The Lawxy Times

Author Image
Lawxy Times Reporter

NSO Group: Pegasus Spyware Compromises EU Parliament Committee

The European Parliament's committee investigating spyware abuses was compromised when former MEP Stelios Kouloglou was hacked with Pegasus spyware. This incident raises questions about the protection of fundamental rights and the rule of law in the EU. The hacking occurred during critical phases of the investigation, potentially exposing confidential parliamentary work. The European Commission's inaction on the abuse of Pegasus spyware is under scrutiny.

Full News Breakdown

The hacking of Stelios Kouloglou's phone was discovered by researchers from Toronto University's Citizen Lab, who found that his phone was infected at least twice, on October 21, 2022, and March 6-7, 2023.

  • The PEGA Committee was investigating government use of spyware in Greece, Cyprus, and Spain.

  • The spyware would have given the attacker access to Kouloglou's private emails, text messages, and other communications relating to the committee's deliberations.

  • The researchers are not attributing the hacking to any specific government.

  • The report identifies overlaps with a previously documented Pegasus campaign targeting exiled Russian- and Belarusian-speaking journalists and activists in Europe.

How Does This Affect You?

The revelation of Kouloglou's hacking clarifies the risk of spyware compromising sensitive information. This shift means that individuals and organizations working with sensitive information face a heightened risk of unauthorized access. The impact of this development will be felt by various stakeholders, including lawyers, law students, and businesses.

For Lawyers & Advocates

  • Lawyers advising clients on data protection and privacy matters may wish to consider the risk of Pegasus spyware and review their clients' security measures, including the use of end-to-end encryption and regular device audits.

  • The use of Pegasus spyware creates a compliance obligation for lawyers to protect their clients' personal data, particularly in relation to the processing of personal data by third-party vendors under the General Data Protection Regulation (GDPR) and the UK's Data Protection Act 2018.

  • Lawyers involved in cases related to spyware and surveillance may want to take steps to protect their own communications and data, such as using secure communication channels and encrypting sensitive information.

  • The hacking of Kouloglou's phone highlights the potential consequences of Pegasus spyware for client confidentiality and privilege.

  • Lawyers may find it useful to review their security protocols and conduct regular security audits to mitigate the risks associated with Pegasus spyware.

For Law Students

The decision provides an opportunity to examine EU Data Protection Law, UK Surveillance Law, and the right to privacy and data protection in the face of surveillance and spyware.

  • The core legal doctrine or distinction students should focus on is the balance between national security and individual rights to privacy and data protection.

  • The decision is comparable to Schrems v. Data Protection Commissioner (2015) and Big Brother Watch v. UK (2018), which also dealt with the protection of fundamental rights in the face of surveillance and data processing.

For Businesses

  • Companies providing surveillance and spyware services may want to consider the potential risks and consequences of their use, including the potential for their products to be used to compromise sensitive information.

  • Businesses handling sensitive information may want to review their security measures to prevent hacking and unauthorized access, including implementing robust security protocols and conducting regular security audits.

  • Companies may find it useful to take into account the potential consequences of Pegasus spyware for their reputation and relationships with clients and partners.

  • Businesses may want to consider implementing additional security measures to protect their communications and data, such as end-to-end encryption and secure communication channels.

Key Takeaways

  • The legal principle established: the use of Pegasus spyware against EU officials raises questions about the protection of fundamental rights and the rule of law.

  • The practice consequence: lawyers and businesses may wish to review their security measures to protect against Pegasus spyware and other forms of surveillance.

  • The enforcement consequence: regulators and courts may find it useful to consider the potential implications of Pegasus spyware for the protection of human rights and the rule of law.

  • What to watch next: the European Commission's response to the abuse of Pegasus spyware and the potential for new regulations or directives on surveillance and data protection.

  • General Counsel may want to review and update their company's security measures to protect against Pegasus spyware and other forms of surveillance.

References

  1. Untitled

  2. [PDF] Congress of the United States

  3. Overview of the American Data Privacy and Protection Act, H.R. 8152

  4. [PDF] U.S. – E.U. Convergence: Can We Bridge the Atlantic?

  5. European Commission - Congress.gov

  6. Court of Justice of the European Union - curia

  7. U.S.-EU Trade Relations

  8. [PDF] Reports of Cases - Supreme Court

  9. FACIAL RECOGNITION TECHNOLOGY: PART I ITS IMPACT ON ...

  10. [PDF] EU Data Protection Rules and U.S. Implications - Congress.gov

  11. [PDF] Written Testimony - June 5 Hearing on CLOUD Act - C Wilson Palow

Source: Probe finds former MEP investigating Pegasus was hacked with Pegasus

LAWXY

Legal Intelligence Layer Businesses Rely On

Copyright© 2026 Lawxy AI. All Rights Reserved.

Secure by design. Built for enterprise.

More About Security

Lawxy AI is designed with encrypted infrastructure, access controls, audit visibility, and enterprise-grade security standards.

SOC 2 Type I, II

GDPR

ISO 27001

VAPT Tested

LAWXY

Legal Intelligence Layer Businesses Rely On

Copyright© 2026 Lawxy AI. All Rights Reserved.

Secure by design. Built for enterprise.

More About Security

Lawxy AI is designed with encrypted infrastructure, access controls, audit visibility, and enterprise-grade security standards.

SOC 2 Type I, II

GDPR

ISO 27001

VAPT Tested

LAWXY

Legal Intelligence Layer Businesses Rely On

Copyright© 2026 Lawxy AI. All Rights Reserved.

Secure by design. Built for enterprise.

More About Security

Lawxy AI is designed with encrypted infrastructure, access controls, audit visibility, and enterprise-grade security standards.

SOC 2 Type I, II

GDPR

ISO 27001

VAPT Tested