Back to all lessons
Awareness Lessons
3 months ago

Pegasus Spyware Targets MEP Investigating Spyware Abuses

A member of the European Parliament's PEGA Committee — the body specifically tasked with investigating spyware abuse — had his personal phone compromised twice with NSO Group's Pegasus spyware during active proceedings. This attack highlights a chilling pattern of adversaries targeting the very individuals responsible for oversight and accountability, undermining democratic processes at their most critical moments. The sophistication of Pegasus, which can exploit zero-click vulnerabilities requiring no user interaction, makes traditional security awareness training insufficient on its own. This case underscores that high-value targets, especially those in politically sensitive roles, require proactive, device-level protections and dedicated threat intelligence support — not just policy guidance.

Tactical Insight

Immediate actions

  • Deploy mobile threat defense (MTD) solutions on all devices used by high-risk individuals such as legislators, investigators, and journalists.
  • Perform immediate forensic audits of devices belonging to personnel involved in sensitive investigations using tools like Amnesty International's Mobile Verification Toolkit (MVT).
  • Issue dedicated, hardened devices (e.g., GrapheneOS-based phones) for official communications to individuals in high-profile oversight roles.

Long-term improvements

  • Establish a formal threat model for staff in politically sensitive roles and mandate periodic device security reviews.
  • Implement a zero-trust mobile device policy that restricts installation of third-party apps and enforces encrypted communications via vetted platforms.
  • Engage with national CERTs or specialized groups like Citizen Lab to provide continuous threat intelligence relevant to targeted spyware campaigns.

Detection measures

  • Schedule regular Pegasus/spyware scans using MVT or equivalent forensic tooling as part of a routine security hygiene programme.
  • Enable centralised logging and anomaly detection for device telemetry to identify indicators of compromise (IOCs) associated with known spyware families.
  • Create a clear, accessible incident reporting channel so staff can immediately escalate suspected device compromises to a dedicated security team.