Sources: FBI did not use Cellebrite to crack San Bernardino iPhone, paid hackers for undisclosed software flaw that was used to create hardware to crack PIN
FBI paid professional hackers one-time fee to crack San Bernardino iPhone — The FBI cracked a San Bernardino terrorist's phone …
Context & Ripple Effects
Earlier reporting attributed the San Bernardino unlock to Israel's Cellebrite, but sources now say the FBI instead paid professional hackers a one-time fee for an undisclosed software flaw, which was turned into hardware that brute-forces the shooter's PIN — closer to the NAND-mirroring approach analysts speculated about than to a forensics-vendor service.
The correction lands alongside two disclosures that frame its significance: the FBI has admitted paying over $1.3M — the most it has acknowledged spending on a hacking technique — and it confirmed it will not send the method to the government review that could have forced sharing details with Apple.
First-order effects
- Apple will not learn of the flaw through any official channel, because the FBI's refusal to submit the method for interagency review removes the mechanism that could have compelled disclosure — leaving the iOS vulnerability unpatched and unknown to the vendor.
- Cellebrite's role is now contradicted by sourcing, a reputational hit for the forensics firm that had been publicly credited with the crack, while the anonymous hackers hold a technique Reuters reports works on any iPhone 5c running iOS 9 without further payment.
Second-order effects
- Gray-market exploit sellers just gained proof that the FBI pays premium one-time fees for undisclosed flaws, strengthening their hand in future negotiations with law-enforcement buyers who cannot compel vendors like Apple to cooperate.
- Other agencies facing locked iPhones can now buy or reuse the same hardware approach for the 5c/iOS 9 population at no additional cost, shifting demand away from commercial forensic vendors toward bespoke hacker-built tools.
Third-order effects
- If the pattern holds, the government's default path into encrypted devices moves from courtroom compulsion of vendors — the fight Apple won publicly — to quiet purchases of zero-day flaws outside any disclosure regime, eroding the patch-and-disclose model that keeps consumer devices secure.
- A procurement channel with no review, no vendor notification, and admitted seven-figure payouts points toward eventual regulatory scrutiny of how agencies buy and hoard hacking techniques, since the secrecy here was a deliberate choice, not a constraint.
The trend: Law enforcement is shifting from forcing vendors to unlock devices through the courts to quietly buying undisclosed vulnerabilities from hackers, keeping both the flaw and the method outside public disclosure.