Apple will alert users exposed to state-sponsored spyware attacks


AppleInsider is supported by its audience and may earn commission as an Amazon Associate and affiliate partner on qualifying purchases. These affiliate partnerships do not influence our editorial content.

As part of Apple’s initiative to battle state-sponsored spyware, or more specifically the surveillance and monitoring of Apple device owners, the company will alert users when it believes they were targeted in such attacks.

On Tuesday, Apple announced that it filed suit against NSO Group and its parent company over the creation and deployment of the Pegasus spyware.

Ostensibly developed to aid in law enforcement campaigns, Pegasus relies on vulnerabilities, like the now-patched FORCEDENTRY exploit, to install a surveillance package capable of granting access to iOS and Android device microphones and cameras, as well as onboard data. The tool was sold — allegedly indiscriminately — to governments with poor human rights track records, who used it to monitor journalists, activists, researchers, politicians and other targets of interest.

Apple said it is notifying a “small number of users” who were targeted by FORCEDENTRY, and promised to continue to alert customers if and when future attacks are detected.

“Any time Apple discovers activity consistent with a state-sponsored spyware attack, Apple will notify the affected users in accordance with industry best practices,” the company said.

The system is already active, as a Reuters report on Wednesday details alert messages that were sent to at least six Thai activists and researchers.

Apple explains threat notifications in a support document. Noting that a vast majority of users will not encounter state-sponsored attacks due to their inherent nature — expensive, complex and highly targeted — Apple says that if one of its customers is affected, they can expect to be informed in two ways: a prominent alert notification displayed at the top of the Apple ID website and alerts sent via email and iMessage to the address and phone number associated with an Apple ID.

Notifications from Apple will never ask users to click links, open files, install apps or profiles, or provide their Apple ID password or verification code by email or on the phone, the company says. Those who receive a threat notification can verify its authenticity by visiting the Apple ID portal, where an identical alert will appear should the message be genuine.

The tech giant acknowledges that false alarms are possible and that the system might not detect all attacks. As a precaution, users should follow these best practices:

  • Update devices to the latest software, as that includes the latest security fixes
  • Protect devices with a passcode
  • Use two-factor authentication and a strong password for Apple ID
  • Install apps from the App Store
  • Use strong and unique passwords online
  • Don’t click on links or attachments from unknown senders

In addition to the notification service, Apple is providing technical, threat intelligence and engineering assistance to Citizen Lab, the group that first identfied FORCEDENTRY, and will offer the same assistance to similar security research organizations. The company is also donating $10 million and any damages won in its suit against NSO to cybersurveillance research and advocacy organizations.

Leave a Reply