All news
cybersecurityregulation

Pegasus Spyware Hacked EU PEGA Member's iPhone

07 Jul 2026

What happened

Stelios Kouloglou, a Greek journalist and former politician who served on the European Parliament's PEGA committee — the body created to investigate spyware abuses in the EU — has had his phone hacked with Pegasus spyware. Security researchers at the University of Toronto's Citizen Lab confirmed the hacking and released a report on Friday.

According to the timeline in Citizen Lab's findings, Kouloglou's phone was first compromised in October 2022, then hacked again at least twice in March 2023, specifically on March 6 and March 7. Kouloglou has said he plans to sue NSO Group, the Israeli-headquartered maker of Pegasus.

How the hack worked

The spyware reportedly exploited a previously discovered flaw in Apple's smart home software using a zero-click exploit — meaning no user interaction, such as clicking a link, was required for the compromise to succeed. This class of exploit is notable because it removes the human element typically relied upon in phishing-based attacks, making detection and prevention significantly harder for the end user.

The report also notes that an unnamed American investment group funneled tens of millions of dollars into NSO Group, though the identity of that group has not been disclosed.

What's still unknown

Several key details remain unconfirmed or undisclosed in the current reporting:

  • Who ordered or operated the Pegasus deployment against Kouloglou
  • The identity of the American investment group that funded NSO Group
  • NSO Group's response to the allegations and the planned lawsuit
  • Whether the underlying Apple smart home software flaw has since been patched
  • The status of any legal proceedings
  • Whether other PEGA committee members were similarly targeted

Why founders should care

This incident carries several implications worth weighing for early-stage founders, particularly those handling sensitive data, operating in regulated sectors, or engaging with policymakers and oversight bodies:

  • Patching may not be enough. Because the exploit leveraged a previously discovered flaw, founders should likely treat prompt device and OS updates as a baseline security practice rather than a one-time fix — known vulnerabilities can remain exploitable longer than expected.
  • Oversight roles may carry elevated risk. Kouloglou's role investigating spyware abuses appears connected to his targeting, suggesting that founders or team members involved in compliance, investigative, or regulatory-adjacent work could face a higher likelihood of being targeted by similar tools.
  • Investor due diligence matters. The report's mention of an unnamed American investment group funding NSO Group suggests founders may want to scrutinize not just who invests in their own companies, but how capital flowing into the broader surveillance-technology ecosystem could indirectly affect their industry's risk profile.

Bottom line

With Citizen Lab's confirmation now public and a lawsuit reportedly forthcoming, this case is likely to keep spyware accountability — and the vulnerabilities that enable it — in the spotlight. Founders operating in cybersecurity-adjacent spaces, or those simply relying on iPhones for sensitive communications, may want to treat this as a reminder that zero-click threats remain an active and evolving risk category.

Sources