Skip to content
LIVE
The Executives BriefThe Executives BriefBeta

Spyware investigator’s phone was hacked with Pegasus, NSO says a government customer did it

An EU spyware watchdog faced a real Pegasus intrusion, underscoring how oversight can become the next target.

ByYousef Al-ZahraniTechnology Correspondent, The Executives Brief
·3 min read
Spyware investigator’s phone was hacked with Pegasus, NSO says a government customer did it
Executive summary

A government customer of NSO Group used Pegasus spyware to hack into the phone of a European politician. At the time, the politician served on an EU committee investigating the spyware industry.

A European politician who helped investigate spyware abuses had his phone hacked with Pegasus spyware, using NSO Group technology through a government customer, according to the report. The detail that makes this land hard is timing: the politician was serving on an EU committee tasked with investigating the spyware industry when the intrusion happened.

That means this was not a hypothetical “trust us” oversight test or a distant geopolitical tale. The same ecosystem under scrutiny was allegedly active inside it. If an EU committee member looking at spyware abuses can still be targeted, the basic assumption behind oversight weakens: monitoring the market does not automatically protect the monitors.

To understand why this matters to decision-makers, it helps to zoom out to how spyware procurement and accountability typically work in the real world. Pegasus is sold to government customers, and that creates a firewall problem for everyone else. Vendors are often insulated by government procurement structures, while governments can treat operational details as sensitive. That makes it difficult for regulators, legislators, and watchdogs to trace harm from a specific tool to a specific authorization, especially across borders. So even when policy work happens at the EU level, the operational layer can still move faster, and more quietly, than public oversight.

The EU committee angle matters for another reason. EU-level investigations do not just generate headlines, they shape standards, regulatory thinking, and the political legitimacy of enforcement. A committee member is usually meant to bring scrutiny and institutional credibility. When the reported target is the investigator, it turns oversight into a kind of live stress test: can oversight processes identify and deter abuse quickly enough to reduce harm?

There is also a governance and incentives angle. Committees and regulators rely on cooperation from the institutions and states that are also embedded in procurement relationships. If those relationships are the source of the threat, there can be hesitation to push too hard. Not because oversight leaders want to fail, but because escalation can trigger political pushback, information withholding, or broader diplomatic fallout. The report does not add new motives, but the dynamic is familiar to anyone who has watched compliance efforts collide with national security narratives.

Second-order implications extend well beyond one phone. If Pegasus-like tools can reach high-scrutiny individuals, then any executive, board member, journalist, or NGO leader who becomes a public-facing subject of investigations may face elevated risk. Even if a specific person is not targeted, the market signal is loud: the spyware industry, or at least its misuse pathways, can withstand scrutiny. That can change how boards think about risk management, how companies structure incident readiness, and how organizations handle sensitive communications.

For investors and tech leaders, the corporate angle is equally uncomfortable. NSO Group’s Pegasus is positioned as a powerful capability sold to governments, and the report centers on a government customer using Pegasus to hack the phone of a politician on a spyware-investigation committee. That creates a credibility problem for the broader narrative vendors sometimes rely on, namely that regulatory attention can contain abuse. When the alleged target is already in the room building the rules, it suggests the gap between policy discussions and real-world operational use can be dangerously large.

Strategically, this is the sort of story that should prompt peers in oversight-adjacent roles to rethink assumptions. The headline fact is specific and consequential: Pegasus spyware was reportedly used to hack a European politician’s phone, and that politician served on an EU committee investigating the spyware industry. If oversight is itself a target surface, then the system needs stronger technical safeguards, faster investigative pathways, and clearer accountability mechanisms that do not collapse under classification or procurement opacity. Otherwise, the same cycle repeats: investigate the problem, get targeted, and then debate deterrence again with fewer protective options than before.

Executive ActionsLocked

This story's Key Insights and Take-aways are locked.

Create a free account to unlock Executive Actions for one credit.

Register to Unlock

Always free for Executives Club members. Join the Club

More in Technology