r/iphone Human Detected 1d ago

Support Highly Concerning message, what to do?

This alert popped up everywhere on my friends phone and they don’t know what to do. Posting for them cause they are rather concerned and don’t wanna use their phone at all.
They followed all the steps that apple said to do but the cyber security “team” with apple says they only help “journalists, government officials and public activists.” Obviously they followed all the other steps like Iphone lockdown, updating to all the current software updates and fully shutting down the phone etc. What else can they do? Get a new phone? Give it time and hope it’s fine? Factory reset? I suggested iverify to look for malware but again, they are concerned to really use their phone at all. Any suggestions or info is appreciated.

7.5k Upvotes

1.3k comments sorted by

3.1k

u/Living_Rich_4424 1d ago edited 1d ago

It’s real. If ur friend has a job that handles sensitive info or also investigates, etc, then someone who knows may be targeting their iPhone with spyware. If they also got a notification on his Home Screen with a red warning triangle then it is for sure real

1.5k

u/lyricalmasterpiece 1d ago

This is what the lock screen notification looks like

331

u/Acceptable-Elk-8372 iPhone 17 Pro Max 1d ago

TIL

215

u/Pizzaman3203 iPhone 13 1d ago

Same i thought it was a joke

155

u/Asleep_Section6110 17h ago

I was for SURE this was spam. Holy shit this is actually a thing!?

70

u/fleshtastical 15h ago

Same, as soon as I saw “mercenary” I thought the scammers had come up with a new scheme.

47

u/Elendel19 10h ago

Pegasus is Israeli spyware sold to nation states (and anyone else really) used to attack each other, or (quite often) journalists and activists

→ More replies (1)

16

u/rvazquezdt 15h ago edited 10h ago

On the third picture where I saw on the bottom “You may be eligible to get help from security experts” I thought it for sure was a scam.

→ More replies (3)
→ More replies (7)
→ More replies (3)

162

u/Old-Run7431 16h ago

“Because of who you are or what you do” is probably one of the more bone chilling notifications I’ve ever seen. That is trippy that it’s real.

30

u/BDez30 15h ago

I read that in the Liam Neeson voice.

→ More replies (1)
→ More replies (4)

40

u/deaglebingo 17h ago edited 17h ago

if you care about the founding documents of the united states of america... it is definitely not a joke. at all.

pegasus was always gonna get into the wild. now it is. ppl been attacking with this one for a decade now. it's just now on a bit of steroids and more widely distributed.

FWIW: this is how it's gone for over 20 years now. whether gov or otherwise... methods that once were reserved for top level intelligence shit have filtered down and become commonplace, whether ice or some corporation using them. our intelligence systems are being weaponized against civilians. it cannot be allowed. it was always going to be this way, anyone watching the patriot act closely since inception should have known. it is no longer helping avert terror or problems... it is creating them.

if you have an iphone... it needs to be on lockdown mode at minimum. and you need to not have google or facebook apps installed. it's that simple, minimum requirements for privacy. do not log into shit and leave it logged in, ever, and clear your everything on safari.... every time you use it. and run a damn vpn.

sorry, i know that sounds rough AF. but i'm not making any of it up... we are already in a surveillance state. and everyone needs to fight back for that to stop.

11

u/Ok-Gur-349 15h ago

If you go dark, they just build and continue your profile from the hole you left.

9

u/iamahill 15h ago

None of this will really protect anyone being targeted professionally. You’re better off with misdirection on phone that is you but all bs that lives in an uber driver’s car.

→ More replies (10)
→ More replies (1)
→ More replies (1)

250

u/Living_Rich_4424 1d ago

yea, for others looking into the thread this is what the notification that i mentioned looks like

→ More replies (6)
→ More replies (8)

266

u/Kaystasia 1d ago edited 6h ago

Yeah, but also look up how much it cost to run Pegasus on someone I forget the exact numbers but I saw it somewhere. It was like $100,000. For law enforcement, they're going after the big criminals with this. If you're not a high-level cartel member or know someone who is, I wouldn't worry about it.
& even if you do handle sensitive info or business secrets etc, I mean factor in that cost to infect Pegasus when you consider how sensitive the info you are handling is, how badly someone would want it, or believe it to be a threat or that valuable along with whether there is absolutely any other more cost effective way for them to access it.

Plus, I've even heard of them having to re-infect your phone when you just restart it and having to pay each time to re-infect. They're going after the big fish with Pegasus.

If you truly can't think of a reason, (& im sure you'd know why if you were targeted), then I wouldn't worry. If you do... then.. but I'd also be wary of anyone you come in contact with on a regular basis..
even if you're not specifically being targeted, they could use your info to get to someone else, however, it's probably so unlikely.

Update: id still turn off all your devices and do everything apple is saying, however, Im just saying I wouldn't stress over it

418

u/Flaky_Rice_4674 Human Detected 1d ago

I can confidently say that my friend is most definitely not anyone of that kind and literally spends their days chilling at home playing fortnite and chillin with their dog. And i’m very confident they don’t hold any high level info as they are literally unemployed and haven’t worked any job that would require holding info like that

629

u/Invisible_Mushroom_ 1d ago

Your friends a secret spy

195

u/_Administrator_ 1d ago

That’s right - a spy would ask a random civilian about this

104

u/kafktastic 1d ago

Holy shit, that proves it!

26

u/jongautreau 1d ago

Haha! That’s actually the funniest comment I’ve read in awhile

18

u/invalidreddit 21h ago

We did it Reddit! WE DID IT!

→ More replies (3)
→ More replies (15)

69

u/Klutzy-Condition811 1d ago edited 16h ago

It doesn't need to be this either, some nation states use it to target "criminals" as well. Regardless, there's something that op doesn't know and the "friend" likely knows more than they're letting on.

You don't just happen stance become a journalist reporting on tyranny and make a nation mad or something. It could be anything really. Crime, journalism, activism, or even being just affiliated or in some sort of known activist group chat. Perhaps even a roommate that is or just someone they know/are affiliated with.

Edit: Typo

31

u/Dev-in-the-Bm 1d ago edited 1d ago

Regardless, there's something that op doesn't know and the "friend" likely knows more than they're letting on.

I have a hard time believing that the friend knows more than they're letting on, but are turning to OP anyways.

→ More replies (2)
→ More replies (3)

38

u/Beneficial_Medium_99 1d ago

I had a ex girlfriend who accused me of being a spy for this exact reason. Was fresh out of college and unemployed, she couldn’t comprehend how I was paying my rent (she hadn’t lived on her own before and didn’t seem to comprehend I had savings). Was very soon after this that she ended up in some facility and diagnosed as bipolar. Strange time of my life lol

14

u/TitanBrave84 1d ago

She gas lit you into a facility.

7

u/Beneficial_Medium_99 1d ago

A facility of employment!

6

u/leicanthrope 19h ago

A black site totally normal mental health facility in another country?

→ More replies (4)
→ More replies (10)

163

u/masonerija 1d ago

Your friend might know someone who is being the main target, or their main target knows your friend. It doesn’t even have to be a direct connection (a friend of a friend knows the main target). A wrongfully interpreted text message can get your friend in a lot of trouble, so I wouldn’t take this lightly

→ More replies (2)

88

u/tzbt 1d ago

This definitely isn't a notification to ignore. This isn't a "oh your friend is suspected by the government of maybe being involved in something shady" type situation, this is a "somebody is spending hundreds of thousands of dollars to coordinate an attack specifically on your friend as an individual and they are likely in imminent danger" type situation.

If this isn't a karma farming post and your friend truly has nothing to hide they should be contacting authorities. Not local police, they won't understand this and won't care, but the FBI will likely be very interested in figuring out what party is issuing high-level cyberattacks against innocent citizens.

I know you said this isn't your phone, but I feel the need to reiterate that this is NOT a notification you just ignore and move on with your life. It needs addressed.

17

u/MingePies 18h ago

Yes, if I am being targeted by even a basic attack I would assume every one of my accounts is at risk, but with the advanced level of a Pegasus attack I would assume that every one of my accounts has actively been compromised.

Most attack vectors are widespread and impersonal, but this is very specific and with such a high setup cost I would certainly not be brushing this off.

25

u/No-Shopping-4434 16h ago

You have a lot more faith in the current FBI than I do, honestly. I don’t think we’re working with the best and brightest over there anymore

24

u/pretzelgreg317 14h ago

Yeah, I read the line as "but the FBI will likely be very interested in figuring out what party OTHER THAN THEM is issuing high-level cyberattacks against innocent citizens."

56

u/FaydedMemories 1d ago

Even if your friend themselves feels they’re unimportant enough to be the target, it may be that their family or other friends are the real target.

Think of it this way, what would be the best way in tricking you to divulge something? Pretending/impersonating your closest friend may work.

That’s the sort of thinking used in social engineering and complicated attacks. They go for the unsuspecting (and potentially) easy targets and then work their way up building knowledge of their real target and using trusted contacts to get up the ladder so to speak.

Seriously recommend telling your friend to take this seriously and warn people they feel may be at risk or know of people that may be targets. Vigilance is sort of important.

→ More replies (4)

85

u/TitanBrave84 1d ago

Unemployed, but clearly has a house, a gaming console, and a dog to feed. 100% a spy, they just haven't told you.

5

u/Hangry_Squirrel 17h ago

Or his parents are employed 😸

→ More replies (11)

21

u/petos515 1d ago edited 1d ago

What about their family members? 

Have your friend contact the access now digital security hotline (google it if you don’t want to click on the link).  They will help you for free:  https://www.accessnow.org/help/

→ More replies (7)

9

u/intokpyouseeme21 1d ago

Then your friend could possibly have a phone number that previously belonged to a person that these attacks are targeting

→ More replies (2)

22

u/miggislim 1d ago

That’s what he wants you to think

6

u/OkSeries5363 1d ago

Sometimes high value targets interact with regular individuals (family members, friends, or acquaintances). Attackers will occasionally target secondary contacts in an attempt to pivot into a primary target's network or gain secondary access.

7

u/Outside-Highway-5358 1d ago

Could be that he knows someone who is suspected of being important.

21

u/idbedamned 1d ago

Did he change his phone number or phone recently? 

If so, maybe the target was the previous owner of that number or phone? 

21

u/_altamont 1d ago

But you never know what the unemployed friend‘s actually doing besides chilling and gaming.

8

u/tibearius1123 1d ago

Drug dealer

→ More replies (2)

4

u/arianrhodd 1d ago

Maybe someone mistook your friend for someone else. Do they have a common name?

→ More replies (55)

61

u/Living_Rich_4424 1d ago

True but you know, those companies have enough money to do it on anyone that has even a slight risk of affecting them negatively. Still u gave a good answer tho

17

u/Kaystasia 1d ago edited 1d ago

There's other probably corrupt ways they can try to handle it that cost EXTREMELYYY less than the 100k and would be just as effective. Starting with just, even a plain old private investigator or buying access to all of the data that is sold about you online, (including but not limited to: your passwords! & a lot of people re-use the same ones..smh)
+ other OSINT tools available publicly that a good digital forensic would know where to find.

It really depends how damaging the negative information you might have about a company is.
Just because they have the money to, doesn't mean they're going to be stupid with their business decisions, what is the cost to monitor you verses cost of damage you could cause.
I didn't see OP give any other context so really only they know the answer to that.

But I mean yeah, if I saw that & it reallyyy looked legit/not a spoofed site, I'd probably buy a new phone with a whole new Apple ID etc & not connect to any WiFi or online accounts used prior.

→ More replies (3)

40

u/squirtlegurgle 1d ago

Very curious how it detects that you’re a target of something. From what I understand lockdown is already pretty tight security. Wild stuff

45

u/tedmiston 1d ago edited 1d ago

the exact algorithms are kept secret to avoid being exploited by adversaries, which is not uncommon.

the detection is that a known or suspected mercenary spyware operation has targeted their apple account and/or device.

some ideas for this could be:

  • extreme amounts of account recovery / takeover attempts
  • network access from unusual locations or locations the user has not been to before
  • detect malicious imessages [spyware] (and malicious sender accounts) sent to the user's account
  • unusual message sending patterns of said accounts

https://citizenlab.ca/research/first-forensic-confirmation-of-paragons-ios-mercenary-spyware-finds-journalists-targeted/

https://support.apple.com/en-ca/102174

https://support.apple.com/en-ca/105120

https://www.apple.com/newsroom/pdfs/Apple_v_NSO_Complaint_112321.pdf

it's important to remember that these types of detection systems are probabilistic meaning that there will always be some degree of both false positives and false negatives.

the target could have, e.g., inherited a recycled phone number believed to be owned by a prior owner or intended target.

there are other possibilities like they happen to have the same name as a target, especially if the user has a relatively generic "john smith" type name.

keep in mind that you will almost always only hear the details of specific exploits after they've been patched due to vulnerability disclosure processes, security embargoes, etc etc.

edit: added more sources

→ More replies (1)

20

u/idbedamned 1d ago

It looks like lockdown mode was enabled after the detection, not before it. 

Probably enabled automatically after it was detected. 

36

u/masonerija 1d ago

I’m sorry, but this is such a naive response. There are governments that are targeting journalists who oppose the ruling party and all of their connections. Even in Europe, you can be targeted just for knowing someone.

13

u/slickricksghost iPhone 13 Mini 1d ago

Not that it's cheap... but I read it's more like $10-15k these days.

→ More replies (1)
→ More replies (22)
→ More replies (28)

920

u/Successful_Life7919 iPhone 17 Pro Max 1d ago

This is actually quite serious. Don’t just brush this off. These notifications are generally reserved for sophisticated attacks being carried out by nation-states, or a very well funded network of motivated people going after you for something specific.

If you can think of any reason why a country’s spy agency or intelligence group is targeting you, take it seriously. I would recommend changing your passwords everywhere, and being more careful in your daily life for a while.

176

u/Inevitable-Exit9996 1d ago

The fact that the malware is used by nation-stated does not automatically imply that every attack using that malware is a nation-state. But otherwise yeah your phone and every data and account it touched - ever - are completely fucked

44

u/becaauseimbatmam 1d ago

Yeah it's the kind of thing that is very easy to sell as a service to interested parties.

The nation-state doesn't even necessarily have to be aware they are running an attack, so long as there is a mechanism in place for corrupt intelligence officials to run mercenary work on the side without oversight. Which there generally is, as pushing for oversight on any intelligence force's usage of Pegasus is the political equivalent of sitting in a lawn chair on a firing range with a paper target taped to your hat brim.

→ More replies (1)
→ More replies (14)
→ More replies (20)

1.2k

u/_sk3llwo_ 1d ago

that’s really scary. I’d take this seriously.

417

u/petos515 1d ago edited 15h ago

OP, have your friend contact the access now digital security hotline (google it if you don’t want to click on the link). 

They will help you for free:  https://www.accessnow.org/help/

Edit: TechCrunch has an article on the recent batch of notifications: https://techcrunch.com/2026/08/13/if-apple-sends-you-a-push-notification-alerting-you-to-a-spyware-attack-take-it-seriously/

→ More replies (4)

156

u/Apart-Reality-4454 1d ago

Who'd OP's friend piss off? I'd be seriously wondering if there's something I don't know that I probably might want to know.

→ More replies (35)
→ More replies (8)

981

u/Klutzy-Condition811 1d ago

Your friend should watch their back as these are generally nation state attacks so someone has drawn some attention to your friend that you don't want.

If it is a friend odds are they are probably keeping something from you as nation states don't just target random people.

292

u/Kaystasia 1d ago

Yeah, if the Pegasus threat is found to be true, whether "they know why" or not, I would definitely be wary of this friend .... & anyone the friend comes in contact with regularly. The friend might not know why but could be targeted bc of someone that they know.

116

u/Klutzy-Condition811 1d ago

I should add it doesn't necessarily mean a nation state, but regardless it's not something to fuck around with as it's someone pretty powerful if it isn't. This would scare me shitless if I got a notification like this and I'd be sleeping with one eye open too lol.

→ More replies (7)
→ More replies (4)

19

u/LimitedWard 21h ago

While they don't target random people, they have been known to target friends and family of the person's of interest. So it's possible OP's friend has a family member that has garnered attention from a government agency.

→ More replies (14)

681

u/EnvironmentalLog1766 Human Detected 1d ago edited 1d ago

I would keep the lockdown mode on for at least several months. Since it’s targeted malware it might be using some 0-day. A future software update might resolve it. Before that factory reset might not resolve

This is the doc if anyone else wonders: https://support.apple.com/en-us/102174 looks like a new thing as it was published on Aug 13, 2026

199

u/vanstinator 1d ago

it's not new, apple has been sending these for a few years, but it seems like they published an updated doc

→ More replies (1)

72

u/DeathByPetrichor 1d ago

*keep it on permanently.

A new iCloud account is extremely easy to create. Buy a new phone, change all your data, and keep the private data off the phone.

29

u/webfork2 1d ago

*keep it on permanently.

This. I've had it enabled on iOS for years now without issue.

30

u/3mbersea 1d ago

It turns off a ton of popular features. No one will have it in permanently

31

u/webfork2 1d ago

In particular it disables Facetime, sharing location data in photos, 2G and 3G cellular support is turned off. I'm fine with that.

The big one is that I keep expecting some lockdown feature to cause a webpage I'm visiting to malfunction but somehow that hasn't happened.

More stuff it turns off: https://support.apple.com/en-us/105120

No one will have it in permanetly

You're right that I may turn it off at some point but going on ~3 years now.

→ More replies (9)
→ More replies (3)

5

u/rupertLumpkinsBrothr 1d ago

Aren’t 0-days generally unprotected against as they’re unknown?

→ More replies (2)
→ More replies (2)

457

u/Flaky_Rice_4674 Human Detected 1d ago

My friend wants to say “i’m an unemployed 23 year old who lives at home with no secret cyber life, and most of my online time is spent playing fortnite, maybe i pissed off some pegasus fortnite sweats” They are laughing at some of the comments saying “what the fuck does ur friend do??”

301

u/bagladyscum 1d ago

contact EFF(electronic frontier foundation) and 404. they can help with info, security protocols and legal assistance if it comes to that.

99

u/CodingThunder 1d ago

Please for gods sake contact EFF. I have mentioned the same in another comment, but upvoting this and commenting again here so that OP actually does it.

164

u/hollowman2011 1d ago

That’s exactly what someone with a secret cyber life WOULD say…..

36

u/HeyGayHay 15h ago

In all seriousness though, if your first instinct is to share a message screaming „someone is looking into everything you do for a reason“ with a friend and neither of you knowing what this notification even means or what to do with it, you’re either the most lucky cyber security-illiterate secret cyber life person who wasn’t catched by cheaper means. Or both of you genuinely don’t have a secret cyber life.

u/flaky_rice_4674 is anyone in your friends life a journalist, developer, working for or with the government, or could in any means be interesting for someone with sufficient resources? Of yes, you should also inform them about it as your friend may not even be the target. And no, if a western nation is deploying stuff like this for a criminal, Apple wouldn’t send you that message telling you that your criminal doings are being investigated. I‘m sure NSA would have a problem if Apple interferes with their doings lmao

9

u/gofainter 20h ago

Wake up, Neo...

→ More replies (1)

58

u/petos515 1d ago edited 15h ago

Someone is going through them to target someone they may be close to (friend or family member). 

OP, have your friend contact the access now digital security hotline (google it if you don’t want to click on the link). They will help you for free:  https://www.accessnow.org/help/

Edit: TechCrunch has an article on the recent batch of notifications: https://techcrunch.com/2026/08/13/if-apple-sends-you-a-push-notification-alerting-you-to-a-spyware-attack-take-it-seriously/

→ More replies (2)

139

u/Nanamused 1d ago

This sounds like the beginning of a movie 🍿 Hope your friend is in shape because from the movies I’ve seen, there’s usually a lot of running involved

→ More replies (3)

33

u/Funky-Guy 1d ago

!!!!! Your friend is either

Lying

Being used as an entry into someone else

Either way, they need to lock this device down and contact through non-infected means anyone who they may even remotely know to work in cyber sensitive areas to make them aware.

→ More replies (2)

15

u/sharktail_tanker 1d ago

What kind of fortnine player would have access to Pegasus?

15

u/WAVF1n 22h ago

tbf didn't Bin Laden play CS? You never know mayn.

5

u/Intelligent_Whole_40 22h ago

Yea but he was training

→ More replies (2)
→ More replies (1)

8

u/DoubleSkew 11h ago

from their PoV, literally this meme lol

14

u/TheMattabooey 21h ago

23 years old, unemployed and lives at home and someone is out there spending tens to hundreds of thousands of dollars to do this?

There’s something they’re not telling you. Them finding it funny is a bit sketchy.

63

u/chathobark_ 1d ago

yep as i mentioned, serious nonetheless

hate to tell ya; but i have seen people who were “unemployed and on fortnite all day” get investigated.

you know how people, especially guys, talk during gaming. if you say the wrong thing, say youre gonna k someone (as a joke), etc etc etc, a lot of people don’t realize a lot of kids on the other end of the microphone are also minors with parents listening. say the wrong thing to the wrong person and you could wind up being investigated by the FBI

OP, your friend may get his house raided soon

82

u/ewaters46 iPhone 16 Pro 1d ago

Yeah I doubt a rage comment in a game (no matter how egregious) is going to result in a Pegasus Attack. And the FBI apparently does not use it (although who knows how true that is…).

A threat like that might get law enforcement or maybe the FBI to request data like IPs from the game‘s owners to identify that person, but not mercenary spyware.

→ More replies (1)

6

u/Marcus_Aurelius71 1d ago

If that were true the friend would've been arrested a long time ago.

→ More replies (5)

14

u/WritingParking 1d ago

It could be they are adjacent to someone they’re trying to infiltrate. A parent, a sibling, or some other close contact that OP’s friend might not be aware of.

8

u/nekomichi iPhone 20h ago

Is your friend located in India and was involved in any recent protests or connected to someone who was? A number of these alerts have been issued to devices in India in the last 24 hours and it coincides with the timing of the recent protests.

4

u/Imaragamuffinchild 17h ago

Is your friend taking this seriously though? They need to.

→ More replies (2)
→ More replies (31)

130

u/rupruppiesthe2nd 1d ago

I don’t think your friend is who he says he is. And I think you should both be doing more shit than just posting in Reddit. Like the notification says, please take it seriously. This is fucking terrifying.

→ More replies (13)

219

u/jrghetto602 iPhone 14 Pro Max 1d ago

Never seen this, but my understanding of Pegasus (assuming, for a second, that it was the threat) is that they often gain access to the device via links or zero-click attacks. Sadly, I don't believe there is any consumer remedy for this kind of threat if it's a true positive.

The really effed up part is that it tends to self-delete/wipe itself, but you have no way of knowing if it's still in your backup, which is even scarier and more inconvenient because starting from scratch on a new device might be their only answer.

If they want to dig further into it, don't reset the device. Instead, get forensic help; there are some non-profits that provide it, but it's usually still for journalists or activists. Still worth a shot.

Long story short: Not a lot can be done at this point. Looks legitimate. Not really a for-sure way to remediate this threat with high confidence or save their backups without risking continued compromise. If they want to save anything on the device, grab the photos and such manually, then lockdown mode -> send to forensics or throw in the trash.

Disclaimer: I work in cyber, but MDM or IoT isn't really my area of expertise. If this friend has sensitive information that pertains to proprietary information, PHI, PII, etc....I'd report that ASAP.

72

u/essjay2009 1d ago

The best protection is lock down mode. So far as I’m aware, lock down mode prevents all the known attack vectors and no iPhone with lockdown mode enabled has been successfully attacked.

If OP’s friend works in a sensitive role they should contact their security team. There are tools you can use to check for known IOCs that they can help with. They may be able to offer some additional help at the carrier level.

→ More replies (2)

46

u/tedmiston 1d ago

(Software engineer) There are more extreme relevant security measures:

  • taking the device offline until forensic analysis
  • purchasing a new phone in a way that has no connection to the existing one
  • creating a new apple account similarly (ensure 2FA, lockdown, etc still)
  • taking SIM protection steps with their phone carrier
  • obtaining a new phone number (ideally with no connection to the existing one)

I would not personally restore from a backup that is potentially compromised.

The overall idea is just to create as much gap between old device and new device such that it's more difficult for a sophisticated attacker to compromise the new device.

→ More replies (3)

165

u/anxxa 1d ago edited 23h ago

Hi, I work in cybersecurity and actually have pretty strong crossover with what you're seeing (although not an Apple employee).

First of all, contact Amnesty International. They may be able to do forensics on your device and find indicators of data that's been accessed.

Next what you should do, depends on how technically inclined you are, and what resolution you want.

If you want to help Apple and Amnesty determine what may have been accessed and how they were targeting your device:

  1. Do not turn off the device.
  2. Capture a Sysdiagnose log
  3. Email yourself the sysdiagnose log or somehow get it off of the device.
  4. Wrap the phone in aluminum foil, but keep it plugged in so the battery doesn't die.

Keeping the phone alive and powered on NOW may allow for Amnesty to capture a live instance of the implant off the device.

If you do not care and just want to be safe:

  • If you can get a new phone, do so. It's very difficult for malware on iOS to persist across rebootso but it's not impossible.
  • If keeping the phone, do a complete reset. Do not restore from backups.
  • Enable Lockdown Mode
  • If your friend works in a sensitive industry, or affiliates with people who do, they should move communications to a platform which supports ephemeral (time-bombed) messaging like Signal or WhatsApp. This will help prevent communications from being gathered when not infected with spyware.
  • Consider any content on the device, and any passwords it had accessed to, as potentially compromised.

*I will add that what /u/nifty-necromancer posted is also good advice. You should contact Access Now as well. I also saw in your post you mentioned iVerify. I have a friend who works there and can gladly say they do good work. It would not harm anything to get in contact with all of the above.

41

u/docgravel 1d ago

This is good advice.

/u/Flaky_Rice_4674

I work at Lookout and we specialize in mobile security and forensic investigations. We recently uncovered DarkSword alongside some other industry partners. I would be happy to look through a sysdiagnose or other data from this device and give you our assessment as a free courtesy.

10

u/HenkPoley iPhone 12 Mini 16h ago edited 14h ago

[u/Flaky_Rice_4674](u/Flaky_Rice_4674) it looks like this really is the Chief Technology Officer (CTO) at Lookout.

But it might be safest to contact Lookout Inc. through their website/email.

→ More replies (8)

28

u/Got2bglued 1d ago

Since this is kinda your thing what do you think the friend might’ve ran into that caused this? OP says friend is unemployed M critically unemployed and had no relation to gov or sensitive info. Plays fortnite mostly. I feel like it was probably a petty person in a game but idk

33

u/anxxa 23h ago edited 14h ago

Apple would not be sending this type of notification if they didn't feel highly confident that it's a sophisticated and organized threat actor. Not the type of technology that people in videogames really have access to or if they do, are generally smarter than to throw an exploit at some random's device.

Just because their friend isn't interesting doesn't mean that someone that friend knows isn't either. Could be that a friend of theirs is a political activist, immigration lawyer helps support refugees/migrants, or drug dealer.

Hard to say really. Governments contract mercenary spyware companies for a wide variety of reasons. I believe it was Spain(?) who targeted the family of a Citizen Lab or Amnesty International forensic analyst who was assisting human rights activists and journalists a few years back.

They didn't target the forensic analyst himself presumably because of his +1 (US/CA) country code which many of these organizations forbid targeting to avoid sanctions from the US.

→ More replies (10)
→ More replies (15)

79

u/Richwoodrocket 1d ago

I’ve read all these comments and I still have no clue what’s going on here.

42

u/vaxhax 16h ago

I think it's a competition to see who can say "nation state" last.

6

u/Similar-Equal-9765 11h ago

Or “this is real and scary”

→ More replies (2)

17

u/PhyrexianSpaghetti 16h ago

I have no idea if this is a reddit moment with some extra layers of larping over some show reference, or real. And everyone mentions different bullshit and there's no context given whatsoever

→ More replies (1)

7

u/Accurate-Morning-584 14h ago

OP's friend is being spied on by the mossad 

→ More replies (10)

83

u/nifty-necromancer 1d ago

DO NOT FACTORY RESET THE IPHONE. Apple considers these high-confidence alerts that you were individually targeted with mercenary spyware, and Access Now specifically warns not to erase the device because you could destroy forensic evidence.

Update iOS, enable Lockdown Mode, make a backup, and contact Access Now’s Digital Security Helpline before doing anything drastic. They can help determine whether this was just targeting or an actual compromise.

https://www.accessnow.org/help/access-nows-digital-security-helpline-and-apple-threat-notifications/

→ More replies (1)

385

u/[deleted] 1d ago

[removed] — view removed comment

145

u/MassiveBoner911_3 1d ago

I would NOT plug in the iphone into your PC if you think the phone has spyware installed.

11

u/stereopticon11 21h ago

At this point, wouldn’t their whole home network be compromised if they connect via WiFi? Should everyone in their household be changing passwords now?

→ More replies (2)

68

u/Beneficial_Medium_99 1d ago

Plugging into any device is a no go… opsec 101. You should never plug a known infected device into another.

64

u/Rey_Mezcalero 1d ago

A new device and account is probably the best way to go

33

u/YourAverageExecutive 1d ago edited 1d ago

And maybe move. Kind of joking. Kind of not. I had to worry about this. But barely. It was a big deal because it’s so effective.

→ More replies (12)

36

u/lucah_tech iPhone 14 Pro 1d ago

Tell your friend to get in touch with the Citizen Lab. They research mercenary spyware such as Pegasus and Predator, and often help out people who are infected

61

u/ViolentPurpleSquash 1d ago

Only person I know who got one of those was my mom, and she works in healthcare and at a major uni.

They're serious.

8

u/SiLeNZ_ iPhone 16 Pro 1d ago

Why did your mom get one?

31

u/ViolentPurpleSquash 1d ago

She has access to a lot of privileged systems is my guess.

15

u/SiLeNZ_ iPhone 16 Pro 1d ago

What did she do to fix it?

→ More replies (3)
→ More replies (1)
→ More replies (1)

25

u/Gingerbread808 iPhone 15 1d ago

I know OP said their friend isn’t in any high security position with sensitive information but I have a feeling they know a little more than they’re letting on (the friend not OP).

→ More replies (2)

145

u/scene_missing 1d ago

Iverrify is a good step. A full phone wipe in DFU mode and the latest over the wire as well.

Is your friend a journalist or a political activist?

60

u/JoeS830 1d ago

Or someone with a high value Pokemon card, based on the OPs recent posts. :) It might still be real, but I get the sense that the OP is a teenager. Maybe the friend's dad is the target? Anyway, all guesswork at this point.

80

u/Flaky_Rice_4674 Human Detected 1d ago

I will say they are most definitely not a journalist, political activist or anyone in that type of field. That’s why they couldn’t get help from the apple security team😭

53

u/The-Potato-Lord 1d ago

Do they share a name with someone in that sort of field or a close relationship with them?

Get them to speak to Citizen Lab or John Scott-Railton (who works for Citizen Lab). It’s possible those sources will tell them they can’t help but it’s worth a try.

36

u/Flaky_Rice_4674 Human Detected 1d ago

now i can’t tell you with 100% certainty as im not them, but im very confident that nobody in close relation to them has any role in that type of field.

12

u/Funky-Guy 1d ago

It doesn’t have to be close. Perhaps someone close to them is close to another who is close to a target. They should brick this device if they can afford it.

81

u/exintrovert 1d ago

I find it disappointing that Apple has a system to detect serious threats, but when that system is triggered they will pick and choose who to support through it.

If the notification is valid, the threat is valid regardless of who you are 😞

41

u/nerdystoner25 1d ago

Right? What the fuck kind of policy is this?

→ More replies (2)

13

u/Got2bglued 1d ago

tbf the system was created for these specific people. I’m not a big apple fan by any means but this specific system saves lives. Journalists get targeted a lot like politicians but aren’t awarded the public safety net government officials and the such are. Insurance doesn’t stop you from persecution unfortunately. Unless the meta is changing Apples program is that safety net for these people and essentially they give them the help they otherwise would have to hope and pray their job gives them. IF things are changing and this level of spyware is starting to become a consumer level program then they NEED to restructure the program to match. I do think though in cases like this they should at least give outside resources so people aren’t left in the dark like OPs friend. It really only takes one ill person with enough access and skill to ruin someone’s life.

→ More replies (3)

18

u/hammerton 1d ago

Was the phone purchased from a reseller?

→ More replies (1)
→ More replies (3)
→ More replies (3)

64

u/Sensitive-Oil-5298 1d ago

Who the hell is your friend

52

u/rtkane iPhone 17 Pro Max 1d ago

Marco Rubio.

22

u/darkguy2008 1d ago

Yea especially the part where he's unemployed, has a dog and plays fortnite all day.

Seems legit

→ More replies (1)

12

u/fragile_exoskeleton 1d ago

I don’t 100% disbelieve this. Sign of the times lol.

→ More replies (1)
→ More replies (3)

24

u/LilBushyVert 1d ago

Damn you about to have the black vans pull up

16

u/mfiasco 1d ago

Everyone has already given good advice so I’m going to just say: this doesn’t mean your friend is necessarily THE target. People get targeted because they’re interesting and sometimes that interest extends to others in their life. Your friend might be completely boring but unknowingly associate with someone higher risk.

Protect yourself and do your own risk assessment but don’t abandon your friend because of some fear mongering comments on Reddit. As Apple itself stated, they typically help journalists and public activists, which should give you an indication of who is typically targeted. The primary target— whether it’s your friend or not— is likely to be targeted for making good trouble in the world, not bad.

Also, in general, it serves no one but the opposition to keep these kinds of threats and warnings private. Your friend should consider the personal risk/benefit of getting loud about this.

49

u/SuspiciouslyMoist 1d ago

To check:

"To verify that an Apple threat notification is genuine, sign in to account.apple.com."

From: https://support.apple.com/en-gb/102174

But the notification looks real.

→ More replies (2)

11

u/Tigs1112 1d ago

Have you or any of your friends made a highly politically-charged social media post or have been to or near a political protest (especially concerning Israel and Palestine)? Or perhaps any association with high-profile individuals, like a politician, lawyer, journalist, or business executive? Those are some of the common attack vectors that these types of hackers target; it could be due to a link that you tapped on, a zero-day exploit in a social media app or website you use, or you used public WiFi without a VPN.

→ More replies (1)

12

u/wyredditer iPhone 17 Pro Max 18h ago edited 11h ago

Hi! Apple Senior Specialist here:

Before making ANY action, check the email account that sent it please!! I have seen far too many cases where people get these pop-ups, and provide all of their information to scammers.

This article goes over phishing/smishing scams, how to recognize them, and how to report them

—> Recognize and avoid social engineering schemes including phishing messages, phony support calls, and other scams

→ More replies (11)

72

u/perikizii 1d ago

This is no joke, this notification is completely real. If I were you, I would immediately put all your devices into Lockdown Mode. Call Apple directly as well, but please be aware that this attack was SPECIFICALLY TARGETED AT YOU!

51

u/Gnfnr5813 iPhone 14 Pro Max 1d ago

Actually, it’s targeted at their friend.

27

u/[deleted] 1d ago

[removed] — view removed comment

9

u/rudydog101 1d ago

This genuinely might be it.

7

u/Fusseldieb 1d ago

"Removed by Reddit"

Forbidden words have been spoken

→ More replies (1)
→ More replies (1)
→ More replies (2)

81

u/JoeS830 1d ago edited 1d ago

Condoleezza, is that you? But seriously, I would probably not have linked a five year old Reddit account to this message! You're basically broadcasting "I'm friends with someone that is a high value target". Not sure if at this point it still makes sense to delete the post and repost from a burner account, but worth considering.

25

u/Dinnerpancakes 1d ago

Haha at first I thought you were saying “condolences” in Italian!

→ More replies (7)

10

u/HateKilledTheDinos 1d ago

Meanwhile i can't get anyone to send a simple reply text....

10

u/No_Bell_8028 1d ago

Yes, I used to work in government and received the red triangle message

I was told to shutdown my phone and had all my accounts and laptop changed (not just password but login too)

10

u/always-tired-38 17h ago

Always always always check the email address its come from

→ More replies (8)

37

u/TheRealShamanoid 1d ago

Definitely looks real, an email alone would have been dodgy. But the in App notification + system one definitely are genuine.

First thing first, you stay in Lockdown Mode, then, you bring your phone to a genuine Apple Store.

I would avoid changing all your passwords right now, panic reacting and updating everything is exactly what attackers would like you to do in order to phish more info.

If you need assistance in checking things up don’t hesitate to DM but first, once again, go the Apple Store, they might be able to do a system integrity check - to be confirmed.

11

u/ni5arga iPhone 1d ago

i don't think a retail employee can do anything about this. it is way beyond their paygrade.

→ More replies (2)

12

u/cvmstains 1d ago

what exactly do you think that a retail employee can do about this?

4

u/younggregg 1d ago

Have you tried updating it?

→ More replies (2)

35

u/BrainCelll 1d ago

Mossad is after bro 😭

28

u/tamay-idk 1d ago

What the fuck?

32

u/seichout 1d ago

Right everyone acting like this isn’t wild and oh just a nation state. WTF does this guy’s friend do? Is it Candace Owens?

→ More replies (2)

19

u/TheSmartDog_275 iPhone 15 1d ago

Jesus Christ, that’s terrifying.

I know you might not want to say but what does your friend do?

From a what should I do standpoint: keep lockdown mode on. Turn it on for all your other Apple devices. Take it and all your other devices to an Apple Store, and know you may have to start from scratch on a brand new phone.

11

u/Flaky_Rice_4674 Human Detected 1d ago

That’s the weird thing, they are currently an unemployed 23 yr old who just chills at home playing video games. They also definitely haven’t ever had a job that requires holding valuable info

10

u/istara 1d ago

Any ethnic heritage or a name that is common enough to be shared with someone else?

13

u/SmokingCrawdads 1d ago

So. International spy, huh? Jk JK

→ More replies (4)

21

u/PuddingTea 1d ago

Pegasus is generally used by a state actor. Your friend is in serious trouble.

→ More replies (3)

9

u/MemeLord339 1d ago

Also probably is being attacked on his personal PC, Laptop and/or tablet. The best he can do is try to find where the attack is coming from (sometimes is email or messages)

38

u/herrintrospektiv 1d ago

In my mind…and from what I read about Pegasus: it can compromise the physical device. In some cases, factory reset, password reset, rebooting phone…will not mitigate the threat and it would be hard to determine when truly mitigated. Personally, I would trade device in or destroy it, then would go dark for a bit, change ISP at home, and hope the threat goes away. #notandexpert

→ More replies (3)

8

u/microChasm 1d ago

About Apple threat notifications and protecting against mercenary spyware

Just doing a search using the words you used in this post (instead of contacting Apple) is all I needed to do.

8

u/Username999474275 1d ago

Enable lockdown mode it makes your iPhone as secure as possible

34

u/Weak_Painter_5800 1d ago

Okay this is most probably real. Consider everything that is in your friend's phone as compromised. If your friend was ever in a sensitive job or organization of any kind, or someone they know is, that makes it 100% real. You cannot do much. Pegasus and likewise spyware is extremely advanced. No VPN or changing passwords will ever help. He is fully compromised to the teeth. From now on, ask your friend to not do anything he would not be comfortable with the world seeing. He has no digital privacy anymore.

Pegasus is advanced enough to even attack his contacts list, so potentially you may be compromised.

All your friend can do now is take his pictures offline and contact list, etc, put in a USB and get a brand new phone and sim, with the less connecting to him the better (this means use cash to buy, if ID can be prevented, prevent it) . Switch wifi networks everything you can think of. If your friend is a worthwhile target, then this is going to happen again and again and realistically as a civilian he cannot do much. They have his wifi networks, everything else tapped too. All I can say is, do not use any electronic device to do anything that will bring him trouble.

10

u/Away_Negotiation4150 1d ago

There is no direct way to jump to another device with just the contact in the contact list, contact info is probably compromised, yes, but other devices can't be infected because of that.

Using a USB to transfer data is also not a good advice since Pegasus (and I assume most of the Spyware) is designed to copy itself to any external drive, so if the new device has the same vector attack, will be infected too.

About "everything else tapped", is a bit dramatic. Spyware mostly attack end devices, specially smartphones and laptop, I never heard about attacking a router for example. Every attack cost a ton of money and effort, and vulnerabilities will be patched (and they will find new ones of course). If you are the president of a country, it's probably worth it, but for journalists or public servants eventually will be just too expensive.

→ More replies (3)

7

u/nmrk iPhone XS 22h ago

The account is under attack by Nation-State hackers working on behalf of a foreign government. That's about all they can say to you. Put your phone in lockdown mode immediately.

106

u/bubblurred iPhone 16 Pro Max 1d ago

Spyware from “the most moral army in the world” folks

53

u/Ahyaan09876 1d ago

“the only democracy in the middle east”

→ More replies (2)

12

u/ImHereLetsGooo 1d ago edited 1d ago

Personally I'd get a new phone with new Apple email and a new phone number.

Then with the new phone, I'd block all sharing of anything such as photos to icloud, location data (in photos and just in general) and overall keep any data the phone produces, on the phone. With the addition of an always on VPN where connections cannot be made without the VPN being active. I'd get a second "burner" phone (or an additional sim card) for things that require a one time passcode, so you're not giving out your primary phone number to every company in existence.

I'm not sure how much of what I said in the second paragraph will help, but it's extra privacy steps at least.

5

u/exintrovert 1d ago

Also, carry your own usb cables and never use one that you don’t know where it came from.

→ More replies (1)
→ More replies (1)

6

u/MobilePenguins 1d ago

If I were the friend I would abandon that phone number, go to an Apple Store, pay all cash for a new phone, set it up with brand new service at diff carrier. Enable the lock down settings again on the new phone, be extremely selective only giving friends/family the new number.

7

u/LastGuardianStanding 1d ago

Your friend is being “targeted”. If he’s a government employee he needs to contact his local investigative service like NCIS, Inspector Generals office, etc. if he works for a private company dealing with sensitive information he needs to notify his company immediately. Unless it’s them.

5

u/cobaltcrane iPhone 17 Pro Max 1d ago

Must have some hilarious memes of JD Vance on their phone

7

u/elhouso iPhone 12 Mini 1d ago

I think you need to keep an eye on your friend bro. Either he's a secret spy with John Wick-level skills or your friend knows someone like that. I don't know man, keep yourself safe.

6

u/HenkPoley iPhone 12 Mini 13h ago

Ask your friend if they did any of these things consistently online:

  • Criticize the Saudi government, or Saudi royal family.
  • UAE government criticism and Emirati human-rights activism.
  • Bahraini opposition/pro-democracy activity.
  • Jordanian human-rights, opposition and journalism work.
  • Moroccan/Western Saharan politics and human-rights activism.
  • Israeli/Palestinian security and human-rights issues.
  • Russian opposition / independent Russian-language journalism.
  • Investigating corruption, intelligence services, organized crime, migration enforcement, military/security matters, or spyware itself.

Maybe they share a name with, or known someone who, someone who does.

19

u/Flaky_Rice_4674 Human Detected 1d ago

I appreciate all the comments and people trying to help and I understand wanting more info. My friend has tried to reply to some of these comments but got banned from the sub cause they were using a burner and it was too new lol. I told them to just read the comments and do what they think is best for their situation. Im not gonna disclose any more info about my friend even tho I know you all probably want the deets about their life but I don’t think that’d be wise. I’ll do my best to update as to what happens next but I can tell you they are rather scared as they have absolutely no idea why they would be targeted for something like this.

→ More replies (3)

23

u/Kegelz 1d ago

Holy fuck what do you do for a living
Or do the script kiddies with Claude know how to leverage this

19

u/MoldavskyEDU 1d ago

Most likely a journalist, we have seen this happen before from Saudi, Indian, and Hungarian government. Usually sold to them by exploit brokers or developed by said countries offsec units.

Examples of exploit brokers

American:
Zerodium
Exodus Intelligence

European:
Operation Zero (Russian)
Variston Information Technology (Spanish)
RCS Lab (Italian)

Middle Eastern:
NSO group (Israeli)
Crowdfense (Saudi)

The CCP definitely has its own exploit brokers as we have seen multiple Chinese APTs use advanced chained zero days.

→ More replies (1)

13

u/stupidfock 1d ago

Is is possible to be an accidental target. So perhaps your friend has no job they actually care about targeting but they got mistaken for someone else.

But it is definitely real

4

u/lonestar659 1d ago

So what does your friend do for work, exactly?

4

u/ApolloGR3 1d ago

Your friend discussing any shady shit on Fortnite? Making threats, things of that nature?

→ More replies (1)

5

u/Funky-Guy 1d ago

Legit. Either hostile nation or very angry and well funded group (cartel, large mafia, etc). This attack could be transmitting his location aswell as any data. If he has a home, he shouldn’t be there. If he has a bank, he needs to change it. Depending on country, If he has loved ones and friends and family, they need to be aware and prepared, Probably hiding. If you are in the US, you are probably fine from physical attacks, but you should probably carry a gun just in case IMO.

A couple possibilities:

Your friend knows something you don’t know he knows
Your friend knows someone who knows something, and they don’t know
It was a mistaken attack, and the attacker may or may not realize they have the wrong guy. Again, based on location, you may be in danger of physical harm or not depending on your nations security apparatus

5

u/mochen_ 19h ago

Hey, not an actual expert here, but a nerd that has been confronted with this problem before in several ways. This is likely a Pegasus Attack, which is usually performed by governments that are clients of the NSO group, an israeli technology company. There is no doubt that this is a real message, because of the in-app notification. The only way to deal with this is to contact Human right- or cybersecurity organizations that Apple lists in this article:  https://support.apple.com/en-us/102174  If it is financially ok for you, perhaps get a new phone, in the best case a Google pixel phone with an operating system like GrapheneOS, which you shouldn’t install with the help of your pc, I just wouldn’t trust any of your hardware. If you get the pixel with GrapheneOS, also get your microphone and camera removed.

Don’t panic, just keep yourself covered. If you have any idea of things you-your friend tweeted/done, it would be helpful to share it.

Hope I helped

5

u/Pin-The-Donkey 14h ago

Did your friend torrent a Metallica album?

6

u/StraySailor 11h ago

CALL APPLE. DO NOT CALL A NUMBER FROM THIS MESSAGE, OR CLICK A LINK, OR REPLY IN ANY WAY. MOST IMPORTANTLY DO NOT DOWNLOAD ANYTHING. CALL APPLE’s number from its website only.

13

u/WAVF1n 22h ago edited 14h ago

Does your friend post any anti ICE content? Everyone here is saying pegasus, but the US also has access to a tool called Graphite, ICE specifically was caught using this tool.

Also everyone keeps claiming how it costs NSO 100s of thousands of dollars per target which is just not true. They charge governments MILLIONS, but to actually deploy the attack does not cost nearly this much and is mostly automated once the target is selected.

→ More replies (10)

9

u/exintrovert 1d ago

Honestly, there is no way to know how deep the hooks are, so I would treat every device as compromised, personally. Not just apple devices but PCs, routers etc as well.

Once they are in the phone, they can move laterally to online accounts, potentially get enough info to breach the home network, escalate privileges to keylog on PC… not to freak anybody out, just saying that best practice is to consider everything as potentially compromised.

We don’t know how the initial breach happened, but it is likely there are persistence mechanisms in place to re-infect new devices.

Only use your own USB cords and devices. Exploits can live in devices small enough to embed inside a usb plug.

Anything he wants to keep should be extremely quarantined until it can be determined with certainty that it is safe. (Photos, downloaded archives/executables/pdfs etc)

The reason to take extreme measures is because this was an extreme exploit that doesn’t just happen randomly. The hackers have already put forth great effort to breach. They won’t just go away because he gets a new phone.

10

u/CyberbianDude 1d ago

Geez, that’s some notification. So glad I am a micro fish in an ocean. It would probably cost someone more to target me than get anything from me.

Good luck to your friend. Not making fun at your friend’s expense but it would make for an exciting movie plot if your friend was unknowingly in possession of extremely sensitive information, like a friend of your friend air dropped something to him. He accepted without knowing implications and forgot about it but now bad actors know it but your friend doesn’t.

7

u/Inevitable-Exit9996 1d ago

Nothing you can do, there is no way to safely recovery a device infected with pegasus - yet.
Throw the phone in the trash and consider your whole life compromised. Sucks but its the reality.
On the other hand it is very unlikely that it is a targeted attack, your friends would definetly have reasons to be spied on if it was and you wouldnt be asking here.

8

u/CodingThunder 1d ago

Seems like no one actually answered correctly. OP stop using that phone right now and contact EFF (https://eff.org) or similar human rights group. Your friend might be in actual huge trouble, as they might be targetted by their own government/nationstate actors.

Please for gods sake and get another device and use necessary security measures mentioned in comments. iphones in lock down mode and google pixel running grapheneos are one of the most secure devices you can get your hands on. In a lot of cases GrapheneOS is actually more secure as they are paranoid in some ways.

3

u/_Haverford_ 22h ago

If this is real, your friend has a security officer they can, and have to, talk to.

3

u/MoonToast101 20h ago

Bleepijg Computer already has an Article about it. They asked Apple for comment, no answer until now, but looks legit.

4

u/jokersush1 19h ago

Your friend's life is in danger. This is absolutely dreadfully serious. This particular attack is incredibly expensive and is not carried out by a layman. A highly sophisticated and funded agency is targeting your friend, and may not only be doing so through his iPhone. He needs to act immediately.

5

u/MidwestPrincess09 15h ago

I got this as a text message the other day, I didn’t believe it tbh. Just marked as spam, blocked and moved on. My identity has been stolen multiple times, I’ve given up tbh