Pegasus hits the EU Parliament — what it signals for executive digital security
Citizen Lab has documented that a member of the European Parliament’s PEGA committee — the body established specifically to investigate commercial spyware — was themselves targeted and infected with Pegasus spyware. The finding carries an obvious irony, but the more important point is what it illustrates about where this category of threat now operates.
Pegasus is sold exclusively to government customers by NSO Group. Its deployment against a sitting MEP engaged in legislative oversight is a significant escalation: it places state-grade mobile device surveillance inside the institutions designed to scrutinise and constrain it. That’s no longer a distant geopolitical story. It is a live indicator of how broadly and politically these tools are now being deployed.
Why the Private Sector Should Pay Attention
The direct threat to most UK and European businesses from Pegasus itself remains low — the tool is expensive, government-licensed, and targeted. But Citizen Lab’s finding matters to the private sector for two reasons.
First, the techniques developed for high-profile political targets eventually migrate. Zero-click mobile exploits, silent persistence, and exfiltration from encrypted applications were once the exclusive province of state-on-state intelligence operations. They are now documented against politicians, executives, lawyers, and journalists. The attack surface and the methods follow capability, not original intent.
Second, devices that carry email, authentication apps, CRMs, and messaging platforms are high-value targets for any adversary with something to gain. Executive mobile security — device management, network traffic inspection, and operational security hygiene — is no longer a luxury reserved for defence contractors and investment banks.
The Governance Implication
For UK organisations operating post-Brexit, the regulatory backdrop around commercial spyware continues to diverge from the EU’s PEGA-driven framework. Practically, that means UK businesses cannot rely on incoming EU-level constraints to define their security baseline.
If your organisation holds significant trade secrets, is involved in M&A activity, or works in sectors of national interest, this is a prompt to review your mobile security posture. The threat level has not decreased.