FAULT LINES
Signals That Move Strategy
Rules of the Game · Europe · Intelligence & Counterintel

Pegasus Spyware Infected European Parliament Investigator Twice During PEGA Probe

Stelios Kouloglou, a former European Parliament member serving on the committee investigating commercial spyware abuses, was infected with Pegasus spyware twice while on the committee, according to researchers cited by The Record. The infections occurred during his tenure on the PEGA (Special Committee on the Protection of Children in the Digital Environment and other related aspects of digital services) committee.
AI synthesis, editor-reviewed · 1 source · July 03, 2026
Photo: The Record (Recorded Future)

If Pegasus operators successfully compromised a PEGA committee member's phone during the investigation, they gained real-time visibility into the committee's findings, witness testimony, and strategic direction. This creates a cascading credibility problem: any recommendations the PEGA committee issues can now be framed as potentially influenced or pre-empted by operators who knew what was coming.

EU member states considering stricter spyware export controls or licensing frameworks will face pressure to delay or weaken rules, citing the breach as evidence that enforcement is futile if investigators themselves are compromised. Watch for member states to cite this incident during upcoming Digital Services Act or cybersecurity directive negotiations.

WHY IT MATTERS

A sitting investigator of spyware abuses was himself targeted with the tool under investigation — a direct signal that Pegasus operators are actively monitoring EU institutional oversight.

Kouloglou's dual infections during active committee work suggest either that the targeting was ongoing counter-surveillance against the probe itself, or that his communications were compromised throughout his tenure, potentially exposing the committee's investigative strategy and witness contacts. The European Parliament's ability to conduct credible oversight of commercial surveillance tools is now in question if its own members cannot be protected from the tools they are investigating.

WHAT THIS DOESN’T TELL US

Which state or non-state actor deployed Pegasus against Kouloglou? The article does not identify the operator — critical for understanding whether this was counter-intelligence targeting against the EU institution or opportunistic espionage.

Sources: The Record (Recorded Future)
LinkedInX

Fault Lines

Strategic intelligence, synthesized daily — with a public track record. Every call graded against what actually happened.

Front page → Get the weekly brief →