Why Was a Greek MEP Targeted With Pegasus Spyware?

Why Was a Greek MEP Targeted With Pegasus Spyware?

The digital battlefield of modern surveillance has reached a new legal flashpoint as Stelios Kouloglou, a prominent Greek journalist and former Member of the European Parliament, initiated a rigorous criminal complaint against the NSO Group at the Athens prosecutor’s office. This legal action follows the forensic discovery that his mobile device was compromised by the infamous Pegasus spyware, a tool often reserved for high-stakes military or intelligence operations. By targeting the Israeli firm responsible for this technology, Kouloglou is bringing the complexities of state-sponsored digital espionage into the courtroom. The complaint alleges several serious felonies, including the breach of communication confidentiality, illegal access to information systems, and substantial violations of national data protection laws. This case marks a critical development in Greece’s ongoing struggle with surveillance, highlighting the vulnerability of political figures to sophisticated cyber intrusions that bypass traditional security measures.

Forensic Evidence and Parliamentary Oversight

Central to the legal challenge is the concrete forensic evidence provided by Citizen Lab at the University of Toronto, which confirmed that Kouloglou’s phone was successfully infected with Pegasus on two specific occasions. These breaches occurred in October 2021 and March 2023, creating a timeline that appears both calculated and deliberate. The most striking aspect of this intrusion is that it took place while Kouloglou was actively serving on the European Parliament’s PEGA committee, a specialized body established to investigate the illicit use of Pegasus and similar malware within the European Union. Kouloglou argues that being targeted while investigating the very tools used against him adds a unique layer of gravity to the situation, suggesting a direct attempt to undermine legislative oversight and intimidate those tasked with upholding transparency. This intersection of personal surveillance and official parliamentary duties underscores the brazen nature of the actors involved in these digital operations.

The scope of the surveillance detailed in the legal filing is incredibly exhaustive, representing a near-total collapse of personal and professional privacy for the former MEP. By deploying Pegasus, the perpetrators gained unfettered access to Kouloglou’s private contacts, encrypted messaging history, personal photographs, and sensitive health information. Furthermore, the spyware provided real-time location tracking and the ability to remotely activate the device’s camera and microphone without the user’s knowledge. This capability effectively turned a standard communication tool into a permanent monitoring station that followed the official into closed-door meetings and private residences alike. Beyond the individual violation, the complaint posits that such deep-seated intrusions pose a systemic threat to democratic stability. It argues that compromising the communications of an elected official during an active inquiry directly interferes with the independent exercise of parliamentary mandates and the investigation of matters that are in the public interest.

National Vulnerability and Digital Accountability

While this specific case focuses on Pegasus, it cannot be viewed in isolation from the broader Predator scandal that has previously shaken the foundations of the Greek national intelligence service. Attorney Zacharias Kesses highlighted that the infections persisted even after the initial waves of surveillance scandals became public knowledge in recent years. This suggests that despite increased scrutiny and political pressure, the Greek state remains susceptible to high-end digital espionage orchestrated by external or clandestine actors. The persistence of these attacks indicates a failure in the current defensive protocols designed to protect high-ranking officials and journalists from sophisticated spyware. By moving forward with this judicial inquiry, Kouloglou and his legal team aim to peel back the layers of anonymity that typically shield the operators of these technologies. The case now rests with the Athens first-instance prosecutor, who must navigate a complex landscape of international law to address the felony charges.

The resolution of this case required a paradigm shift in how European institutions approached the regulation of dual-use technologies and the protection of democratic representatives. Experts recommended that the European Union implement mandatory, independent forensic audits for the devices of all officials serving on sensitive committees to detect intrusions in their early stages. Furthermore, the legal proceedings underscored the necessity for a more robust framework of international liability that held spyware manufacturers accountable for the misuse of their products by state or non-state actors. National governments were encouraged to strengthen their domestic whistleblower protections to allow tech experts within intelligence agencies to report illegal surveillance without fear of retribution. Moving forward, the focus shifted toward establishing a digital immunity protocol that granted MEPs specific technical protections similar to their traditional legal immunities. These steps were seen as vital to ensuring that the tools of the information age did not become the primary instruments for dismantling privacy.

subscription-bg
Subscribe to Our Weekly News Digest

Stay up-to-date with the latest security news delivered weekly to your inbox.

Invalid Email Address
subscription-bg
Subscribe to Our Weekly News Digest

Stay up-to-date with the latest security news delivered weekly to your inbox.

Invalid Email Address