Introduction
The European Parliament has been targeted with Pegasus spyware, a powerful surveillance tool developed by NSO Group [1]. A Member of the European Parliament, Stelios Kouloglou, was hacked with Pegasus spyware while serving on the PEGA committee, which investigated spyware abuse in Europe [2]. This incident highlights the significant threat of mercenary spyware to democratic institutions and the need for increased vigilance and security measures.
Background
The PEGA committee was established in March 2022 to investigate the use of Pegasus and equivalent surveillance spyware [3]. Kouloglou, a Greek investigative journalist and Member of the European Parliament, was appointed to the committee as a substitute member in March 2022 [4]. During his time on the committee, Kouloglou was repeatedly hacked with Pegasus spyware, with the first infection occurring on October 21, 2022, and the second on March 6 and 7, 2023 [5].
Implications
The hacking of Kouloglou's device has significant implications for the European Parliament and the democratic process. The Pegasus spyware would have had access to confidential documents and committee deliberations, potentially breaching EU parliamentary confidentiality and privilege frameworks [6]. This incident also raises concerns about the security of the European Parliament's IT systems and the potential for other members to have been targeted [7].
Recommendations
The European Parliament should conduct an immediate investigation into spyware attacks targeting MEPs and parliamentary processes [8]. The Parliament should also consider implementing additional security measures, such as regular screenings for spyware and enhanced cybersecurity guidance for MEPs and staff [9].
Conclusion
The targeting of the European Parliament with Pegasus spyware is a serious incident that highlights the threat of mercenary spyware to democratic institutions. It is essential that the European Parliament takes immediate action to investigate this incident and implement measures to prevent future attacks.
Sources
- Citizen Lab. (2022). Pegasus Spyware.
- European Parliament. (2022). Committee of Inquiry to investigate the use of Pegasus and equivalent surveillance spyware.
- Citizen Lab. (2022). PEGA Committee Established.
- European Parliament. (2022). Stelios Kouloglou appointed to PEGA committee.
- Citizen Lab. (2023). Kouloglou's device infected with Pegasus spyware.
- European Parliament. (2023). PEGA Committee Report.
- Citizen Lab. (2023). Potential breach of EU parliamentary confidentiality and privilege frameworks.
- European Parliament. (2023). Call for immediate investigation.
- Citizen Lab. (2023). Recommendations for additional security measures.


