Israel Israel NSO Group Pegasus surveillance policy

Pegasus Hacked the Lawmaker Who Investigated Pegasus — Israel's Export Licence Is the Loose Thread

Forensic proof a PEGA Committee member was hacked three times revives scrutiny of Israel's opaque licensing of NSO Group, but the real fix is enforcement, not a ban.

Pegasus, PEGA, and Israel's Licensing Chokepoint People of Internet Research · Israel 3 Pegasus infections confirmed Kouloglou's iPhone was infected Oc… 30+ Civil society signatories Organizations joined Access Now an… ~$500M NSO debt to be shed The pending sale to US investors r… 2007 Export law enacted Israel's Defense Export Control La… peopleofinternet.com
Pegasus, PEGA, and Israel's Licensing … People of Internet Research · Israel 3 Pegasus infections confi… 30+ Civil society signatories ~$500M NSO debt to be shed 2007 Export law enacted peopleofinternet.com

Key Takeaways

A Committee Investigator, Hacked by the Thing He Was Investigating

On July 3, 2026, Citizen Lab published a forensic analysis confirming that Stelios Kouloglou — a Greek investigative journalist who served as a substitute member of the European Parliament's Committee of Inquiry into Pegasus and equivalent spyware (PEGA) from March 2022 to July 2023 — had his iPhone infected with NSO Group's Pegasus spyware at least three times: on October 21, 2022, and again on March 6 and 7, 2023 (Citizen Lab). The infections landed during periods of intense PEGA activity, including deliberations on abuse cases in Cyprus, Greece, Hungary, Poland, and Spain, exposing what Citizen Lab says could have included confidential committee exchanges (TechCrunch).

Citizen Lab did not attribute the hack to a specific NSO customer, but found technical overlap with an operator that had separately targeted Russian and Belarusian exiled journalists across multiple European jurisdictions — suggesting a Pegasus licensee with reach into several EU states, not necessarily Greece itself. On July 6, Access Now, the Committee to Protect Journalists, Amnesty International, and more than 30 other civil society organizations issued a joint statement demanding an independent EU investigation, a full accounting of PEGA Committee targeting, remedies for victims, and implementation of Parliament's 2023 recommendations (Access Now; CPJ).

The Steelman: Why Critics Want Israel's Licence Revisited

The strongest version of the case against Israel's export regime deserves a fair hearing. Under Israel's 2007 Law for Oversight of Security Exports, Pegasus is legally classified as a weapon, and every sale requires a license from the Defense Ministry's Defense Export Control Agency (DECA) (Israel Ministry of Defense). That licensing regime is supposed to be the chokepoint that keeps Pegasus out of the hands of governments that would abuse it. Yet the European Parliament's own PEGA Committee — after a 2022–2023 inquiry that included a fact-finding mission to Israel — found Pegasus and equivalent tools had been used for political and even criminal purposes across multiple EU states, and called explicitly for stricter export-control enforcement alongside EU-wide standards (European Parliament). If a sitting member of the very committee tasked with investigating spyware abuse can be hacked with Pegasus while doing that job, the argument that Israeli end-use attestations are functioning as a real backstop looks shakier than DECA's official line — that exports are restricted to "legal purposes" like counterterrorism and serious-crime investigation — would suggest. That is a legitimate structural critique, not a talking point.

Where the Steelman Overreaches

But the Kouloglou case doesn't actually indict Israel's licensing regime specifically — it indicts an accountability vacuum that spans both ends of the supply chain. Citizen Lab was explicit that it could not attribute the hack to a named customer, let alone establish that DECA approved a sale it knew would be misused this way. The joint civil society statement's own ask is telling: it calls on the EU to investigate, not on Israel to revoke licenses. That's the right target, because the accountability gaps this incident exposes — no mandatory device screening for MEPs, no EU-wide legal remedy for spyware victims, and three years of unimplemented PEGA recommendations — are gaps in European oversight of European intelligence services and procurement, not gaps that a different Israeli export policy would automatically close.

It's also worth noting the licensing lever is not dormant. NSO Group's pending sale to a group of American investors led by Hollywood producer Robert Simonds — reported at roughly tens of millions of dollars plus divestment of about $500 million in company debt, and marking the exit of NSO's last Israeli founders — cannot close without DECA approval (Calcalist). That's the licensing regime functioning as a chokepoint on corporate control, exactly as designed. A wholesale export ban, by contrast, would not touch Intellexa/Predator, Candiru, or the next unregulated hacker-for-hire outfit the PEGA Committee also documented — it would just push Pegasus-class capability toward vendors with even less regulatory exposure than an Israeli company subject to a licensing statute at all.

The Fix Is Enforcement, Not Abolition

Commercial spyware serves a genuine, narrow purpose: lawful counterterrorism and serious-crime investigation that European governments themselves rely on. The proportionate response to Kouloglou's hacking is not to treat Israel's export-licensing model as illegitimate, but to make it and its EU-side counterpart actually bite. That means DECA publishing more about post-sale audits and license suspensions when licensed customers are caught misusing the tool — not just at the point of sale — and it means the European Parliament finally legislating the common spyware-use standards its own PEGA Committee recommended in June 2023 rather than letting the file sit for three years. Citizen Lab's narrower ask — mandatory forensic screening for MEPs and published screening statistics — is the kind of concrete, achievable fix that closes the actual gap this case revealed, without pretending that banning a licensing regime that is at least nominally auditable would leave Europe's journalists and lawmakers any safer.

Sources & Citations

  1. Citizen Lab forensic report
  2. European Parliament PEGA reforms briefing
  3. Times of Israel — Israel Defense Ministry on NSO export permits
  4. Access Now press release
  5. CPJ on joint statement
  6. TechCrunch
  7. Calcalist on NSO sale