A Greek prosecutor, not a parliament, now holds the Pegasus file
Former MEP Stelios Kouloglou filed a criminal complaint against NSO Group officials in Athens on 28 September. The forensics behind it are three and four years old; the legal route is what is new.
Kouloglou, a journalist and former member of the European Parliament, filed the complaint with the Athens prosecutor’s office on 28 September, alleging his phone was infected with Pegasus while he sat as a substitute member of the Parliament’s inquiry committee into surveillance software. He said a forensic examination by the University of Toronto’s Citizen Lab dated infections to around 21 October 2022 and again to 6 and 7 March 2023. The filing was reported by Greek public broadcaster ERT and reached this desk through Anadolu and Middle East Monitor — three layers of aggregation off a Greek-language original, and MEMO is the weakest of them. No response from NSO Group was captured, and there is no confirmation that the Athens prosecutor has opened a formal file. The filing is an event; the infection remains a claim resting on Citizen Lab’s forensics.
The rest of the week’s mercenary-spyware traffic is older or unproven. Middle East Eye reported on 8 September, citing unnamed sources familiar with the matter, that Apple notified at least three Turkish ministers of possible mercenary spyware targeting as part of a batch of alerts sent to users in 110 countries, and that Ankara believes the attempts failed because the officials used encrypted applications. That item is three weeks old. Separately, SecurityWeek reported on 29 September that Apple had patched a zero-day, CVE-2026-86950, credited to Meta’s product security team, on the same page noting CISA had set a 28 September federal patching deadline for CVE-2026-65660. Nothing captured links CVE-2026-86950 to commercial spyware, and it should not be written as part of a Pegasus chain.
Assessment: The interesting variable is venue. A parliamentary inquiry produces a report; a national prosecutor produces a docket, discovery obligations and named defendants. Whether that matters turns entirely on a decision nobody has announced — whether Athens opens a file at all. Treat the complaint as filed and nothing more. Two other things to distrust this week: the Citizen Lab report on Pegasus in 45 countries is indexing with a July 2026 date but is the 2018 study, and its Gulf passages on Ahmed Mansoor and on Bahrain’s FinFisher operations describe 2010–2016, not now. And an Apple patch credited to a platform security team, rather than to Citizen Lab or Amnesty, is a different signal than the one readers will assume.