Apple plans to notify targets of state-sponsored spyware attacks like NSO's ForcedEntry and commits $10M to cybersurveillance researchers and advocates
this is a good day to celebrate the formidable impact of @RonDeibert @jsrailton & the @citizenlab research team, systematically exposing human rights abuses and holding the industry accountable https://twitter.com/... Edward Snowden / @snowden : Software giants who have seen the commercial malware targeting their users should look at this as a template for imposing consequences on this predatory industry. The “business” of human-rights-violations-as-a- service must be stamped out—before it grows. https://www.apple.com/... https://twitter.com/... Dennis / @dennisf : This is the OPENING LINE of @apple's suit against NSO: “Defendants are notorious hackers—amoral 21st century mercenaries who have created highly sophisticated cyber-surveillance machinery that invites routine and flagrant abuse.” John Scott-Railton / @jsrailton : 11/ It would take a huge internal effort for a massive company to undertake any one of these: ✔Lawsuit ✔Victim Notification ✔Attribution ✔Civil society support. @apple did it all at once. There are unsung heroes in this story. Complaint: https://www.apple.com/... Runa Sandvik / @runasand : @Laughing_Mantis @juanandres_gs I'd love to see this happen. Profdeibert / @rondeibert : Apple commends the work of @AmnestyTech and @citizenlab, and notes that our disclosure of FORCEDENTRY (in this report https://citizenlab.ca/...) was critical to hunting down NSO's abuses of their infrastructure. https://twitter.com/... John Scott-Railton / @jsrailton : 8/ I see @Apple's lawsuit as partly triggered by findings & efforts of so many of our @citizenlab peers: E.g. @AmnestyTech @accessnow @RSF_inter @EFF @pressfreedom @R3Dmx @article19org & many more. Most importantly though: the victims that bravely came forwards. Here's why... Greg Linares / @laughing_mantis : @juanandres_gs How about blue teams who manage large amounts of assets with high levels of risk from state-sponsored and similar attacks? Would be absolutely great to get a direct line from Apple for threats similar to what Microsoft has had for years Runa Sandvik / @runasand : Great to see Apple recognize all the NSO research by @citizenlab and @AmnestyTech with words, funding, and collaboration. 🍎⚒️ https://www.apple.com/... Tavis Ormandy / @taviso : @runasand ... Apple always use the same strategy when security research is involved: “Promise everything, deliver nothing”. Chris Vickery / @vickerysec : @KimZetter I want to see a concrete list of identified individuals who were employed at and by NSO as a result of this suit (if Apple succeeds). Those individuals should not be allowed to simply set up shop under different company names or continue this kind of work elsewhere. John Scott-Railton / @jsrailton : 9/ The FORCEDENTRY zero-click exploit is prominently mentioned @apple's lawsuit. It was discovered when a spyware victim let us check their phone. This is as it should be: targets of dictatorial surveillance contributing to fighting back & helping protect us all. https://twitter.com/... @rasha_abdul : 🚨 HUGE news (again) - @Apple sues NSO Group to curb the abuse of state-sponsored spyware and announces a $10 million contribution to support cybersurveillance researchers and advocates. Cites the work of @AmnestyTech & @citizenlab 🙏🏽https://www.businessw ire.com/ ... #PegasusProject https://twitter.com/... Kim Zetter / @kimzetter : Never seen anything like this. Apple sues Israeli spy firm NSO Group for hacking Apple devices. “seeks to ban NSO...from further harming individuals by using Apple's products....also seeks redress for...flagrant violations of US federal and state law” https://www.apple.com/... Arvind Gunasekar / @arvindgunasekar : Apple sues NSO Group (Pegasus) to curb the abuse of state-sponsored spyware. “Apple is notifying the small number of users that it discovered may have been targeted by FORCEDENTRY” https://www.apple.com/... @marwasf : HUGE news! Apple today filed a lawsuit against NSO Group and its parent company to hold it accountable for the surveillance and targeting of Apple users with its Pegasus spyware. https://www.apple.com/...
Context & Ripple Effects
Apple had already shipped security updates for flaws that bypassed Blastdoor protections. It is now pairing technical remediation with target notification and a $10 million commitment for the researchers and advocates who investigate cybersurveillance.
The measures arrive alongside Apple's federal lawsuit seeking to bar NSO Group from its products, making the response broader than a software fix alone: it addresses affected users, alleged vendor access, and the investigative ecosystem.
First-order effects
- People Apple believes were targeted by FORCEDENTRY or similar state-sponsored spyware are set to receive notifications from Apple.
- Cybersurveillance researchers and advocates gain a $10 million funding commitment, including work associated with Citizen Lab's exposure of abuse.
Second-order effects
- Apple's notification program and its NSO litigation apply separate pressure to alleged spyware operations: targets are alerted while Apple seeks to restrict NSO's use of its products.
- Funding independent researchers and advocates strengthens the groups that identify spyware campaigns and connect technical findings to human-rights accountability.
Third-order effects
- Apple's response points to a broader vendor playbook in which patching is supplemented by victim notification, legal action, and support for outside investigators.
- If sustained, that model makes the commercial-spyware market more dependent on staying hidden from both platform security teams and independent research organizations.
The trend: Commercial-spyware defense is expanding from closing exploits to disrupting the ecosystem around their discovery, disclosure, and use.