament
  2. European Parliament: Pegasus spyware inquiry — MEPs outline necessary reforms
  3. CyberScoop: Spyware probe overseer targeted with spyware
  4. TechCrunch: Politician who investigated spyware abuses hacked with Pegasus
  5. CyberScoop: Israeli court rejects Amnesty bid to revoke NSO export license