How iPhone users clicking on a malicious Twitter link forced their phones to dial 911, overwhelming 911 call centers in atleast a dozen US states last October
Ryan Knutson / Wall Street Journal :
Context & Ripple Effects
The Wall Street Journal's reporting traced last October's wave of phantom 911 calls to a single malicious Twitter link: tapping it triggered code that forced iPhones to repeatedly dial emergency services, swamping call centers across at least a dozen states. Weeks later, Apple shipped iOS 10.3 with a fix for the vulnerability, closing the specific hole but leaving the underlying exposure visible.
What makes the incident worth revisiting is that it was an early instance of a problem that did not go away: by 2023, emergency operators were reporting inundation from false calls auto-placed by Apple Watches and iPhone 14s worn by skiers and other fitness enthusiasts — no attacker required.
First-order effects
- 911 call centers in at least a dozen US states absorbed a flood of automated dials originating from ordinary consumers' iPhones, degrading their ability to answer genuine emergencies.
- Apple had to respond with a software patch rather than a security advisory alone — the fix landed in iOS 10.3, making every un-updated iPhone a potential node in the attack.
Second-order effects
- The episode turned social platforms' link distribution into a measurable public-safety attack surface: a single tweet functioned as a denial-of-service weapon against emergency infrastructure, raising the stakes for how quickly platforms and device makers coordinate on takedowns and patches.
- Emergency-call systems built on the assumption that callers are humans making deliberate choices were forced to confront machine-originated call volume, whether malicious (the Twitter link) or accidental (later wearable auto-dials).
Third-order effects
- If the pattern holds, emergency infrastructure will need technical means to distinguish and throttle automated or spoofed calls — a shift from treating every dial as a person in distress toward verifying caller intent.
- Consumer devices sitting on top of safety-critical systems become a systemic liability: one OS bug or one misfiring sensor feature can scale instantly into a multi-state disruption, pushing regulators and carriers to treat handset software as critical infrastructure.
The trend: Emergency-response systems are being overwhelmed less by attackers directly than by the devices in people's pockets and on their wrists — maliciously in 2017, accidentally by 2023 — forcing 911 infrastructure to adapt to machine-generated call volume.