Apps & Consumer
What to do if you receive a government spyware alert
Tech companies are increasingly alerting users to potential government spyware attacks, but they do not provide direct assistance, leaving victims to navigate forensic remediation on their own.
Tech companies including Apple, Google, and WhatsApp are increasingly proactive in alerting users when they become targets of government hackers. For instance, Apple users might receive a notification stating, “Apple detected a targeted mercenary spyware attack against your iPhone.” In this context, mercenary spyware refers to spyware developed by private companies for government use. However, receiving a notification from Apple or WhatsApp does not necessarily mean the user was hacked, as the attempt may have failed. While these tech giants use their telemetry data to detect malicious activity, they do not provide direct assistance once they send the warning, leaving users to manage the aftermath.
Investigating these attacks has become significantly more difficult because modern spyware may not leave any traces on a device. According to Hassan Selmi, who leads the incident response team at the nonprofit Access Now, spyware manufacturers often employ a “smash and grab” strategy. This is a strategy where spyware steals data and deletes itself to avoid detection. By infecting a device, stealing data, and removing traces, the spyware hides its activity from investigators and protects the product from being analyzed.
Because tech companies do not offer direct forensic support, targeted individuals must seek external help. For former spyware company employee Jay Gibson, receiving an alert triggered immediate panic. “I was panicking. It was a mess. It was a huge mess,” Gibson said. Depending on their professional role, targeted individuals can turn to several specialized organizations and private firms for forensic investigations:
- Access Now: A nonprofit operating a 24/7 global digital security helpline.
- The Citizen Lab: A university-based digital rights research group that has been investigating spyware abuses for almost 15 years.
- Amnesty International: A nonprofit organization that investigates spyware cases.
- Reporters Without Borders: A nonprofit offering digital security investigations.
- iVerify: A private security company offering forensic investigations.
- Safety Sync Group: A security startup offering forensic investigations.
- Hexordia: A security startup offering forensic investigations.
- Lookout: A mobile cybersecurity company offering forensic investigations.
- TLPBLACK: A security research team with experience analyzing cyberattacks from government hacking teams in the United States, Russia, and Iran.
Why it matters
Tech companies are increasingly proactive in alerting users to government-backed spyware attacks, but they do not provide direct assistance, leaving users to navigate forensic investigation and security remediation on their own.