European Parliament Members Investigating Spyware Hacked by Pegasus: The Watchdogs Become the Watched

EU spyware investigators hacked by Pegasus—the watchdogs become the watched.
A European Parliament member serving on the PEGA committee investigating spyware abuse was themselves hacked by Pegasus, NSO Group's zero-click spyware. The incident exposes fundamental failures in democratic oversight when surveillance tools target the very people responsible for regulating them, highlighting the urgent need for international commercial spyware regulation.
A Surveillance Scandal Dripping with Irony
In the ongoing battle between cybersecurity and privacy protection, few events carry more dramatic irony than this: a European political figure specifically responsible for investigating spyware abuse had their phone successfully compromised by the very same type of spyware.
According to reports, a government client of NSO Group used the company's Pegasus spyware to successfully infiltrate the phone of a European political figure. At the time of the breach, this individual was serving on an EU committee specifically tasked with investigating the spyware industry.

This incident is not merely a violation of personal privacy—it represents a direct challenge to the democratic oversight mechanism itself. When those responsible for oversight become the targets of surveillance, the chain of accountability is fundamentally broken.
Pegasus: The Silent, Elite Surveillance Weapon
For readers unfamiliar with this concept, it's worth understanding exactly what Pegasus is and why it inspires such fear.
What Is Pegasus
Pegasus is a commercial-grade spyware developed by Israeli company NSO Group, positioned as a lawful surveillance tool exclusively for governments and law enforcement agencies. NSO Group has consistently claimed that its products are only sold to vetted government clients and are limited to combating terrorism and serious crime.
Founded in 2010 and headquartered in Herzliya, Israel, NSO Group is one of the world's most prominent "Offensive Cyber Intelligence" companies. Israel maintains a strict defense export licensing system for cyber weapons, requiring NSO Group to obtain Ministry of Defense approval before selling Pegasus to specific countries—effectively tying product sales to Israeli foreign policy. However, this regulatory framework lacks transparency, with approval criteria and client lists classified as state secrets. Beyond NSO Group, similar companies include Italy's Hacking Team (which collapsed after a 2015 data breach), Greece's Intellexa (developer of Predator spyware), and others, forming a global gray market worth over ten billion dollars with severely inadequate regulation. In 2021, the U.S. Department of Commerce placed NSO Group on its Entity List, representing one of the most impactful regulatory actions against a commercial spyware company to date.
However, what truly makes Pegasus alarming is its technical capability. It can exploit "zero-click" vulnerabilities in mobile operating systems—victims don't need to click any links or perform any actions for the attack to silently succeed. Once infected, attackers gain access to text messages, call records, location data, encrypted chat content, and can even remotely activate cameras and microphones.
Technical Principles and Attack Economics of Zero-Click Vulnerabilities: Zero-click vulnerabilities represent one of the most dangerous attack vectors in mobile security. Unlike traditional phishing attacks, they exploit memory safety flaws in operating systems or built-in applications (such as iMessage, WhatsApp, or SMS processing modules) when parsing specific data formats. An attacker only needs to send a specially crafted message to the target device—even if the user never opens the message, the underlying parsing process automatically triggers the vulnerability, enabling code injection and privilege escalation. These vulnerabilities are extremely difficult to defend against because the attack chain completely bypasses user interaction—the traditional security awareness advice of "don't click suspicious links" is entirely ineffective against zero-click attacks.
To understand the danger level of zero-click vulnerabilities, we need to examine the underlying logic of software engineering. Modern smartphone operating systems, in pursuit of better user experience, perform "pre-processing" when receiving messages or specific data—for example, automatically generating link previews, decoding media file thumbnails, or rendering rich text formats. These automated processing workflows often invoke complex underlying parsing libraries, and memory safety vulnerabilities lurking within them—buffer overflows, integer overflows, use-after-free bugs—become the entry points for zero-click attacks. Taking the FORCEDENTRY vulnerability exposed in 2021 as an example, it exploited an integer overflow flaw in iOS's image rendering engine when processing PDF format files. An attacker could send a malicious PDF file disguised as a GIF image through iMessage, achieving interaction-free code execution on the target device—the entire process leaves virtually no trace on the phone screen, appearing to the user as nothing more than receiving an ordinary message.
From an attack economics perspective, the scarcity and high value of zero-click vulnerabilities have created a unique cyber arms market ecosystem. Vulnerability broker Zerodium's publicly listed prices show that a full-chain zero-click vulnerability for iOS can command up to $2.5 million—exceeding the unit price of some countries' conventional weapons procurement contracts. This pricing mechanism has spawned "vulnerability hoarding": government agencies and spyware companies prefer to secretly use vulnerabilities for extended periods before they're discovered, rather than disclosing them to vendors to push for patches, thus leaving all users continuously exposed to unknown risks. Security researchers estimate that a high-value zero-click vulnerability has been used in the wild for an average of 12 to 18 months before public disclosure, creating a significant "invisible attack window."
Behind this "vulnerability hoarding" phenomenon lies a profound public interest paradox: the institutions purchasing and using these vulnerabilities often simultaneously bear responsibility for protecting their own citizens' cybersecurity. When national security agencies choose to hoard vulnerabilities rather than push for fixes, millions of ordinary citizens using the same devices in their own country are equally exposed to potential attack risks. The NSA's leaked "EternalBlue" exploit tool eventually made its way to the black market and was used to launch the global WannaCry ransomware attack—the most destructive real-world footnote to this paradox.
Pegasus is also known for its multi-stage infection chain design, integrating zero-click vulnerability exploitation, kernel-level privilege escalation, and persistent residence across three technical modules. After infection is complete, Pegasus actively removes infection traces and disguises itself as a system process, making conventional forensic analysis extremely difficult to detect. Research institutions like Citizen Lab have been able to reconstruct infection paths only by analyzing subtle anomalies in network traffic and system logs. Notably, Pegasus also conducts dedicated research against Apple's "Lockdown Mode" and other hardened security configurations, continuously iterating its infection methods—demonstrating the peak engineering capabilities of commercial spyware.
From Law Enforcement Tool to Abuse Weapon
Despite NSO Group's emphasis on strict client vetting procedures, multiple independent investigations over the years have repeatedly revealed that Pegasus has been widely used to surveil journalists, human rights activists, lawyers, and political opposition figures. It was precisely these well-documented abuse cases that prompted the EU to establish a dedicated committee to investigate.
These abuse cases are not isolated incidents but reveal a clear systemic pattern. Citizen Lab's series of reports since 2016 have documented Pegasus operational infrastructure in at least 45 countries, with victims ranging from journalists at mainstream outlets like The Guardian and Financial Times, to Amnesty International researchers, and even heads of state including French President Macron and Moroccan King Mohammed VI. The 2018 murder of Saudi journalist Jamal Khashoggi, which U.S. intelligence assessments determined was linked to Pegasus surveillance, directly connected commercial spyware abuse to the most severe human rights violations, becoming a pivotal moment in pushing the international community to confront this issue.
The Watchdogs Become the Watched: An Alarm Bell for Democratic Mechanisms
This incident has attracted particular attention precisely because of the victim's special identity.
The European Parliament formally established the PEGA Committee (Committee of Inquiry to investigate the use of Pegasus and equivalent surveillance spyware) in March 2022. The direct trigger was the 2021 exposure of the "Pegasus Project"—a joint investigation published by Forbidden Stories in collaboration with 17 global media organizations revealing that Pegasus had been used to surveil at least 37 phones, targeting heads of state, journalists, and social activists from various countries.
The establishment of the PEGA Committee itself reflects a deep institutional tension within the EU between digital sovereignty and member states' law enforcement autonomy. From an institutional design perspective, the European Parliament's committee of inquiry has quite limited powers: it cannot compel witness testimony, cannot access classified files from member states' intelligence agencies, and cannot impose direct sanctions on member state government actions. Poland, Hungary, and other member states accused of Pegasus abuse have refused to provide the committee with needed information citing "national security." This institutional dilemma means that while the PEGA Committee's final report carries important political symbolic significance, its actual enforcement effectiveness is highly dependent on member states' voluntary cooperation—and precisely those countries most in need of investigation tend to be the least willing to cooperate. Notably, the PEGA Committee is not a permanent EU oversight body; its existence is bound by the European Parliament's term, further undermining its institutional value as a long-term accountability mechanism.
This institutional limitation becomes clearer from a comparative political systems perspective. The EU, as a supranational organization with limited sovereignty transfer, built substantial member state autonomy into its oversight mechanisms from the outset. This design functions adequately in most policy areas, but in national security and intelligence surveillance, "national security exception" clauses provide member states with virtually unlimited legal cover to refuse cooperation. In comparison, U.S. Congressional oversight of domestic intelligence agencies—while also having numerous shortcomings—at least possesses two substantive institutional tools: subpoena power and budget veto authority. The European Parliament lacks both when it comes to cross-border spyware abuse. This structural deficiency means that the blow dealt to the PEGA Committee represents, in a sense, a deliberate demonstration of the limitations of the entire EU oversight architecture.
The PEGA Committee is responsible for investigating the abuse of Pegasus and similar software within EU member states and proposing reform recommendations for the legislative framework. The committee's work involves substantial sensitive witness testimony and transnational intelligence information, making it inherently a high-value intelligence target—and thus naturally a prime attack target for adversaries.
This political figure, serving on the EU spyware investigation committee, was professionally tasked with exposing and curbing the abuse of such surveillance technology. Yet this person—holding sensitive investigation information and exercising oversight functions on behalf of the public—became precisely the target of spyware.
The signals this conveys are deeply unsettling:
- Investigation work may be subject to targeted sabotage. Attackers could gain real-time access to the committee's investigation progress, witness information, and internal discussions, enabling them to plan ahead, interfere with evidence gathering, or pressure relevant individuals.
- The boundaries of political surveillance are blurring. When lawful surveillance tools are used against legislative overseers, promises of "only for fighting crime" ring hollow.
- Accountability mechanisms face systemic risk. If even oversight institutions cannot secure their own communications, ordinary citizens' privacy protections are even more untenable.
The Regulatory Dilemma of the Commercial Spyware Industry
This incident once again thrusts the commercial spyware industry into the spotlight of public scrutiny.
Regulatory Lag and Loopholes
The commercial spyware industry has long operated in a gray zone. On one hand, governments have legitimate national security and law enforcement needs; on the other, sales models lacking transparency and effective oversight make these powerful tools extremely susceptible to abuse. While NSO Group has repeatedly emphasized its compliance review processes, the vague definition of "government client" itself leaves enormous room for misuse.
The current international regulatory framework for commercial spyware is highly fragmented. The Wassenaar Arrangement, the primary multilateral framework for dual-use technology export controls, added "intrusion software" to its control list in 2013, but its non-binding provisions and consensus-based principles severely undermine enforcement. The fundamental limitation of the Wassenaar Arrangement lies in its Cold War legacy design logic: it was originally designed for the proliferation of tangible military materials. When this logic is transplanted to the rapidly evolving software domain, the structural contradiction of "control list update speeds falling far behind technological evolution" becomes unavoidable. The Wassenaar Arrangement currently has 42 member states, but China, Israel, and other major cyber weapons producing countries are not included—a critical gap that fundamentally limits its effectiveness as a global governance framework. A piece of spyware can be legally exported from one member state while being restricted in another, leading to the widespread phenomenon of companies circumventing controls by establishing subsidiaries in jurisdictions with lax regulations.
The Wassenaar Arrangement also faces a unique technical challenge in spyware governance: how to define the boundaries of "intrusion software." Legitimate cybersecurity penetration testing tools, vulnerability research platforms, and spyware often share the same underlying technology at the technical level. The core dilemma facing regulators is how to restrict malicious software proliferation without stifling legitimate security research. In 2015, the first expansion of the agreement's definition of "intrusion software" triggered strong backlash from the security research community—researchers worried that an overly broad definition would expose routine security research activities to export control legal risks, forcing the agreement to subsequently revise the provisions. This struggle reflects the eternal dilemma in technology governance: over-regulation suppresses defensive innovation, while under-regulation enables offensive weapon proliferation.
In 2023, 45 countries including the U.S., UK, and France signed a "Joint Statement on the Proliferation of Commercial Spyware," committing to establishing common standards but lacking specific enforcement mechanisms. At the EU level, the PEGA Committee proposed a series of legislative recommendations, including judicial authorization requirements for spyware deployment and establishing an EU-level technical laboratory for independent spyware testing. However, member state governments' reservations about sovereign law enforcement powers make implementation of these recommendations extremely difficult.
The Challenge of Cross-Border Accountability
Such surveillance often involves cross-border operations—software developed by an Israeli company, purchased by one government, then used to surveil targets in another country. This complex cross-border chain makes accountability extremely difficult and hampers investigation efforts by multilateral bodies like the EU. The continued absence of a regulatory framework is essentially an extension of geopolitical competition and technology sovereignty disputes into cyberspace.
The difficulty of cross-border accountability is not only reflected at the legal level but is deeply rooted in the practical limitations of technical forensics. Pegasus's command-and-control infrastructure employs multi-layer proxies and Domain Fast-Flux techniques, routing attack traffic through servers in multiple intermediate countries to obfuscate the ultimate source of commands. Even if forensic investigators successfully reconstruct the attack chain, converting technical attribution into state responsibility attribution in a legal sense still requires bridging the enormous gap between intelligence information and judicial evidence—the former often cannot be presented in open court due to source protection requirements, making it nearly impossible for victims to obtain remedy through conventional judicial channels. WhatsApp's 2019 civil lawsuit against NSO Group is the only related case to have advanced to substantive trial proceedings in U.S. courts to date, and its arduous journey itself serves as a profound test of the current legal framework's capacity to address transnational spyware threats.
On the technical detection front, Amnesty International's technical team developed the Mobile Verification Toolkit (MVT), which can analyze iOS backup files and Android device images for known Pegasus infection indicators; researchers also monitor anomalous communications between devices and known command-and-control servers through network traffic analysis. MVT works by comparing device logs against a continuously updated database of known malicious Indicators of Compromise (IOC), but this method has inherent limitations—it can only detect "known known threats." For Pegasus variants employing entirely new techniques or that have already erased infection traces, MVT's effectiveness is significantly diminished. NSO Group continuously iterates its software to evade known detection rules, meaning that even regular testing cannot guarantee infallibility. Furthermore, MVT as an open-source tool still has a relatively high usage barrier for ordinary users—it currently primarily serves professional security researchers and auxiliary verification for high-risk target groups, remaining far from being a privacy protection tool accessible to the general public.
The detection dilemma revealed by MVT reflects the structural disadvantage defenders face when confronting high-level attackers. There is a well-known principle in the security field of "attacker-defender asymmetry": attackers only need to find one unpatched vulnerability to succeed, while defenders must cover all possible attack surfaces—a principle that manifests in its most extreme form in the zero-click spyware domain. Citizen Lab researchers have candidly acknowledged that their detection success rate for Pegasus infections falls far below the actual infection rate; a large number of infected devices may never be identified, and the true scale of the victim population likely far exceeds currently documented cases. The existence of this detection blind spot means the actual extent of commercial spyware abuse may be systematically underestimated—which ironically provides a covert but dangerous form of "statistical cover" for regulatory inaction.
Far-Reaching Implications and Insights
For readers concerned with tech ethics and digital rights, this incident warrants deep reflection on several levels.
Power imbalances created by technological asymmetry. When highly advanced surveillance technology is concentrated in the hands of a few institutions, the information gap between the public and overseers continues to widen, and the foundation of democratic accountability erodes accordingly. This asymmetry is not merely a technical issue but reflects structural tension between state power and civil society—between actors possessing nation-state-level attack capabilities and legislative overseers who rely on commercial devices and standard security protections, there exists a capability gap that is nearly impossible to bridge. From a historical perspective, the proliferation of surveillance technology capabilities to non-democratic regimes and authoritarian actors is systematically reshaping the distribution of global power, with long-term impacts potentially far exceeding any single technological event.
This technological asymmetry raises a fundamental question at the political philosophy level: to what extent does the effective functioning of democracy depend on roughly equivalent information access capabilities between overseers and the overseen? Traditional separation of powers theory assumes legislators can effectively oversee executive power, but this assumption rests on a roughly symmetrical information environment between both parties. When executive institutions can use spyware to monitor legislative overseers' communications in real-time while the latter remain completely unaware, this institutional assumption fundamentally fails. This incident is therefore not merely an individual case but a real-world stress test of the theory of separation of powers in the digital age.
The practical limitations of communications security. Even political figures in key positions who should receive stringent protection can still have their personal devices breached by elite spyware. This reminds all organizations and individuals: when facing nation-state-level attackers, traditional security measures may be far from sufficient. Apple's "Lockdown Mode," introduced in 2022, is currently one of the most systematic protection solutions for high-risk users. It works by proactively reducing the attack surface—disabling some message preview features, restricting just-in-time compilation execution, and blocking certain web technologies—to reduce the success rate of zero-click vulnerability exploitation, but at the cost of sacrificing some usability. This trade-off itself reveals the real-world projection of the eternal "usability versus security" paradox in security protection. For political figures, journalists, and human rights defenders engaged in high-risk work, operational security (OPSEC) measures such as using dedicated communication devices, regularly replacing devices, and using end-to-end encrypted communication apps have become unavoidable survival skills in the digital age.
It's worth noting that even Lockdown Mode, currently the strongest protective capability available, is not an infallible silver bullet. Security researchers point out that while Lockdown Mode significantly increases attack costs by reducing the attack surface, attackers can concentrate resources on functional modules that remain open within Lockdown Mode, developing targeted bypass techniques. Fundamentally, without revolutionary changes in underlying hardware and operating system architecture, defense against zero-click vulnerabilities will always be a pursuit rather than an ultimate solution. This reality has prompted some security researchers to engage in deeper reflection on the concept of the "secure phone": perhaps for extremely high-risk targets, regularly using disposable devices and strictly confining sensitive communications to physically isolated environments is a more reliable security strategy than relying on software protections.
The absence of an international regulatory framework. Whether in export controls, sales transparency, or accountability mechanisms for abuse, the commercial spyware industry urgently needs more comprehensive international norms. Otherwise, the absurd scenario of "investigators being investigated" will likely continue to recur.
Key Takeaways
Related articles

MLOps Hands-On Project: A Complete End-to-End Breakdown of Building a Laundry Care Recognition System
A detailed walkthrough of building an end-to-end MLOps laundry care recognition system, covering automated data collection, model retraining, Docker containerization, AWS deployment, and Grafana+Prometheus monitoring.

Deep Dive into Row-Bot's Multi-Agent Orchestration Architecture: Parent-Child Agent Collaboration and Concurrency Control
Deep analysis of Row-Bot's multi-agent orchestration: parent-child Agent collaboration, Git worktree concurrency safety, state persistence, and fault recovery design for production AI Agent systems.

Unsloth Desktop Released: An All-in-One Desktop App for Local Model Inference and Training
Unsloth Desktop is an open-source cross-platform app combining model inference, fine-tuning, and deployment. Supports Mac/Windows/Linux with 2x training speed, 70% VRAM savings, and zero telemetry.