Sign in

Opposition leaders among Apple users warned of possible iPhone compromise bid

Congress’s Shashi Tharoor, who is among those who have been alerted, said he would not want to assume that it is the Indian government

Updated on: Oct 31, 2023, 14:22:14 IST
Share
Share via
  • facebook
  • twitter
  • linkedin
  • whatsapp
Copy link
  • copy link

At least seven leaders from the Opposition Indian National Developmental Inclusive Alliance (INDIA) have received emails from Apple warning them that state-sponsored attackers were potentially remotely trying to compromise the iPhones associated with their IDs.

Congress leader Shashi Tharoor said it could be another government as well. (PTI)
Congress leader Shashi Tharoor said it could be another government as well. (PTI)

They are the Congress’s Shashi Tharoor, Pawan Khera and Supriya Shrinate, Shiv Sena’s Priyanka Chaturvedi, Trinamool Congress’s Mahua Moitra, Aam Aadmi Party’s Raghav Chadha, and Sitaram Yechury from Communist Party of India (Marxist). All India Majlis-E-Ittehadul Muslimeen’s Asaduddin Owaisi was also notified.

Online publication The Wire’s founding editor Siddharth Varadarajan, resident editor of Deccan Chronicle Sriram Karri, Hyderabad-based independent journalist Revathi Pogadadanda, and Observer Research Foundation’s Samir Saran also got the email.

Apple said it does not attribute the threat notifications to any specific state-sponsored attacker. “State-sponsored attackers are very well-funded and sophisticated, and their attacks evolve over time. Detecting such attacks relies on threat intelligence signals that are often imperfect and incomplete,” it said in a statement.

The statement added it is possible that some Apple threat notifications may be false alarms, or that some attacks are not detected. “We are unable to provide information about what causes us to issue threat notifications, as that may help state-sponsored attackers adapt their behaviour to evade detection in the future.”

Tharoor, Khera, Chaturvedi and Varadarajan told HT that they got the message and follow-up email between 11:30pm on Monday and 12:15am on Tuesday. Tharoor said he saw the email around 7am on Tuesday. On logging into his account on the Apple website, his account displayed a warning about potential compromise in red. “The email does not advise us to go public but I think it is important to go public as that is the best security we have.”

Tharoor said there was a pattern and called it a disgrace that taxpayers’ money was being wasted this way. “There are more genuine threats to national security than opposition leaders,” he said. Tharoor added that he would not want to assume that it is the Indian government. “It could be another government as well,” he said.

Khera said he received a text message from Apple on Monday at 11:47pm but he saw the message on Tuesday morning. When HT contacted him, he had not yet checked his email about this.

Chaturvedi said she got a message followed by an email from Apple. “... they gave us some dos and don’ts to safeguard ourselves and to reach out to Apple through this 24X7 helpline website to safeguard ourselves and our identity. They expressed concerns that this is a very serious issue that should not be taken lightly.”

She added she verified it through some cyber law experts on Monday and they confirmed that it was a genuine message. “I do intend to write to the Prime Minister [Narendra Modi] and home minister [Amit Shah] as well as the IT minister...[Ashwini Vaishnaw] to resolve this because the Opposition cannot function in a space where state-sponsored attacks are happening and are being monitored and surveilled all the time,” she said.

“Every single person who is now calling me, I am asking them to tweet Amit Shah ji. You can also say good morning to Amit Shah ji since he is listening in.”

The alerts from Apple came to light a year after a committee of Supreme Court-appointed experts found inconclusive evidence of the presence of Pegasus spyware in the 29 phones it analysed. The panel said the government did not cooperate with its probe while recommending new laws and measures to protect citizens from illegal surveillance and cyber attacks.

The panel found some malware in five of the phones but there was nothing conclusive to show it was Pegasus.

The Raveendran committee set up by the top court analysed devices after it was mandated to determine whether the Pegasus spyware was used on phones or other devices to access stored data, eavesdrop on conversations, intercept information, etc.

The panel’s mandate also included determining details of those targeted with the spyware, the actions taken following the alleged illegal infiltration, whether the government acquired Pegasus to spy on Indian citizens, and if it did, under what rule or guideline.

The findings of the panel were based on “sophisticated tests” conducted on the devices people voluntarily turned in. Among the tools used was one made by Amnesty International, which was among the organisations that examined Pegasus infections, and the programme was also used in other countries for forensic analysis.

In July 2021, a consortium of media outlets and investigative journalists reported that the phones of Indian ministers, politicians, activists, businessmen, and journalists were among the 50,000 selected for infection with the Pegasus malware.

  • Aditi Agrawal
    ABOUT THE AUTHOR
    Aditi Agrawal

    Aditi covers technology policy, online free speech, privacy, cybersecurity, and surveillance.

Get the latest India News, breaking headlines and real-time updates from across the country. Stay informed about politics, government policies, crime, weather and major national developments.