1. Executive summary
Citizen Lab researchers have confirmed that the mobile phone of Stelios Kouloglou — a former Member of the European Parliament (MEP) who served on the PEGA Committee investigating commercial spyware abuse — was infected with NSO Group's Pegasus zero-click spyware on at least two occasions (October 2022 and March 2023) during his tenure on the committee. The same Pegasus operator is linked by Citizen Lab to a separate series of infections targeting seven Russian- and Belarusian-speaking journalists and opposition figures between August 2020 and January 2023, based on shared targeting email infrastructure. Attribution to a specific government is unconfirmed: Kouloglou alleges Greek government responsibility, but Citizen Lab states it has no indications supporting that claim. No verified CVE data, CVSS scores, or CISA-KEV exploitation states have been resolved for this item. For EMEA financial services, the primary risk is demonstration of sustained, targeted zero-click mobile spyware capability against high-value individuals engaged in sensitive institutional work — a pattern directly relevant to executives, compliance officers, and regulators.
2. Regulatory framing
| Article | Trigger (the fact in this item) | Practical impact |
|---|---|---|
| DORA Art. 17: ICT-related incident management process | Confirmed spyware infection on a parliamentarian's mobile device during active committee work — an ICT-related incident involving targeted surveillance | Financial institutions should ensure their ICT incident management processes encompass mobile device compromises of senior personnel, including forensic triage and classification of targeted spyware as a major incident category |
| DORA Art. 18: classification of ICT-related incidents and cyber threats | Zero-click spyware deployment against a named individual — a targeted cyber threat with potential intelligence-collection objectives | Institutions should classify targeted mobile spyware infections at a high severity tier given the potential for exfiltration of communications, documents, and contacts |
| NIS2 Art. 23: incident reporting obligations | Confirmed targeted spyware infection of a device belonging to an individual engaged in sensitive institutional work | NIS2-covered entities should ensure incident reporting procedures account for targeted surveillance of key personnel as a reportable incident where it affects the entity's own systems or personnel |
No specific DORA/NIS2 article is directly engaged regarding UK NIS 2018 OES/RDSP duties, as this incident does not involve an essential service operator or relevant digital service provider.
3. Technical analysis & attack chain
Confirmed attack chain
- Target selection: Kouloglou, an MEP serving on the PEGA Committee (investigating commercial spyware abuse), was identified as a target. The timing of the first infection (October 2022) coincided with a period of active committee hearings and preparation of a draft report — less than one week prior to scheduled hearings.
- Initial access vector — zero-click deployment: Pegasus spyware was deployed via zero-click delivery, meaning no user interaction was required on the target device. The specific delivery mechanism (e.g., iMessage exploit chain, WhatsApp vector) is not detailed in the source material. Infections occurred in October 2022 and again in March 2023.
- Targeting infrastructure — operator-specific email: Citizen Lab identified that the same email address used to target Kouloglou was also deployed in attacks against seven Russian- and Belarusian-speaking journalists and opposition figures between August 2020 and January 2023. Citizen Lab asserts that targeting emails are unique to specific operators, establishing a link between the Kouloglou attacks and the Russia/Belarus attacks.
- Operator licensing constraint: Citizen Lab notes that only some Pegasus customers hold licensing allowing operations across multiple countries. The cross-jisdictional pattern (Greece-adjacent MEP target plus Russia/Belarus targets) narrows the pool of potential operator-customers.
- Forensic discovery timeline: Kouloglou brought his phone to Citizen Lab for examination in May 2026. Researchers found evidence that Kouloglou had received three Apple threat notifications about potential spyware in recent years, but Kouloglou stated he never saw them.
- Linked incidents: Citizen Lab's May 2024 report documented the seven Russia/Belarus infections. The Kouloglou report (July 2026) establishes the operator link via shared targeting email.
Spyware capabilities (Pegasus — general, from source context)
Pegasus is described in the source as "a powerful zero-click spyware." The source does not enumerate specific post-exp exploitation capabilities (e.g., microphone activation, location tracking, message exfiltration), file paths, C2 infrastructure, or persistence mechanisms. No CVE identifiers, exploit chain details, or technical IOCs (hashes, domains, IP addresses) are provided in the source material.
Unconfirmed / single-sourced claims (confidence caveat)
- Attribution to Greek government: Single-sourced — claimed by Kouloglou based on his personal assessment. Citizen Lab explicitly states it has "no indications that is true." Greece's prior spyware scandal involved technology manufactured by Intellexa, not NSO Group/Pegasus, which complicates but does not definitively refute the claim. Treat attribution as unconfirmed.
- Apple threat notifications: Reported by Citizen Lab researchers as found during forensic examination. Kouloglou's statement that he never saw them is self-reported. Single-sourced via the Citizen Lab report; verify before enforcement.
- NSO Group response: NSO Group did not respond to a request for comment. No vendor statement is available.
4. Mitigation & containment
P1 — Within 24 hours
- Mobile device security posture review: For executives, board members, compliance officers, and personnel engaged in sensitive regulatory or investigative work, ensure all corporate-managed mobile devices are running the latest available OS versions. Pegasus zero-click exploits historically target unpatched iOS versions; ensure iOS/iPadOS is current.
- Apple threat notification audit: Verify that Apple threat notifications are enabled and monitored for all senior personnel Apple IDs. In this case, three notifications were sent but never seen by the target. Ensure notification delivery is not silently filtered by email rules or device settings. Apple threat notifications are sent via Apple ID registered email and iMessage — confirm both channels are monitored.
- Threat-intintel monitoring: Subscribe to or monitor Citizen Lab and Amnesty Tech Lab publications for Pegasus operator infrastructure disclosures, as targeting email infrastructure has been shown to persist across multiple campaigns over years.
P2 — Within 72 hours
- Mobile device forensic readiness: Establish or refresh the capability to perform forensic examination of mobile devices for senior personnel. Citizen Lab and Amnesty International's Security Lab provide methodologies and tools (e.g., MVT — Mobile Verification Toolkit) for Pegasus detection. Ensure incident response runbooks include mobile device forensic triage as a standard procedure.
- Communication channel review: For personnel engaged in sensitive institutional work (regulatory engagement, M&A, compliance investigations), review the use of end-to-end encrypted messaging platforms and ensure they are patched. Pegasus has historically exploited both iMessage and WhatsApp vectors; ensure all messaging applications are current.
- Awareness briefing: Brief senior personnel on the threat of targeted zero-click spyware, emphasising that such attacks require no user action and may go undetected for years. The Kouloglou infections went undiscovered from October 2022 until May 2026 — nearly four years.
P3 — Within 7 days
- Policy update — mobile incident classification: Update ICT incident management processes (per DORA Art. 17) to explicitly include targeted mobile device spyware infections as a distinct incident category with defined severity classification (per DORA Art. 18). Define escalation paths for incidents involving senior personnel.
- Third-party risk assessment: If the institution or its personnel engage with parliamentary, regulatory, or governmental bodies, assess the risk that personnel may be targeted by state-level spyware operators. Incorporate this into executive-protection and travel-security briefings.
- Tabletop exercise: Conduct a scenario exercise simulating discovery of Pegasus on a senior executive's device, testing forensic triage, incident classification, notification obligations, and communication protocols.
5. Indicators of compromise
No indicators of compromise available in the source material. The Citizen Lab report referenced in the source may contain technical IOCs, but none are provided in the fetched source content. No file hashes, domains, IP addresses, email addresses, or C2 infrastructure details are available.
Confidence caveat: The targeting email identified by Citizen Lab as linking the Kouloglou and Russia/Belarus attacks is a potential IOC, but its value is not disclosed in the source material. Single-sourced via Citizen Lab; verify before enforcement.
6. Detection
Insufficient indicators to author detection rules. The source material does not contain file hashes, file names, paths, registry keys, mutex names, C2 domains, IP addresses, distinctive strings, or command-line artefacts that could be used to construct YARA or Sigma rules. The Citizen Lab report itself (not provided in source material) may contain such artefacts.
7. Sources
- The Record / Recorded Future News — "Spyware found on phone of European Parliament member probing it" — https://therecord.media/pegasus-spyware-european-parliament-pega-committee-member — 2026-07-03
- Citizen Lab (referenced) — Report released 2026-07-03 (Friday) detailing Pegasus infections of Stelios Kouloglou; linked to May 2024 Citizen Lab report on seven Russian/Belarusian journalist infections. No direct URL provided in source material.
8. Adverse Trace position
Severity assessment: HIGH for targeted-individual risk; MEDIUM for institutional risk. This is a confirmed, forensically validated deployment of zero-click commercial spyware against a sitting parliamentarian engaged in sensitive investigative work. The infections went undetected for approximately four years (October 2022 to May 2026), demonstrating the persistent, low-visibility nature of this threat class. No verified CVE/CVSS/CISA-KEV data has been resolved for this item — the advisory is based solely on the Citizen Lab report as surfaced through The Record. Attribution to the Greek government is unconfirmed and single-sourced (Kouloglou's personal assessment); Citizen Lab explicitly disputes having evidence for this claim. Client-impact assessment: EMEA financial services clients should treat this as a demonstration of the sustained, targeted mobile-spyware threat to high-value personnel — executives, board members, and staff engaged in regulatory or investigative work are plausible targets for the same class of operator. The shared targeting-email infrastructure linking attacks across multiple countries and target sets indicates persistent, resourced operators with multi-year campaign horizons. Next actions: Adverse Trace will monitor for the full Citizen Lab report and any subsequent IOC disclosures. We will issue an updated advisory if technical indicators (targeting email, C2 infrastructure, exploit chain details) become available. Clients with personnel engaged in EU institutional or regulatory engagement should contact their Adverse Trace analyst for individualised threat assessment.
Published via PulseTrace — Adverse Trace threat intelligence.