Sources: FBI paid under $1M to unlock San Bernardino iPhone, can use technique on any iPhone 5c running iOS 9 without additional payment
FBI paid under $1 million to unlock San Bernardino iPhone: sources — The FBI paid under $1 million for the technique used to unlock the iPhone used …
Context & Ripple Effects
The attribution on this case has whipsawed in a month: first the FBI was reported to be working with Israel's Cellebrite, then sources said it actually bypassed Cellebrite and paid hackers for an undisclosed software flaw, and last week the price tag came out at over $1.3 million. Today's Reuters sourcing tightens both numbers and scope: under $1 million, for a method reusable on any iPhone 5c running iOS 9.
That reusability is the pivot — the FBI bought a repeatable capability, not a one-off key to a single device — and it lands one day after the FBI confirmed it won't send the method to the government review that could have forced it to share details with Apple.
First-order effects
- Every iPhone 5c still running iOS 9 is now exposed to a method the FBI can deploy repeatedly at no additional cost, while Apple remains locked out of knowing the flaw because the agency skipped the interagency review.
- The revised sub-$1M figure corrects the earlier $1.3M estimate and sets a concrete benchmark for what a reusable phone-unlock exploit costs a federal buyer.
Second-order effects
- Whoever sold the technique retains a durable asset — a hardware-assisted PIN crack that works across a whole model-and-OS population — which can be resold to other agencies or governments, turning the one-time hack into a product line.
- Apple's countermeasures narrow to software: patching iOS 9 for remaining 5c users is its only lever, since the FBI's refusal of the review forecloses the disclosure route that would otherwise surface the flaw.
Third-order effects
- If agencies keep buying exploits while opting out of the kind of government review described in the coverage, disclosure becomes optional for law enforcement and phone makers lose their early-warning channel on which devices are already open.
- Older handsets drift toward structural insecurity as priced, model-specific unlock methods accumulate per OS version — security decaying by device age rather than by vendor intent.
The trend: Law enforcement is assembling a paid gray-market pipeline for phone-unlock exploits, trading vendor transparency and formal review for reusable offensive capabilities.