Suspected spyware attacks target Turkish ministers’ phones
Apple sent notifications to phones belonging to at least three Turkish ministers warning that they may have been targeted in mercenary spyware attacks, sources familiar with the matter told Middle East Eye.
Last month, the technology company alerted an unspecified number of iPhone users in 110 countries, including Turkey, that they may have been targeted. MEE understands that the ministers were notified as part of the same batch.
The alerts are not surprising, as senior Turkish officials were previously targeted in suspected attacks involving the Israeli-made Pegasus spyware in 2021.
That same year, Forbidden Stories, a Paris-based nonprofit working with 16 media organisations, revealed that government clients had selected more than 50,000 phone numbers as potential hacking targets since 2016.
It is not immediately clear what type of spyware was used in this year’s attack, as several companies offer similar surveillance tools.
New MEE newsletter: Jerusalem Dispatch
Sign up to get the latest insights and analysis on Israel-Palestine, alongside Turkey Unpacked and other MEE newsletters
A Turkish official told MEE that authorities believe the attempts to hack the ministers’ phones were unsuccessful. The official declined to reveal the identities of the ministers.
The ministers had been using phones with enhanced security measures and specially encrypted applications to protect sensitive information, the official said.
Following Apple’s notification, Turkey’s newly established Presidency of Cyber Security examined the phones, replaced them and implemented additional safeguards, the official added.
Attempts to hack ministers, politicians, businesspeople and other prominent figures have become common in the region, according to the official. As a result, officials generally behave as though they could be targeted at any time.
“A specific reason isn’t needed for these attacks, and we all have to be vigilant,” the official said.
Experts say there are several ways to make phones more secure. In 2021, for example, Turkish officials replaced their phones and changed their phone numbers to sever any possible connection with mercenary spyware.
Apple also offers a special security feature known as Lockdown Mode, which is designed to protect users against highly sophisticated attacks, including so-called zero-click exploits. Such attacks can compromise a smartphone without requiring the user to click a link or take any other action.
Pegasus famously exploited a vulnerability in iMessage to gain access to data stored on smartphones.
Sources in Ankara speculate that a wide range of political and economic interest groups could be behind the latest attacks, although identifying those responsible is extremely difficult. Many suspect countries such as Israel and Greece, but Pegasus has also been sold to numerous governments across the region.
Updating an iPhone’s iOS operating system can erase potential evidence of an attack. Any remaining traces may point only to an IP address associated with a particular country, which does not necessarily reveal the attack’s true origin.
Middle East Eye delivers independent and unrivalled coverage and analysis of the Middle East, North Africa and beyond. To learn more about republishing this content and the associated fees, please fill out this form. More about MEE can be found here.