A European politician who was part of a committee investigating the misuse of NSO Group's Pegasus spyware had his own phone infected with the same surveillance tool, according to multiple reports. The incident underscores the brazen targeting of officials probing the spyware industry and has reignited calls for stricter regulation of commercial cyber-surveillance weapons.

Who Was Targeted and How?

The victim, a member of the European Parliament (MEP) serving on the EU's Pegasus committee, was hacked using NSO's Pegasus spyware, which can remotely take over a smartphone and extract messages, photos, and recordings. The attack was revealed by a joint investigation from The Guardian, Wired, and other outlets, which analyzed data from a leaked NSO customer list. The MEP's name has not been publicly disclosed for security reasons, but sources confirm the infection occurred while the politician was actively investigating the spyware's abuses.

Amnesty International, which has extensively documented Pegasus attacks, noted that the targeting of a committee member represents a new low in the abuse of surveillance technology.

“This is a direct attack on democratic oversight and the rule of law,” said a spokesperson for Amnesty International. “It shows that even those tasked with holding spyware companies accountable are not safe.”

Context: The Pegasus Committee and Ongoing Investigations

The EU's Pegasus committee was established in 2022 to investigate allegations that NSO Group's spyware was used by governments to target journalists, human rights activists, and political opponents. The committee has heard testimony from experts and victims, and its work has been seen as a crucial step toward regulating the spyware industry. The hacking of one of its members is a stark reminder of the risks faced by those who challenge powerful surveillance actors.

According to Wired, the attack was likely carried out by a government customer of NSO Group, though the specific perpetrator has not been identified. The leak mentioned by The Guardian—a massive trove of NSO customer data—has previously revealed widespread abuse of Pegasus in countries like Hungary, Poland, and Spain. In Spain, Amnesty International reported that at least 65 Catalan separatists were targeted with Pegasus, prompting outrage and legal action.

Differing Perspectives on the Story

The coverage of this incident varies across outlets. TechCrunch focused on the irony of a spyware investigator being hacked, emphasizing the vulnerability of even high-profile targets. The Guardian highlighted the broader implications for democratic institutions, framing the attack as an assault on the EU's investigative capacity. Wired took a more technical angle, detailing how the infection was detected and the challenges of attributing such attacks. Amnesty International used the incident to call for a moratorium on the sale of spyware to governments with poor human rights records.

Some sources, such as Yahoo News, initially reported the story but provided limited additional context due to access restrictions. However, the consensus across all reports is clear: the Pegasus spyware continues to be used with impunity, and the mechanisms to hold abusers accountable are insufficient.

Historical Background: The Pegasus Leak

The revelations about Pegasus first exploded into public view in July 2021, when a consortium of media organizations published the Pegasus Project, based on a leaked list of 50,000 phone numbers that were potential targets of NSO clients. The list included the numbers of heads of state, prime ministers, and activists. NSO Group has consistently denied wrongdoing, stating that it sells its products only to vetted governments for use against crime and terrorism. However, investigations have repeatedly shown that Pegasus has been used to surveil civil society, lawyers, and journalists.

The EU committee's work is part of a broader push to regulate spyware. In 2023, the European Parliament passed a resolution calling for strict controls on the export and use of surveillance technology. The hacking of a committee member is likely to accelerate these efforts.

Data Points and Expert Views

According to the Citizen Lab at the University of Toronto, which has tracked Pegasus infections globally, the spyware has been detected in at least 45 countries. The cost of an infection can range from thousands to millions of dollars, making it a tool primarily used by wealthy governments. Dr. John Scott-Railton, a senior researcher at Citizen Lab, commented:

“This is not just about one politician. It's about the systemic failure to control a technology that is inherently designed for abuse.”

NSO Group has not commented on this specific incident, but in past statements, the company has said it investigates any misuse of its products and terminates contracts if violations are found. Critics argue that such self-regulation is inadequate.

Implications and Next Steps

The attack on the MEP has already prompted calls for an immediate EU-wide ban on the use of Pegasus and similar spyware. Some lawmakers are pushing for sanctions against NSO Group and other spyware makers. The incident also raises questions about the security of EU institutions and the need for better cybersecurity protections for elected officials.

As the investigation continues, the Pegasus committee is expected to release a final report later this year. The hacking of one of its own members will likely feature prominently, serving as a stark illustration of the dangers posed by unregulated surveillance technology.

For now, the story serves as a warning: no one is beyond the reach of spyware, and those who seek to expose its abuses may themselves become targets.