FBI paid over $1.3M to break into San Bernardino iPhone, the most the FBI has admitted to paying for a hacking technique
FBI paid more than $1.3 million to break into San Bernardino iPhone — Federal Bureau of Investigation Director James Comey said on Thursday the agency paid …
Context & Ripple Effects
The San Bernardino saga has been a month-long whodunit: sources first credited Israel's Cellebrite with the crack, then walked that back when reporting showed the FBI instead paid hackers for an undisclosed software flaw used to build PIN-cracking hardware. Comey's disclosure puts a public price tag on that purchase — the most the FBI has ever admitted paying for a hacking technique — though follow-up reporting pegged the technique itself at under $1M, implying much of the total went elsewhere.
Two days after this story, the FBI confirmed it would not send the method through a government review that could have forced disclosure to Apple, keeping the flaw private. Four years later, FOIA records show law enforcement agencies in over 11 states had spent $4M+ on phone-breaking tools — evidence the one-off San Bernardino buy became a procurement category.
First-order effects
- The FBI now owns a reusable unlock capability rather than a one-time result: per the related reporting, the technique works on any iPhone 5c running iOS 9 without additional payment, so the $1.3M buys repeat access, not a single phone.
Second-order effects
- Because the FBI kept the method out of the government equities review, Apple never learns the underlying flaw and cannot patch it — leaving iOS 9 devices exposed while the FBI retains exclusive use.
- Gray-market exploit sellers gain proof of a seven-figure US government buyer, strengthening the case for vendors like Cellebrite to keep selling unlock capabilities to agencies rather than disclosing flaws to manufacturers.
Third-order effects
- Phone-cracking shifts from extraordinary legal battles with device makers to routine line-item procurement — the 2020 FOIA data showing $4M+ across 11 states suggests every mid-sized agency can now budget for access without involving Apple or the courts.
- A standing government market for undisclosed vulnerabilities hardens around secrecy incentives: agencies that pay for flaws have little reason to route them through review processes that end in patches.
The trend: Law enforcement is institutionalizing smartphone-exploit purchasing as standard equipment budgets, replacing headline court confrontations with quiet, recurring tool acquisitions.