Pegasus without borders the Kouloglou case and the threat to democracy by commercial surveillance

Author: Published 4 min de lectura 174 reading

The images in this article were generated with artificial intelligence. How we publish

The Canadian Citizen Lab laboratory has once again placed an uncomfortable reality at the heart of public debate: surveillance with commercial espionage tools is not only a technical abstraction, but a real and concrete threat to democratic supervision. According to his report, former European Member Stelios Kouloglou was repeatedly infected with Pegasus spyware while he was part of the European Parliament committee responsible for investigating precisely the use and abuse of these products. The fact that a member of the commission of inquiry is a direct objective of the object of the investigation reveals a serious gap between regulatory theory and operational practice.

Forensic findings indicate infections in October 2022 and March 2023, taking advantage of a zero-click explosion in the implementation of Apple's smart home function, known by researchers such as PWNYOURHOME and corrected in later iOS updates. In addition, the researchers identified operational matches with a previous campaign for journalists and exiled activists in Europe, suggesting that the client who bought the espionage service was authorized to operate in several Member States. This crossing of jurisdictions, which is possible through commercial licences, makes regulatory frameworks that depend only on national borders insufficient..

Pegasus without borders the Kouloglou case and the threat to democracy by commercial surveillance
Image generated with IA.

The case presents several simultaneous lessons. On the one hand, the technical sophistication of these exploits - zero- click, abuse of IoT implementations and threat notifications that are late or not followed by immediate measures - shows that the individual safety of the device is no longer sufficient guarantee. On the other hand, research also highlights another way of risk: telecommunications networks have been exploited by actors who manipulate protocols such as SS7 and Diameter or send SMS messages with hidden commands to convert a phone into a tracker without installing visible malware. Privacy security combines software, hardware and network architecture factors; mitigation requires technical and regulatory intervention.

For legislators and public institutions, the first obligation is to assume the political scope of the problem. It is essential to establish mandatory intrusion notification mechanisms for public offices and commissions of inquiry, to provide Parliament and administrations with independent forensic capacity and clear response procedures, and to review the permits for the use of surveillance technologies. The European Union already has forums and committees on these issues, such as the PEGA committee itself whose work can be consulted on the European Parliament's website, but making incidents public, auditing suppliers and conditioning spyware export licences are steps that need to be accelerated(see general information on PEGA - European Parliament).

Pegasus without borders the Kouloglou case and the threat to democracy by commercial surveillance
Image generated with IA.

For journalists, activists and high-risk officials, digital hygiene must be complemented by institutional policies: to segregate working devices for sensitive deliberations, to implement security updates as soon as they are available, to verify and act on manufacturer threat reports, and to use reputable forensic laboratories when there are signs of commitment. Citizen Lab and other specialized groups have published guides and analysis on how this type of intrusion is detected and mitigated; their work remains accessible in Citizen Lab. Receiving a notification from Apple or another supplier is not a conclusion, but the start of a coordinated response chain.

At the technological level there are specific measures that reduce the attack surface: separate accounts and devices for critical tasks, minimize the exposure of metadata in communications, use hardware security control solutions and verify the supply chain of security providers. Even so, the structural and political lesson is deeper: the existence of digital mercenaries and suppliers who sell capacities to violate fundamental rights requires contractual transparency, licensing, independent audits and effective sanctions against abuse. Apple has published information on its response to vulnerabilities and iOS updates that correct exploited vectors; it is important to verify these updates in the company's official repositories and apply them without delay ( Apple security updates).

Finally, the Kouloglou case illustrates that technology can undermine the capacity of institutions to monitor their own use. If those investigating cannot have safe channels to deliberate, the deterrent effect on institutional research will be profound. Respond requires combining technical measures, legal reforms and political will to control a trade that now operates in a grey area between security and abuse. Meanwhile, citizens and public officials must act quickly: to audit risk devices, demand transparency on spyware contracts and strengthen forensic and incident response capacities to regain confidence in democratic control over these technologies.

Coverage

Related

More news on the same subject.