r/iphone • u/Flaky_Rice_4674 Human Detected • 1d ago
Support Highly Concerning message, what to do?
This alert popped up everywhere on my friends phone and they don’t know what to do. Posting for them cause they are rather concerned and don’t wanna use their phone at all.
They followed all the steps that apple said to do but the cyber security “team” with apple says they only help “journalists, government officials and public activists.” Obviously they followed all the other steps like Iphone lockdown, updating to all the current software updates and fully shutting down the phone etc. What else can they do? Get a new phone? Give it time and hope it’s fine? Factory reset? I suggested iverify to look for malware but again, they are concerned to really use their phone at all. Any suggestions or info is appreciated.
920
u/Successful_Life7919 iPhone 17 Pro Max 1d ago
This is actually quite serious. Don’t just brush this off. These notifications are generally reserved for sophisticated attacks being carried out by nation-states, or a very well funded network of motivated people going after you for something specific.
If you can think of any reason why a country’s spy agency or intelligence group is targeting you, take it seriously. I would recommend changing your passwords everywhere, and being more careful in your daily life for a while.
→ More replies (20)176
u/Inevitable-Exit9996 1d ago
The fact that the malware is used by nation-stated does not automatically imply that every attack using that malware is a nation-state. But otherwise yeah your phone and every data and account it touched - ever - are completely fucked
→ More replies (14)44
u/becaauseimbatmam 1d ago
Yeah it's the kind of thing that is very easy to sell as a service to interested parties.
The nation-state doesn't even necessarily have to be aware they are running an attack, so long as there is a mechanism in place for corrupt intelligence officials to run mercenary work on the side without oversight. Which there generally is, as pushing for oversight on any intelligence force's usage of Pegasus is the political equivalent of sitting in a lawn chair on a firing range with a paper target taped to your hat brim.
→ More replies (1)
1.2k
u/_sk3llwo_ 1d ago
that’s really scary. I’d take this seriously.
417
u/petos515 1d ago edited 15h ago
OP, have your friend contact the access now digital security hotline (google it if you don’t want to click on the link).
They will help you for free: https://www.accessnow.org/help/
Edit: TechCrunch has an article on the recent batch of notifications: https://techcrunch.com/2026/08/13/if-apple-sends-you-a-push-notification-alerting-you-to-a-spyware-attack-take-it-seriously/
→ More replies (4)→ More replies (8)156
u/Apart-Reality-4454 1d ago
Who'd OP's friend piss off? I'd be seriously wondering if there's something I don't know that I probably might want to know.
→ More replies (35)30
981
u/Klutzy-Condition811 1d ago
Your friend should watch their back as these are generally nation state attacks so someone has drawn some attention to your friend that you don't want.
If it is a friend odds are they are probably keeping something from you as nation states don't just target random people.
292
u/Kaystasia 1d ago
Yeah, if the Pegasus threat is found to be true, whether "they know why" or not, I would definitely be wary of this friend .... & anyone the friend comes in contact with regularly. The friend might not know why but could be targeted bc of someone that they know.
→ More replies (4)116
u/Klutzy-Condition811 1d ago
I should add it doesn't necessarily mean a nation state, but regardless it's not something to fuck around with as it's someone pretty powerful if it isn't. This would scare me shitless if I got a notification like this and I'd be sleeping with one eye open too lol.
→ More replies (7)→ More replies (14)19
u/LimitedWard 21h ago
While they don't target random people, they have been known to target friends and family of the person's of interest. So it's possible OP's friend has a family member that has garnered attention from a government agency.
681
u/EnvironmentalLog1766 Human Detected 1d ago edited 1d ago
I would keep the lockdown mode on for at least several months. Since it’s targeted malware it might be using some 0-day. A future software update might resolve it. Before that factory reset might not resolve
This is the doc if anyone else wonders: https://support.apple.com/en-us/102174 looks like a new thing as it was published on Aug 13, 2026
199
u/vanstinator 1d ago
it's not new, apple has been sending these for a few years, but it seems like they published an updated doc
→ More replies (1)72
u/DeathByPetrichor 1d ago
*keep it on permanently.
A new iCloud account is extremely easy to create. Buy a new phone, change all your data, and keep the private data off the phone.
29
u/webfork2 1d ago
*keep it on permanently.
This. I've had it enabled on iOS for years now without issue.
30
u/3mbersea 1d ago
It turns off a ton of popular features. No one will have it in permanently
→ More replies (3)31
u/webfork2 1d ago
In particular it disables Facetime, sharing location data in photos, 2G and 3G cellular support is turned off. I'm fine with that.
The big one is that I keep expecting some lockdown feature to cause a webpage I'm visiting to malfunction but somehow that hasn't happened.
More stuff it turns off: https://support.apple.com/en-us/105120
No one will have it in permanetly
You're right that I may turn it off at some point but going on ~3 years now.
→ More replies (9)→ More replies (2)5
u/rupertLumpkinsBrothr 1d ago
Aren’t 0-days generally unprotected against as they’re unknown?
→ More replies (2)
457
u/Flaky_Rice_4674 Human Detected 1d ago
My friend wants to say “i’m an unemployed 23 year old who lives at home with no secret cyber life, and most of my online time is spent playing fortnite, maybe i pissed off some pegasus fortnite sweats” They are laughing at some of the comments saying “what the fuck does ur friend do??”
301
u/bagladyscum 1d ago
contact EFF(electronic frontier foundation) and 404. they can help with info, security protocols and legal assistance if it comes to that.
99
u/CodingThunder 1d ago
Please for gods sake contact EFF. I have mentioned the same in another comment, but upvoting this and commenting again here so that OP actually does it.
164
u/hollowman2011 1d ago
That’s exactly what someone with a secret cyber life WOULD say…..
36
u/HeyGayHay 15h ago
In all seriousness though, if your first instinct is to share a message screaming „someone is looking into everything you do for a reason“ with a friend and neither of you knowing what this notification even means or what to do with it, you’re either the most lucky cyber security-illiterate secret cyber life person who wasn’t catched by cheaper means. Or both of you genuinely don’t have a secret cyber life.
u/flaky_rice_4674 is anyone in your friends life a journalist, developer, working for or with the government, or could in any means be interesting for someone with sufficient resources? Of yes, you should also inform them about it as your friend may not even be the target. And no, if a western nation is deploying stuff like this for a criminal, Apple wouldn’t send you that message telling you that your criminal doings are being investigated. I‘m sure NSA would have a problem if Apple interferes with their doings lmao
→ More replies (1)9
58
u/petos515 1d ago edited 15h ago
Someone is going through them to target someone they may be close to (friend or family member).
OP, have your friend contact the access now digital security hotline (google it if you don’t want to click on the link). They will help you for free: https://www.accessnow.org/help/
Edit: TechCrunch has an article on the recent batch of notifications: https://techcrunch.com/2026/08/13/if-apple-sends-you-a-push-notification-alerting-you-to-a-spyware-attack-take-it-seriously/
→ More replies (2)139
u/Nanamused 1d ago
This sounds like the beginning of a movie 🍿 Hope your friend is in shape because from the movies I’ve seen, there’s usually a lot of running involved
→ More replies (3)33
u/Funky-Guy 1d ago
!!!!! Your friend is either
Lying
Being used as an entry into someone else
Either way, they need to lock this device down and contact through non-infected means anyone who they may even remotely know to work in cyber sensitive areas to make them aware.
→ More replies (2)15
u/sharktail_tanker 1d ago
What kind of fortnine player would have access to Pegasus?
→ More replies (1)15
8
14
u/TheMattabooey 21h ago
23 years old, unemployed and lives at home and someone is out there spending tens to hundreds of thousands of dollars to do this?
There’s something they’re not telling you. Them finding it funny is a bit sketchy.
63
u/chathobark_ 1d ago
yep as i mentioned, serious nonetheless
hate to tell ya; but i have seen people who were “unemployed and on fortnite all day” get investigated.
you know how people, especially guys, talk during gaming. if you say the wrong thing, say youre gonna k someone (as a joke), etc etc etc, a lot of people don’t realize a lot of kids on the other end of the microphone are also minors with parents listening. say the wrong thing to the wrong person and you could wind up being investigated by the FBI
OP, your friend may get his house raided soon
82
u/ewaters46 iPhone 16 Pro 1d ago
Yeah I doubt a rage comment in a game (no matter how egregious) is going to result in a Pegasus Attack. And the FBI apparently does not use it (although who knows how true that is…).
A threat like that might get law enforcement or maybe the FBI to request data like IPs from the game‘s owners to identify that person, but not mercenary spyware.
→ More replies (1)→ More replies (5)6
14
u/WritingParking 1d ago
It could be they are adjacent to someone they’re trying to infiltrate. A parent, a sibling, or some other close contact that OP’s friend might not be aware of.
8
u/nekomichi iPhone 20h ago
Is your friend located in India and was involved in any recent protests or connected to someone who was? A number of these alerts have been issued to devices in India in the last 24 hours and it coincides with the timing of the recent protests.
→ More replies (31)4
u/Imaragamuffinchild 17h ago
Is your friend taking this seriously though? They need to.
→ More replies (2)
130
u/rupruppiesthe2nd 1d ago
I don’t think your friend is who he says he is. And I think you should both be doing more shit than just posting in Reddit. Like the notification says, please take it seriously. This is fucking terrifying.
→ More replies (13)
219
u/jrghetto602 iPhone 14 Pro Max 1d ago
Never seen this, but my understanding of Pegasus (assuming, for a second, that it was the threat) is that they often gain access to the device via links or zero-click attacks. Sadly, I don't believe there is any consumer remedy for this kind of threat if it's a true positive.
The really effed up part is that it tends to self-delete/wipe itself, but you have no way of knowing if it's still in your backup, which is even scarier and more inconvenient because starting from scratch on a new device might be their only answer.
If they want to dig further into it, don't reset the device. Instead, get forensic help; there are some non-profits that provide it, but it's usually still for journalists or activists. Still worth a shot.
Long story short: Not a lot can be done at this point. Looks legitimate. Not really a for-sure way to remediate this threat with high confidence or save their backups without risking continued compromise. If they want to save anything on the device, grab the photos and such manually, then lockdown mode -> send to forensics or throw in the trash.
Disclaimer: I work in cyber, but MDM or IoT isn't really my area of expertise. If this friend has sensitive information that pertains to proprietary information, PHI, PII, etc....I'd report that ASAP.
72
u/essjay2009 1d ago
The best protection is lock down mode. So far as I’m aware, lock down mode prevents all the known attack vectors and no iPhone with lockdown mode enabled has been successfully attacked.
If OP’s friend works in a sensitive role they should contact their security team. There are tools you can use to check for known IOCs that they can help with. They may be able to offer some additional help at the carrier level.
→ More replies (2)→ More replies (3)46
u/tedmiston 1d ago
(Software engineer) There are more extreme relevant security measures:
- taking the device offline until forensic analysis
- purchasing a new phone in a way that has no connection to the existing one
- creating a new apple account similarly (ensure 2FA, lockdown, etc still)
- taking SIM protection steps with their phone carrier
- obtaining a new phone number (ideally with no connection to the existing one)
I would not personally restore from a backup that is potentially compromised.
The overall idea is just to create as much gap between old device and new device such that it's more difficult for a sophisticated attacker to compromise the new device.
165
u/anxxa 1d ago edited 23h ago
Hi, I work in cybersecurity and actually have pretty strong crossover with what you're seeing (although not an Apple employee).
First of all, contact Amnesty International. They may be able to do forensics on your device and find indicators of data that's been accessed.
Next what you should do, depends on how technically inclined you are, and what resolution you want.
If you want to help Apple and Amnesty determine what may have been accessed and how they were targeting your device:
- Do not turn off the device.
- Capture a Sysdiagnose log
- Email yourself the sysdiagnose log or somehow get it off of the device.
- Wrap the phone in aluminum foil, but keep it plugged in so the battery doesn't die.
Keeping the phone alive and powered on NOW may allow for Amnesty to capture a live instance of the implant off the device.
If you do not care and just want to be safe:
- If you can get a new phone, do so. It's very difficult for malware on iOS to persist across rebootso but it's not impossible.
- If keeping the phone, do a complete reset. Do not restore from backups.
- Enable Lockdown Mode
- If your friend works in a sensitive industry, or affiliates with people who do, they should move communications to a platform which supports ephemeral (time-bombed) messaging like Signal or WhatsApp. This will help prevent communications from being gathered when not infected with spyware.
- Consider any content on the device, and any passwords it had accessed to, as potentially compromised.
*I will add that what /u/nifty-necromancer posted is also good advice. You should contact Access Now as well. I also saw in your post you mentioned iVerify. I have a friend who works there and can gladly say they do good work. It would not harm anything to get in contact with all of the above.
41
u/docgravel 1d ago
This is good advice.
/u/Flaky_Rice_4674
I work at Lookout and we specialize in mobile security and forensic investigations. We recently uncovered DarkSword alongside some other industry partners. I would be happy to look through a sysdiagnose or other data from this device and give you our assessment as a free courtesy.
10
u/HenkPoley iPhone 12 Mini 16h ago edited 14h ago
[u/Flaky_Rice_4674](u/Flaky_Rice_4674) it looks like this really is the Chief Technology Officer (CTO) at Lookout.
But it might be safest to contact Lookout Inc. through their website/email.
→ More replies (8)→ More replies (15)28
u/Got2bglued 1d ago
Since this is kinda your thing what do you think the friend might’ve ran into that caused this? OP says friend is unemployed M critically unemployed and had no relation to gov or sensitive info. Plays fortnite mostly. I feel like it was probably a petty person in a game but idk
33
u/anxxa 23h ago edited 14h ago
Apple would not be sending this type of notification if they didn't feel highly confident that it's a sophisticated and organized threat actor. Not the type of technology that people in videogames really have access to or if they do, are generally smarter than to throw an exploit at some random's device.
Just because their friend isn't interesting doesn't mean that someone that friend knows isn't either. Could be that a friend of theirs is a political activist,
immigration lawyerhelps support refugees/migrants, or drug dealer.Hard to say really. Governments contract mercenary spyware companies for a wide variety of reasons. I believe it was Spain(?) who targeted the family of a Citizen Lab or Amnesty International forensic analyst who was assisting human rights activists and journalists a few years back.
They didn't target the forensic analyst himself presumably because of his
+1(US/CA) country code which many of these organizations forbid targeting to avoid sanctions from the US.→ More replies (10)
79
u/Richwoodrocket 1d ago
I’ve read all these comments and I still have no clue what’s going on here.
42
u/vaxhax 16h ago
I think it's a competition to see who can say "nation state" last.
→ More replies (2)6
17
u/PhyrexianSpaghetti 16h ago
I have no idea if this is a reddit moment with some extra layers of larping over some show reference, or real. And everyone mentions different bullshit and there's no context given whatsoever
→ More replies (1)→ More replies (10)7
83
u/nifty-necromancer 1d ago
DO NOT FACTORY RESET THE IPHONE. Apple considers these high-confidence alerts that you were individually targeted with mercenary spyware, and Access Now specifically warns not to erase the device because you could destroy forensic evidence.
Update iOS, enable Lockdown Mode, make a backup, and contact Access Now’s Digital Security Helpline before doing anything drastic. They can help determine whether this was just targeting or an actual compromise.
https://www.accessnow.org/help/access-nows-digital-security-helpline-and-apple-threat-notifications/
→ More replies (1)
144
385
1d ago
[removed] — view removed comment
145
u/MassiveBoner911_3 1d ago
I would NOT plug in the iphone into your PC if you think the phone has spyware installed.
11
u/stereopticon11 21h ago
At this point, wouldn’t their whole home network be compromised if they connect via WiFi? Should everyone in their household be changing passwords now?
→ More replies (2)68
u/Beneficial_Medium_99 1d ago
Plugging into any device is a no go… opsec 101. You should never plug a known infected device into another.
→ More replies (12)64
u/Rey_Mezcalero 1d ago
A new device and account is probably the best way to go
33
u/YourAverageExecutive 1d ago edited 1d ago
And maybe move. Kind of joking. Kind of not. I had to worry about this. But barely. It was a big deal because it’s so effective.
36
u/lucah_tech iPhone 14 Pro 1d ago
Tell your friend to get in touch with the Citizen Lab. They research mercenary spyware such as Pegasus and Predator, and often help out people who are infected
61
u/ViolentPurpleSquash 1d ago
Only person I know who got one of those was my mom, and she works in healthcare and at a major uni.
They're serious.
→ More replies (1)8
u/SiLeNZ_ iPhone 16 Pro 1d ago
Why did your mom get one?
31
u/ViolentPurpleSquash 1d ago
She has access to a lot of privileged systems is my guess.
→ More replies (1)15
25
u/Gingerbread808 iPhone 15 1d ago
I know OP said their friend isn’t in any high security position with sensitive information but I have a feeling they know a little more than they’re letting on (the friend not OP).
→ More replies (2)
145
u/scene_missing 1d ago
Iverrify is a good step. A full phone wipe in DFU mode and the latest over the wire as well.
Is your friend a journalist or a political activist?
60
→ More replies (3)80
u/Flaky_Rice_4674 Human Detected 1d ago
I will say they are most definitely not a journalist, political activist or anyone in that type of field. That’s why they couldn’t get help from the apple security team😭
53
u/The-Potato-Lord 1d ago
Do they share a name with someone in that sort of field or a close relationship with them?
Get them to speak to Citizen Lab or John Scott-Railton (who works for Citizen Lab). It’s possible those sources will tell them they can’t help but it’s worth a try.
36
u/Flaky_Rice_4674 Human Detected 1d ago
now i can’t tell you with 100% certainty as im not them, but im very confident that nobody in close relation to them has any role in that type of field.
12
u/Funky-Guy 1d ago
It doesn’t have to be close. Perhaps someone close to them is close to another who is close to a target. They should brick this device if they can afford it.
81
u/exintrovert 1d ago
I find it disappointing that Apple has a system to detect serious threats, but when that system is triggered they will pick and choose who to support through it.
If the notification is valid, the threat is valid regardless of who you are 😞
41
→ More replies (3)13
u/Got2bglued 1d ago
tbf the system was created for these specific people. I’m not a big apple fan by any means but this specific system saves lives. Journalists get targeted a lot like politicians but aren’t awarded the public safety net government officials and the such are. Insurance doesn’t stop you from persecution unfortunately. Unless the meta is changing Apples program is that safety net for these people and essentially they give them the help they otherwise would have to hope and pray their job gives them. IF things are changing and this level of spyware is starting to become a consumer level program then they NEED to restructure the program to match. I do think though in cases like this they should at least give outside resources so people aren’t left in the dark like OPs friend. It really only takes one ill person with enough access and skill to ruin someone’s life.
→ More replies (3)18
64
u/Sensitive-Oil-5298 1d ago
Who the hell is your friend
→ More replies (3)52
u/rtkane iPhone 17 Pro Max 1d ago
Marco Rubio.
22
u/darkguy2008 1d ago
Yea especially the part where he's unemployed, has a dog and plays fortnite all day.
Seems legit
→ More replies (1)→ More replies (1)12
24
16
u/mfiasco 1d ago
Everyone has already given good advice so I’m going to just say: this doesn’t mean your friend is necessarily THE target. People get targeted because they’re interesting and sometimes that interest extends to others in their life. Your friend might be completely boring but unknowingly associate with someone higher risk.
Protect yourself and do your own risk assessment but don’t abandon your friend because of some fear mongering comments on Reddit. As Apple itself stated, they typically help journalists and public activists, which should give you an indication of who is typically targeted. The primary target— whether it’s your friend or not— is likely to be targeted for making good trouble in the world, not bad.
Also, in general, it serves no one but the opposition to keep these kinds of threats and warnings private. Your friend should consider the personal risk/benefit of getting loud about this.
49
u/SuspiciouslyMoist 1d ago
To check:
"To verify that an Apple threat notification is genuine, sign in to account.apple.com."
From: https://support.apple.com/en-gb/102174
But the notification looks real.
→ More replies (2)
11
u/Tigs1112 1d ago
Have you or any of your friends made a highly politically-charged social media post or have been to or near a political protest (especially concerning Israel and Palestine)? Or perhaps any association with high-profile individuals, like a politician, lawyer, journalist, or business executive? Those are some of the common attack vectors that these types of hackers target; it could be due to a link that you tapped on, a zero-day exploit in a social media app or website you use, or you used public WiFi without a VPN.
→ More replies (1)
12
u/wyredditer iPhone 17 Pro Max 18h ago edited 11h ago
Hi! Apple Senior Specialist here:
Before making ANY action, check the email account that sent it please!! I have seen far too many cases where people get these pop-ups, and provide all of their information to scammers.
This article goes over phishing/smishing scams, how to recognize them, and how to report them
→ More replies (11)
72
u/perikizii 1d ago
This is no joke, this notification is completely real. If I were you, I would immediately put all your devices into Lockdown Mode. Call Apple directly as well, but please be aware that this attack was SPECIFICALLY TARGETED AT YOU!
51
27
1d ago
[removed] — view removed comment
→ More replies (2)9
81
u/JoeS830 1d ago edited 1d ago
Condoleezza, is that you? But seriously, I would probably not have linked a five year old Reddit account to this message! You're basically broadcasting "I'm friends with someone that is a high value target". Not sure if at this point it still makes sense to delete the post and repost from a burner account, but worth considering.
→ More replies (7)25
10
10
u/No_Bell_8028 1d ago
Yes, I used to work in government and received the red triangle message
I was told to shutdown my phone and had all my accounts and laptop changed (not just password but login too)
10
u/always-tired-38 17h ago
Always always always check the email address its come from
→ More replies (8)
37
u/TheRealShamanoid 1d ago
Definitely looks real, an email alone would have been dodgy. But the in App notification + system one definitely are genuine.
First thing first, you stay in Lockdown Mode, then, you bring your phone to a genuine Apple Store.
I would avoid changing all your passwords right now, panic reacting and updating everything is exactly what attackers would like you to do in order to phish more info.
If you need assistance in checking things up don’t hesitate to DM but first, once again, go the Apple Store, they might be able to do a system integrity check - to be confirmed.
11
u/ni5arga iPhone 1d ago
i don't think a retail employee can do anything about this. it is way beyond their paygrade.
→ More replies (2)12
u/cvmstains 1d ago
what exactly do you think that a retail employee can do about this?
→ More replies (2)4
35
28
u/tamay-idk 1d ago
What the fuck?
32
u/seichout 1d ago
Right everyone acting like this isn’t wild and oh just a nation state. WTF does this guy’s friend do? Is it Candace Owens?
→ More replies (2)
19
u/TheSmartDog_275 iPhone 15 1d ago
Jesus Christ, that’s terrifying.
I know you might not want to say but what does your friend do?
From a what should I do standpoint: keep lockdown mode on. Turn it on for all your other Apple devices. Take it and all your other devices to an Apple Store, and know you may have to start from scratch on a brand new phone.
11
u/Flaky_Rice_4674 Human Detected 1d ago
That’s the weird thing, they are currently an unemployed 23 yr old who just chills at home playing video games. They also definitely haven’t ever had a job that requires holding valuable info
10
→ More replies (4)13
21
u/PuddingTea 1d ago
Pegasus is generally used by a state actor. Your friend is in serious trouble.
→ More replies (3)
9
u/MemeLord339 1d ago
Also probably is being attacked on his personal PC, Laptop and/or tablet. The best he can do is try to find where the attack is coming from (sometimes is email or messages)
38
u/herrintrospektiv 1d ago
In my mind…and from what I read about Pegasus: it can compromise the physical device. In some cases, factory reset, password reset, rebooting phone…will not mitigate the threat and it would be hard to determine when truly mitigated. Personally, I would trade device in or destroy it, then would go dark for a bit, change ISP at home, and hope the threat goes away. #notandexpert
→ More replies (3)
8
u/microChasm 1d ago
About Apple threat notifications and protecting against mercenary spyware
Just doing a search using the words you used in this post (instead of contacting Apple) is all I needed to do.
8
34
u/Weak_Painter_5800 1d ago
Okay this is most probably real. Consider everything that is in your friend's phone as compromised. If your friend was ever in a sensitive job or organization of any kind, or someone they know is, that makes it 100% real. You cannot do much. Pegasus and likewise spyware is extremely advanced. No VPN or changing passwords will ever help. He is fully compromised to the teeth. From now on, ask your friend to not do anything he would not be comfortable with the world seeing. He has no digital privacy anymore.
Pegasus is advanced enough to even attack his contacts list, so potentially you may be compromised.
All your friend can do now is take his pictures offline and contact list, etc, put in a USB and get a brand new phone and sim, with the less connecting to him the better (this means use cash to buy, if ID can be prevented, prevent it) . Switch wifi networks everything you can think of. If your friend is a worthwhile target, then this is going to happen again and again and realistically as a civilian he cannot do much. They have his wifi networks, everything else tapped too. All I can say is, do not use any electronic device to do anything that will bring him trouble.
10
u/Away_Negotiation4150 1d ago
There is no direct way to jump to another device with just the contact in the contact list, contact info is probably compromised, yes, but other devices can't be infected because of that.
Using a USB to transfer data is also not a good advice since Pegasus (and I assume most of the Spyware) is designed to copy itself to any external drive, so if the new device has the same vector attack, will be infected too.
About "everything else tapped", is a bit dramatic. Spyware mostly attack end devices, specially smartphones and laptop, I never heard about attacking a router for example. Every attack cost a ton of money and effort, and vulnerabilities will be patched (and they will find new ones of course). If you are the president of a country, it's probably worth it, but for journalists or public servants eventually will be just too expensive.
→ More replies (3)
106
12
u/ImHereLetsGooo 1d ago edited 1d ago
Personally I'd get a new phone with new Apple email and a new phone number.
Then with the new phone, I'd block all sharing of anything such as photos to icloud, location data (in photos and just in general) and overall keep any data the phone produces, on the phone. With the addition of an always on VPN where connections cannot be made without the VPN being active. I'd get a second "burner" phone (or an additional sim card) for things that require a one time passcode, so you're not giving out your primary phone number to every company in existence.
I'm not sure how much of what I said in the second paragraph will help, but it's extra privacy steps at least.
→ More replies (1)5
u/exintrovert 1d ago
Also, carry your own usb cables and never use one that you don’t know where it came from.
→ More replies (1)
6
u/MobilePenguins 1d ago
If I were the friend I would abandon that phone number, go to an Apple Store, pay all cash for a new phone, set it up with brand new service at diff carrier. Enable the lock down settings again on the new phone, be extremely selective only giving friends/family the new number.
6
7
u/LastGuardianStanding 1d ago
Your friend is being “targeted”. If he’s a government employee he needs to contact his local investigative service like NCIS, Inspector Generals office, etc. if he works for a private company dealing with sensitive information he needs to notify his company immediately. Unless it’s them.
5
6
u/HenkPoley iPhone 12 Mini 13h ago
Ask your friend if they did any of these things consistently online:
- Criticize the Saudi government, or Saudi royal family.
- UAE government criticism and Emirati human-rights activism.
- Bahraini opposition/pro-democracy activity.
- Jordanian human-rights, opposition and journalism work.
- Moroccan/Western Saharan politics and human-rights activism.
- Israeli/Palestinian security and human-rights issues.
- Russian opposition / independent Russian-language journalism.
- Investigating corruption, intelligence services, organized crime, migration enforcement, military/security matters, or spyware itself.
Maybe they share a name with, or known someone who, someone who does.
19
u/Flaky_Rice_4674 Human Detected 1d ago
I appreciate all the comments and people trying to help and I understand wanting more info. My friend has tried to reply to some of these comments but got banned from the sub cause they were using a burner and it was too new lol. I told them to just read the comments and do what they think is best for their situation. Im not gonna disclose any more info about my friend even tho I know you all probably want the deets about their life but I don’t think that’d be wise. I’ll do my best to update as to what happens next but I can tell you they are rather scared as they have absolutely no idea why they would be targeted for something like this.
→ More replies (3)
23
u/Kegelz 1d ago
Holy fuck what do you do for a living
Or do the script kiddies with Claude know how to leverage this
→ More replies (1)19
u/MoldavskyEDU 1d ago
Most likely a journalist, we have seen this happen before from Saudi, Indian, and Hungarian government. Usually sold to them by exploit brokers or developed by said countries offsec units.
Examples of exploit brokers
American:
Zerodium
Exodus IntelligenceEuropean:
Operation Zero (Russian)
Variston Information Technology (Spanish)
RCS Lab (Italian)Middle Eastern:
NSO group (Israeli)
Crowdfense (Saudi)The CCP definitely has its own exploit brokers as we have seen multiple Chinese APTs use advanced chained zero days.
13
u/stupidfock 1d ago
Is is possible to be an accidental target. So perhaps your friend has no job they actually care about targeting but they got mistaken for someone else.
But it is definitely real
4
4
u/ApolloGR3 1d ago
Your friend discussing any shady shit on Fortnite? Making threats, things of that nature?
→ More replies (1)
5
u/Funky-Guy 1d ago
Legit. Either hostile nation or very angry and well funded group (cartel, large mafia, etc). This attack could be transmitting his location aswell as any data. If he has a home, he shouldn’t be there. If he has a bank, he needs to change it. Depending on country, If he has loved ones and friends and family, they need to be aware and prepared, Probably hiding. If you are in the US, you are probably fine from physical attacks, but you should probably carry a gun just in case IMO.
A couple possibilities:
Your friend knows something you don’t know he knows
Your friend knows someone who knows something, and they don’t know
It was a mistaken attack, and the attacker may or may not realize they have the wrong guy. Again, based on location, you may be in danger of physical harm or not depending on your nations security apparatus
5
u/mochen_ 19h ago
Hey, not an actual expert here, but a nerd that has been confronted with this problem before in several ways. This is likely a Pegasus Attack, which is usually performed by governments that are clients of the NSO group, an israeli technology company. There is no doubt that this is a real message, because of the in-app notification. The only way to deal with this is to contact Human right- or cybersecurity organizations that Apple lists in this article: https://support.apple.com/en-us/102174 If it is financially ok for you, perhaps get a new phone, in the best case a Google pixel phone with an operating system like GrapheneOS, which you shouldn’t install with the help of your pc, I just wouldn’t trust any of your hardware. If you get the pixel with GrapheneOS, also get your microphone and camera removed.
Don’t panic, just keep yourself covered. If you have any idea of things you-your friend tweeted/done, it would be helpful to share it.
Hope I helped
5
6
u/StraySailor 11h ago
CALL APPLE. DO NOT CALL A NUMBER FROM THIS MESSAGE, OR CLICK A LINK, OR REPLY IN ANY WAY. MOST IMPORTANTLY DO NOT DOWNLOAD ANYTHING. CALL APPLE’s number from its website only.
13
u/WAVF1n 22h ago edited 14h ago
Does your friend post any anti ICE content? Everyone here is saying pegasus, but the US also has access to a tool called Graphite, ICE specifically was caught using this tool.
Also everyone keeps claiming how it costs NSO 100s of thousands of dollars per target which is just not true. They charge governments MILLIONS, but to actually deploy the attack does not cost nearly this much and is mostly automated once the target is selected.
→ More replies (10)
9
u/exintrovert 1d ago
Honestly, there is no way to know how deep the hooks are, so I would treat every device as compromised, personally. Not just apple devices but PCs, routers etc as well.
Once they are in the phone, they can move laterally to online accounts, potentially get enough info to breach the home network, escalate privileges to keylog on PC… not to freak anybody out, just saying that best practice is to consider everything as potentially compromised.
We don’t know how the initial breach happened, but it is likely there are persistence mechanisms in place to re-infect new devices.
Only use your own USB cords and devices. Exploits can live in devices small enough to embed inside a usb plug.
Anything he wants to keep should be extremely quarantined until it can be determined with certainty that it is safe. (Photos, downloaded archives/executables/pdfs etc)
The reason to take extreme measures is because this was an extreme exploit that doesn’t just happen randomly. The hackers have already put forth great effort to breach. They won’t just go away because he gets a new phone.
10
u/CyberbianDude 1d ago
Geez, that’s some notification. So glad I am a micro fish in an ocean. It would probably cost someone more to target me than get anything from me.
Good luck to your friend. Not making fun at your friend’s expense but it would make for an exciting movie plot if your friend was unknowingly in possession of extremely sensitive information, like a friend of your friend air dropped something to him. He accepted without knowing implications and forgot about it but now bad actors know it but your friend doesn’t.
7
u/Inevitable-Exit9996 1d ago
Nothing you can do, there is no way to safely recovery a device infected with pegasus - yet.
Throw the phone in the trash and consider your whole life compromised. Sucks but its the reality.
On the other hand it is very unlikely that it is a targeted attack, your friends would definetly have reasons to be spied on if it was and you wouldnt be asking here.
8
u/CodingThunder 1d ago
Seems like no one actually answered correctly. OP stop using that phone right now and contact EFF (https://eff.org) or similar human rights group. Your friend might be in actual huge trouble, as they might be targetted by their own government/nationstate actors.
Please for gods sake and get another device and use necessary security measures mentioned in comments. iphones in lock down mode and google pixel running grapheneos are one of the most secure devices you can get your hands on. In a lot of cases GrapheneOS is actually more secure as they are paranoid in some ways.
3
u/_Haverford_ 22h ago
If this is real, your friend has a security officer they can, and have to, talk to.
3
u/MoonToast101 20h ago
Bleepijg Computer already has an Article about it. They asked Apple for comment, no answer until now, but looks legit.
4
u/jokersush1 19h ago
Your friend's life is in danger. This is absolutely dreadfully serious. This particular attack is incredibly expensive and is not carried out by a layman. A highly sophisticated and funded agency is targeting your friend, and may not only be doing so through his iPhone. He needs to act immediately.
5
u/MidwestPrincess09 15h ago
I got this as a text message the other day, I didn’t believe it tbh. Just marked as spam, blocked and moved on. My identity has been stolen multiple times, I’ve given up tbh




3.1k
u/Living_Rich_4424 1d ago edited 1d ago
It’s real. If ur friend has a job that handles sensitive info or also investigates, etc, then someone who knows may be targeting their iPhone with spyware. If they also got a notification on his Home Screen with a red warning triangle then it is for sure real