The Watchdog Got Bitten: When Pegasus Turned on the People Investigating It
There is no crueler plot twist. The person hunting the spyware gets hacked by the spyware. The latest twist in the Pegasus saga lands exactly there: a surveillance tool that now targets the very people trying to rein it in. This is not just another hacking headline, and here is why it should worry you.
Let me be upfront. This is not a story that blew up across Hacker News or X in the last 30 days. But the collision between Pegasus and the European Parliament has been a slow-burning, still-unfolding fight for years now. It is worth pulling the threads back together.
What Pegasus Actually Is
Pegasus is spyware built by the Israeli firm NSO Group. The name sounds elegant. What it does is not. Once planted on a target’s phone, it can pull calls, messages, and photos, and remotely switch on the camera and microphone.
The truly frightening part is how it gets in. This is a so-called zero-click attack. The victim never has to tap a suspicious link or open a file. A single text, or even a missed call, can be enough to hand over the entire device. The user has essentially no way to know they are being watched.
NSO markets Pegasus as a government-only tool for stopping terrorism and serious crime. The problem is the mounting evidence that it has been aimed at journalists, human rights activists, and opposition politicians instead.
When the Watcher Becomes the Watched
The heart of this story is the target. Someone at the European Parliament investigating Pegasus abuse ended up infected by it. The hand digging into the surveillance industry got slapped back with a surveillance tool.
Why does that matter so much? The Parliament took this seriously enough to stand up a dedicated inquiry committee on the Pegasus scandal. In 2023 it adopted a hard-edged resolution demanding an end to illegal spyware use. When a member of that kind of body becomes a target, it reads as a signal: the people running these tools are not afraid of the attempts to regulate them.
Citizen Lab deserves a mention here too. The research group at the University of Toronto is the world’s leading digital forensics outfit for verifying Pegasus infections. When a politician suspects their phone has been cracked, Citizen Lab is what turns that suspicion into scientific evidence. Without independent verifiers like it, cases like this one would likely be dismissed as conspiracy theory.
Why Europe Is So Touchy About This
There is a reason European politics keeps its knives out for Pegasus. In Spain, the “CatalanGate” scandal saw dozens of pro-independence Catalan figures infected. In Hungary and Poland, governments faced accusations of using Pegasus to spy on opposition figures and journalists.
One European People’s Party panel discussion framed it perfectly with its title: the Pegasus spyware scandal and its impact on EU democracy. Note the framing. This is not a cybersecurity problem. It is a democracy problem.
The logic runs like this. Crack an opposition politician’s phone, and their election strategy leaks. Crack a journalist’s phone, and their sources are exposed. Surveil an investigator, and the investigation itself is neutralized. Pegasus stops being about individual privacy and becomes a weapon aimed at the entire system meant to hold power in check.
Why Regulation Keeps Stalling
Europe knows the problem, yet cannot easily shut Pegasus down. The awkward reason is that its own governments are the customers. Plenty of countries adopted the tool in the name of counterterrorism and national security investigations.
That is where the interests tangle. Parliament raises its voice to regulate, while member-state governments have no intention of giving up the toy. “Security when we use it, spying when they do” is the double standard that keeps tripping up reform. It is why proposals to make spyware sales and use transparent keep losing steam.
The Takeaway
The message here is clear. Surveillance tools have grown bold enough to target the very people writing the rules. In a world where the person investigating spyware gets hacked by that spyware, whose phone can honestly be called safe?
Technology is neutral, people like to say. But a tool that can flip on your microphone with zero clicks is a counterterrorism weapon or a gun pointed at democracy, depending entirely on whose hand holds it. The smartphone in your pocket right now — which of those two worlds is it sitting in?
Comments
Loading comments...