# Citizen Lab

Type: Company

Source: Cyber Intelligence Brief — https://getcyberbrief.com/entity/citizen-lab
Canonical HTML page: https://getcyberbrief.com/entity/citizen-lab

## Timeline

- **2026-07-03**: Public disclosure — Citizen Lab publishes its findings, revealing the Pegasus infections during the PEGA inquiry.
- **2026-05**: Contact with Citizen Lab — Kouloglou reaches out to Citizen Lab to investigate potential spyware on his device.
- **2024-07**: Kouloglou's term ends — Kouloglou leaves the European Parliament after elections, no longer holding office.
- **2023-07-18**: PEGA Committee concludes — The committee finalizes its work, publishing a report on spyware contraventions of EU law.
- **2023-03-07**: Second infection wave ends — The second infection event concludes, as per forensic timeline.
- **2023-03-06**: Second infection wave begins — A second Pegasus infection period starts, indicating renewed or sustained targeting against the MEP.
- **2022-10-21**: First Pegasus infection — Kouloglou's iPhone is compromised via the PWNYOURHOME zero-click exploit, with forensic evidence of a HomeKit email lookup and mobile data exfiltration.
- **2022-03-24**: Kouloglou appointed to PEGA — Greek MEP Stelios Kouloglou becomes a substitute member of the PEGA Committee.
- **2022-03-10**: PEGA Committee established — European Parliament sets up an inquiry committee to investigate Pegasus and equivalent spyware misuse in the EU.

## Recent coverage (2 stories)

### Zero-Click Pegasus Exploit PWNYOURHOME Hit MEP's iPhone Twice in 6 Months
2026-07-04 02:08:53 · Sentiment: Strongly negative · Impact: 7/10 · Sources: 2

Citizen Lab’s deep-dive forensic analysis reveals a zero-click Pegasus infection on an EU official’s device, demonstrating the stealth and persistence of state-sponsored mobile spyware.
Full story: https://getcyberbrief.com/story/cyber-pegasus-mep-exploit

### First Confirmed: Pegasus Reuses Attack Email to Hack EU Spyware Investigator
2026-07-03 06:37:18 · Sentiment: Negative · Impact: 8/10 · Sources: 2

The reuse of a Pegasus-loaded email address across multiple campaigns, including the hack of a PEGA committee member, highlights the operational persistence of state-linked spyware customers and the inadequacy of current defenses. This incident provides a critical case study for cybersecurity professionals analyzing zero-click exploit chains and infrastructure tracking.
Full story: https://getcyberbrief.com/story/pegasus-spyware-reuses-email-hack-eu-investigator-cyber-threat

---
This page is a machine-readable summary. Sentiment measures the directional read of each development for this entity, not the tone of the reporting; impact weights consequence, not syndication reach. See https://getcyberbrief.com/guides/methodology for the full editorial methodology.