{"id":172224,"date":"2025-04-30T17:55:06","date_gmt":"2025-04-30T21:55:06","guid":{"rendered":"https:\/\/midatlanticconsulting.com\/blog\/?p=172224"},"modified":"2025-04-30T17:55:06","modified_gmt":"2025-04-30T21:55:06","slug":"apple-alerts-iphone-owners-targeted-by-government-sponsored-spyware-attacks","status":"publish","type":"post","link":"https:\/\/midatlanticconsulting.com\/blog\/2025\/04\/apple-alerts-iphone-owners-targeted-by-government-sponsored-spyware-attacks\/","title":{"rendered":"Apple alerts iPhone owners targeted by government-sponsored spyware attacks"},"content":{"rendered":"\n<p>Apple recently notified iPhone owners around who were targeted by government-sponsored spyware attacks to help increase their security and privacy.<span id=\"more-1035954\"><\/span><\/p>\n<figure id=\"attachment_939063\" aria-describedby=\"caption-attachment-939063\" class=\"wp-caption aligncenter\"><\/figure>\n<p>\u201cApple detected a targeted mercenary spyware attack against your iPhone,\u201d reads the alert shown in a video that Dutch right-wing activist Eva Vlaardingerbroek <a href=\"https:\/\/x.com\/EvaVlaar\/status\/1917495362161631341\" target=\"_blank\" rel=\"noopener\">posted on X<\/a>, according to a new report in <a href=\"https:\/\/techcrunch.com\/2025\/04\/30\/apple-notifies-new-victims-of-spyware-attacks-across-the-world\/\" target=\"_blank\" rel=\"noopener\"><em>TechCrunch<\/em><\/a>.<\/p>\n<p>Apple is not alone in this; its technology peers like Google and Meta-owned WhatsApp also periodically send similar notifications to their users who became targets of sophisticated spyware attacks. Apple previously issued such alerts to high-profile individuals, but this is the first time we have seen the alert in action.<\/p>\n<h2>Apple notifies victims of the latest iPhone spyware attacks<\/h2>\n<p>\u201cThis attack is likely targeting you specifically because of who you are or what you do,\u201d reads the rest of the Apple notification. \u201cAlthough it&#8217;s never possible to achieve absolute certainty when detecting such attacks, Apple has high confidence in this warning\u2014please take it seriously.\u201d<\/p>\n<p>The message advises turning on the <a href=\"https:\/\/www.idownloadblog.com\/2025\/03\/25\/how-to-use-lockdown-mode-iphone-mac\/\">Lockdown Mode feature<\/a> and updating the iOS software of a hacked iPhone to iOS 18.4.1. It also underscores that opening links or attachments from unexpected or unknown senders is risky. It provides no other information, including the type of attack used.<\/p>\n<p>\u201cWe are unable to provide more information about what caused us to send you this notification, as that may help mercenary spyware attacker adapt their behavior to evade detection in the future,\u201d it says. \u201cApple threat notifications like this one will never ask you to click any links, install an app or profile, or provide your Apple account password or verification code by email or over the phone.\u201d<\/p>\n<blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\">\n<p lang=\"en\" dir=\"ltr\">Yesterday I got a verified threat notification from Apple stating they detected a mercenary spyware attack against my iPhone.<\/p>\n<p>We&#8217;re talking spyware like Pegasus.<\/p>\n<p>All I know for sure right now is that someone is trying to intimidate me.<\/p>\n<p>I have a message for them: It won&#8217;t work. <a href=\"https:\/\/t.co\/mLPVyttFwm\">pic.twitter.com\/mLPVyttFwm<\/a><\/p>\n<p>\u2014 Eva Vlaardingerbroek (@EvaVlaar) <a href=\"https:\/\/twitter.com\/EvaVlaar\/status\/1917495362161631341?ref_src=twsrc%5Etfw\">April 30, 2025<\/a><\/p>\n<\/blockquote>\n<h2>This was a global spyware attack<\/h2>\n<p>Apple only does this if you\u2019re a high-value target, like a politician, a celebrity, an important government contractor, an activist or a journalist. Another confirmed victim who received the Apple alert is Ciro Pellegrino, an Italian journalist with the Fanpage news outlet who blogged about his experience.<\/p>\n<p>Pellegrino reported that Apple informed him about the incident via both an email and a text message. His article on <a href=\"https:\/\/www.fanpage.it\/politica\/sono-il-secondo-giornalista-di-fanpage-ad-essere-stato-spiato-e-ancora-non-so-da-chi-ne-perche\/\" target=\"_blank\" rel=\"noopener\"><em>Fanpage<\/em><\/a> says the message confirmed that \u201ctoday&#8217;s notification is being sent to affected users in 100 countries.\u201d<\/p>\n<p>The type of spyware attack used against these individuals is not known, or at least hasn\u2019t been publicly confirmed by Apple. Previous attacks against Pellegrino&#8217;s colleague Francesco Cancellato leveraged software from an Israeli spyware company called Paragon Solutions.<\/p>\n<p>According to <a href=\"https:\/\/www.theguardian.com\/technology\/2025\/feb\/06\/owner-of-spyware-used-in-alleged-whatsapp-breach-ends-contract-with-italy#:~:text=Paragon%20was%20reportedly%20recently%20acquired,on%20markets%20including%20national%20security.\" target=\"_blank\" rel=\"noopener\"><em>The Guardian<\/em><\/a>, Paragon&#8217;s hacking spyware, called Graphite, can infect a smartphone without any intervention or knowledge on a user&#8217;s part. \u201cIt then gives the operator of the spyware full control and access to messages and encrypted chats sent over apps such as WhatsApp and Signal,\u201d notes the article.<\/p>\n<h2>Multi-million dollar hacking tools<\/h2>\n<p><a href=\"https:\/\/paragonsolutions.io\/\" target=\"_blank\" rel=\"noopener\">The official Paragon website<\/a> says the company provides its customers \u201cwith ethically based tools, teams, and insights to disrupt intractable threats.\u201d The company\u2019s key customers are government clients. Therefore, it\u2019s highly likely that the latest spyware attacks against Vlaardingerbroek and Pellegrino are government-sponsored.<\/p>\n<p>Apple argues that such expensive tools are rarely used to conduct widespread attacks against regular people. But if you\u2019re a VIP, that\u2019s another story. <a href=\"https:\/\/support.apple.com\/102174\" target=\"_blank\" rel=\"noopener\">Apple\u2019s support page<\/a> states that the company has so far notified iPhone owners in over 150 countries who were targeted by mercenary spyware attacks.<\/p>\n<p>Another Israeli spyware company, NSO Group, offers a multi-million dollar surveillance tool, dubbed Pegasus. The company claims that Pegasus can <a href=\"https:\/\/www.idownloadblog.com\/2019\/07\/19\/nso-group-pegasus-iphone\/\">extract data from online services<\/a> like Google Drive or iCloud via infected iPhones. The acknowledgment prompted <a href=\"https:\/\/www.idownloadblog.com\/2021\/07\/22\/amnesty-pegasus-spyware-iphone-checker\/\">Amnesty International to release a free tool<\/a> for iPhone owners to check if their phone has been infected with Pegasus spyware.<\/p>\n<p>Source link: https:\/\/www.idownloadblog.com\/2025\/04\/30\/apple-notifies-iphone-spyware-attack-victims\/<\/p>\n <!-- Easy AdSense Pro: WP is not in the loop.  -->\n","protected":false},"excerpt":{"rendered":"<p>Apple recently notified iPhone owners around who were targeted by government-sponsored spyware attacks to help increase their security and privacy. \u201cApple detected a targeted mercenary spyware attack against your iPhone,\u201d reads the alert shown in a video that Dutch right-wing activist Eva Vlaardingerbroek posted on X, according to a new report in TechCrunch. Apple is [&hellip;]<\/p>\n","protected":false},"author":29,"featured_media":172225,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1,12],"tags":[],"class_list":["post-172224","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-allnews","category-appleindustrynews"],"_links":{"self":[{"href":"https:\/\/midatlanticconsulting.com\/blog\/wp-json\/wp\/v2\/posts\/172224","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/midatlanticconsulting.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/midatlanticconsulting.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/midatlanticconsulting.com\/blog\/wp-json\/wp\/v2\/users\/29"}],"replies":[{"embeddable":true,"href":"https:\/\/midatlanticconsulting.com\/blog\/wp-json\/wp\/v2\/comments?post=172224"}],"version-history":[{"count":1,"href":"https:\/\/midatlanticconsulting.com\/blog\/wp-json\/wp\/v2\/posts\/172224\/revisions"}],"predecessor-version":[{"id":172226,"href":"https:\/\/midatlanticconsulting.com\/blog\/wp-json\/wp\/v2\/posts\/172224\/revisions\/172226"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/midatlanticconsulting.com\/blog\/wp-json\/wp\/v2\/media\/172225"}],"wp:attachment":[{"href":"https:\/\/midatlanticconsulting.com\/blog\/wp-json\/wp\/v2\/media?parent=172224"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/midatlanticconsulting.com\/blog\/wp-json\/wp\/v2\/categories?post=172224"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/midatlanticconsulting.com\/blog\/wp-json\/wp\/v2\/tags?post=172224"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}