iVerify says it found the first evidence of an active spyware campaign targeting iPhones in the US and the EU; Apple fixed a flaw, but says it wasn't exploited
Researchers published new findings that they fear could be the first evidence of an active spyware campaign targeting iPhones in the U.S. and the European Union.
Context & Ripple Effects
The report follows iVerify's earlier detection of Pegasus infections in 11 additional cases, including cases where users had not received Apple threat notifications. That left a gap between platform-level warnings and endpoint evidence.
Apple has previously warned people in dozens of countries about suspected mercenary-spyware targeting. The new claim extends scrutiny to alleged activity affecting iPhone users in the U.S. and EU, while Apple disputes that the newly patched flaw was exploited.
First-order effects
- Apple has patched the iPhone vulnerability, while its statement that it was not exploited directly challenges iVerify's attribution of an active campaign to that flaw.
- iVerify's findings put potentially targeted iPhone users and organizations on notice that Apple threat notifications may not be the only signal worth monitoring.
Second-order effects
- The disagreement raises the evidentiary bar for mobile-security vendors: they will need to distinguish observed compromise indicators from proof that a particular vulnerability was used.
- Organizations protecting high-risk users may place more weight on device-level monitoring alongside Apple's notifications, creating pressure for clearer incident-validation and disclosure practices.
Third-order effects
- If recurring detections continue to surface outside platform warning channels, mobile defense will shift toward a layered model in which OS vendors, researchers, and endpoint tools provide complementary—and sometimes conflicting—evidence.
- The episode underscores how commercial spyware turns mobile vulnerability disclosure into a trust question: fast patches matter, but confidence also depends on credible visibility into whether exploitation occurred.
The trend: This is one data point in the widening use of independent mobile telemetry to test—and sometimes challenge—platform providers' visibility into mercenary spyware.