Close Menu
TechBrunchTechBrunch
  • Home
  • AI
  • Apps
  • Crypto
  • Security
  • Startups
  • TechCrunch
  • Venture

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

What's Hot

Glow emerges from stealth with $1.2 billion valuation to take on endpoint security in the age of AI

July 22, 2026

Dimension Capital's $800 million third fund shows the intersection of science and computing is burgeoning

July 22, 2026

Breach of AI music generator Suno affects 55 million users (via Have I Been Pwned)

July 21, 2026
Facebook X (Twitter) Instagram
TechBrunchTechBrunch
  • Home
  • AI

    OpenAI seeks to extend human lifespans with the help of longevity startups

    January 17, 2025

    Farewell to the $200 million woolly mammoth and TikTok

    January 17, 2025

    Nord Security founder launches Nexos.ai to help enterprises move AI projects from pilot to production

    January 17, 2025

    Data proves it remains difficult for startups to raise capital, even though VCs invested $75 billion in the fourth quarter

    January 16, 2025

    Apple suspends AI notification summaries for news after generating false alerts

    January 16, 2025
  • Apps

    Google brings Pixel 6 and new devices to Material3 Expressive, along with other features, to the Pixel 6 and new devices

    September 3, 2025

    Google's NoteBookLM now allows you to customize the tone of your AI podcasts

    September 3, 2025

    Roblox expands the use of age estimation techniques and introduces standardized assessments

    September 3, 2025

    Instagram finally launches the iPad app

    September 3, 2025

    Complete the 2025 Confusion Builder Stage Agenda with the Maximum Scaling Voice

    September 3, 2025
  • Crypto

    Trump Meme Coin Investors Lost $3.8 Billion, Analysis Finds

    July 5, 2026

    Venice AI becomes unicorn with $65M Series A as privacy-first AI platform takes off

    July 1, 2026

    Disrupt 2026 Builders Stage Agenda Revealed

    July 1, 2026

    Crypto exchange OKX wants to hire AI agents and pay each other

    June 30, 2026

    Founder Summit early bird pricing ends tonight

    June 26, 2026
  • Security

    Glow emerges from stealth with $1.2 billion valuation to take on endpoint security in the age of AI

    July 22, 2026

    Breach of AI music generator Suno affects 55 million users (via Have I Been Pwned)

    July 21, 2026

    Hackers are exploiting a recently patched WordPress bug, putting millions of websites at risk

    July 20, 2026

    Hackers steal 'vast amounts' of data from technology company used by thousands of US hospitals and pharmacies

    July 20, 2026

    Watch Flock Safety CEO Garrett Langley talk about the future of surveillance at TechCrunch Disrupt 2026.

    July 20, 2026
  • Startups

    7 days left: Founders and VCs save over $300 on all stage passes

    March 24, 2025

    AI chip startup Furiosaai reportedly rejecting $800 million acquisition offer from Meta

    March 24, 2025

    20 Hottest Open Source Startups of 2024

    March 22, 2025

    Andrill may build a weapons factory in the UK

    March 21, 2025

    Startup Weekly: Wiz bets paid off at M&A Rich Week

    March 21, 2025
  • TechCrunch

    OpenSea takes a long-term view with a focus on UX despite NFT sales remaining low

    February 8, 2024

    AI will save software companies' growth dreams

    February 8, 2024

    B2B and B2C are not about who buys, but how you sell

    February 5, 2024

    It's time for venture capital to break away from fast fashion

    February 3, 2024

    a16z's Chris Dixon believes it's time to focus on blockchain use cases rather than speculation

    February 2, 2024
  • Venture

    Dimension Capital's $800 million third fund shows the intersection of science and computing is burgeoning

    July 22, 2026

    BlueCore Energy raises $10 million to build portable nuclear reactor on barge

    July 21, 2026

    Natural raises $30M to reinvent payments for AI agents and take on Stripe

    July 20, 2026

    Inference startup Infinity raises $15 million from Touring Capital, OpenAI, and Anthropic researchers

    July 20, 2026

    StrictlyVC returns to New York City on September 10th to celebrate a big year for the city's startup community

    July 20, 2026
TechBrunchTechBrunch

You are being targeted by government spyware. Well, what is it?

TechBrunchBy TechBrunchDecember 29, 20258 Mins Read
Facebook Twitter Pinterest Telegram LinkedIn Tumblr WhatsApp Email
Share
Facebook Twitter LinkedIn Pinterest Telegram Email


It was an ordinary day when Jay Gibson received an unexpected notification on his iPhone. “Apple has detected a targeted spyware attack on your iPhone,” the message read.

Ironically, Mr. Gibson once worked for a company that developed the very type of spyware that could trigger such notifications. Still, he was shocked to receive the notification on his phone. He called his father, turned off his cell phone, and went to buy a new cell phone.

“I was panicking,” he told TechCrunch. “It was a mess. It was a huge mess.”

Gibson is just one of a growing number of people receiving notifications from companies like Apple, Google and WhatsApp. All of these companies send similar warnings to users about spyware attacks. Technology companies are becoming more proactive in warning users if they are targeted by government hackers, especially those using spyware created by companies like Intellexa, NSO Group, and Paragon Solutions.

But while Apple, Google and WhatsApp have issued warnings, they are not involved in what happens next. Tech companies direct users to people who might be able to help them, but at that point they back off.

This is what happens when you receive one of these warnings.

caveat

You received a notification that you have been targeted by government hackers. Well, what is it?

First of all, please take it seriously. These companies have large amounts of telemetry data about you and what's happening with both your devices and online accounts. These tech giants have security teams that have been tracking, researching, and analyzing this type of malicious activity for years. If they think you're being targeted, they're probably right.

In the case of Apple and WhatsApp notifications, it's important to note that receiving a notification doesn't necessarily mean you've been hacked. The hacking attempt may have failed, but it still shows that someone tried.

Photo showing the text of a threat notification sent by Apple to a possible spyware victim (Image: Omar Marques/Getty Images)

In the case of Google, the company likely blocked the attack and you should access your account and make sure multi-factor authentication (ideally a physical security key or passkey) is turned on, as well as the Advanced Protection program. This requires a security key and adds another layer of security to your Google Account. In other words, Google can teach you how to better protect yourself in the future.

In the Apple ecosystem, lockdown mode must be turned on. This turns on a series of security features that make it harder for hackers to target Apple devices. Apple has long maintained that there have been no successful hacks against users with Lockdown Mode enabled, but no system is perfect.

Mohammed Al Maskati, director of the Digital Security Helpline at Access Now, a global team of security experts that investigates spyware incidents against members of civil society 24/7, shared with TechCrunch the advice the helpline gives to people concerned about being targeted by government spyware.

This advice includes keeping your device's operating system and apps up to date. Turn on Apple's Lockdown Mode and Google's Advanced Protection for your account and Android devices. Be wary of suspicious links and attachments. Restart your phone regularly. And you need to pay attention to changes in the functionality of the device.

Contact Us Did you receive a notification from Apple, Google, or WhatsApp that you're being targeted by spyware? Or do you have information about the spyware manufacturer? We'd love to hear from you. You can contact Lorenzo Franceschi-Bicchierai securely from your non-work device on Signal (+1 917 257 1382), on Telegram and Keybase @lorenzofb, or by email.

ask for help

What happens next depends on who you are.

There is an open source, downloadable tool that anyone can use to detect suspected spyware attacks on their devices, but it does require some technical knowledge. Mobile Verification Toolkit (MVT) is a tool that allows you to look for forensic evidence of an attack yourself, perhaps as a first step before seeking assistance.

If you don't want or can't use MVT, you can contact someone directly who can help. If you're a journalist, dissident, academic, or human rights activist, there are several organizations that can help.

You can contact Access Now and its Digital Security Helpline. You can also contact Amnesty International. Amnesty International has its own investigative team and has extensive experience in such cases. Alternatively, you can contact The Citizen Lab, a digital rights group at the University of Toronto that has been researching spyware abuse for about 15 years.

If you're a journalist, Reporters Without Borders also has a Digital Security Lab that offers investigations into suspected hacking and surveillance incidents.

People outside these categories, such as politicians and business executives, will have to go elsewhere.

If you work for a large company or political party, you probably have a competent (hopefully!) security team readily available. They may not have the specific knowledge to dig deeper, but in that case, they probably know who to turn to, even if Access Now, Amnesty, and Citizen Lab can't help people outside of civil society.

Otherwise, there aren't many places to turn to business owners and politicians, but we asked around and found the following. Although we cannot fully vouch for these organizations or directly support them, it is worth pointing them out based on suggestions from people we trust.

Perhaps the best known of these private security companies is iVerify. The company has created an app for Android and iOS that also gives users the option to request a detailed forensic investigation.

Matt Mitchell, a well-known security expert who has helped vulnerable people protect themselves from surveillance, has launched a new startup offering this type of service called Safety Sync Group.

Jessica Hyde is a forensic investigator with experience in both the public and private sectors who runs her own startup called Hexordia and offers to investigate suspected hacking cases.

Mobile cybersecurity company Lookout has experience analyzing government spyware around the world and has an online form where you can request help investigating cyberattacks involving malware, device compromise, and more. The company's threat intelligence and forensics teams may then become involved.

Next is Costin Raiu, who leads TLPBLACK. TLPBLACK is a small team of security researchers formerly working at Kaspersky Lab's Global Research and Analysis Group (GReAT). Raiu was in charge of the unit when his team discovered sophisticated cyberattacks by elite government hacking teams from the United States, Russia, Iran and other countries. Raiu told TechCrunch that anyone who suspects they have been hacked can email him directly.

investigation

What happens next depends on who you go to for help.

Typically, the contacting organization may wish to perform an initial forensic check by referring to the diagnostic report file that can be created on the device. Diagnostic report files can be shared with remote investigators. There is no need to give your device to anyone at this time.

This first step could potentially detect targeting and even signs of infection. Sometimes nothing happens. In either case, investigators will need to investigate further and may need to have a complete backup of the device or send you the actual device. At that point, investigators begin their work, which can take some time as modern government spyware attempts to hide and remove their traces, telling us what happened.

Unfortunately, modern spyware may leave no trace. Hassan Selmi, who leads the incident response team at Access Now's Digital Security Helpline, said the latest tactic is a “smash-and-grab” strategy, meaning that once spyware has infected a target device, it attempts to steal as much data as possible, remove all traces and uninstall itself. This is likely an attempt by spyware manufacturers to protect their products and hide their activities from investigators and researchers.

If you are a journalist, dissident, academic or human rights activist, the organizations supporting you may ask you if you wish to publicize the fact that you have been attacked, but you are not required to do so. They will be happy to help you without public recognition. However, you may have a good reason for coming out. To denounce the fact that the government has targeted you. This may have the side effect of alerting others like you to the dangers of spyware. Or they can expose spyware companies by showing their customers misusing their technology.

I hope you don't receive any notifications like this. But if you are, I hope you find this guide useful. Please stay safe.



Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

Glow emerges from stealth with $1.2 billion valuation to take on endpoint security in the age of AI

July 22, 2026

Breach of AI music generator Suno affects 55 million users (via Have I Been Pwned)

July 21, 2026

Hackers are exploiting a recently patched WordPress bug, putting millions of websites at risk

July 20, 2026

Hackers steal 'vast amounts' of data from technology company used by thousands of US hospitals and pharmacies

July 20, 2026

Watch Flock Safety CEO Garrett Langley talk about the future of surveillance at TechCrunch Disrupt 2026.

July 20, 2026

Face Hug confirms that internal datasets and credentials have been compromised, prompting users to take action

July 20, 2026

Leave A Reply Cancel Reply

Top Reviews
Editors Picks

7 days left: Founders and VCs save over $300 on all stage passes

March 24, 2025

AI chip startup Furiosaai reportedly rejecting $800 million acquisition offer from Meta

March 24, 2025

20 Hottest Open Source Startups of 2024

March 22, 2025

Andrill may build a weapons factory in the UK

March 21, 2025
About Us
About Us

Welcome to Tech Brunch, your go-to destination for cutting-edge insights, news, and analysis in the fields of Artificial Intelligence (AI), Cryptocurrency, Technology, and Startups. At Tech Brunch, we are passionate about exploring the latest trends, innovations, and developments shaping the future of these dynamic industries.

Our Picks

Glow emerges from stealth with $1.2 billion valuation to take on endpoint security in the age of AI

July 22, 2026

Dimension Capital's $800 million third fund shows the intersection of science and computing is burgeoning

July 22, 2026

Breach of AI music generator Suno affects 55 million users (via Have I Been Pwned)

July 21, 2026

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

© 2026 TechBrunch. Designed by TechBrunch.
  • Home
  • About Tech Brunch
  • Advertise with Tech Brunch
  • Contact us
  • DMCA Notice
  • Privacy Policy
  • Terms of Use

Type above and press Enter to search. Press Esc to cancel.