Suspected spyware attacks target Turkish ministers’ phones

Sources with direct knowledge of the incident have confirmed to Middle East Eye that technology giant Apple has pushed threat notifications to the personal and official iPhones of at least three senior Turkish government ministers, warning that the devices could be in the crosshairs of mercenary spyware operators.

This latest round of alerts forms part of a broader global warning Apple issued last month, which reached an undisclosed number of iPhone users across 110 countries, with Turkey included among the affected regions. Multiple industry and government sources confirm the Turkish ministers’ notifications were part of this global batch of warnings.

Cybersecurity observers have not flagged this development as unexpected: in 2021, multiple senior Turkish public officials were already identified as targets of suspected surveillance campaigns using Pegasus, the controversial spyware developed by Israeli cybersecurity firm NSO Group. That same year, Paris-based nonprofit journalism collective Forbidden Stories, in partnership with 16 global media organizations, published a groundbreaking investigation exposing that government clients of mercenary spyware firms had flagged more than 50,000 phone numbers across the globe as potential hacking targets starting from 2016.

At this stage, investigators have not been able to confirm what strain of spyware was used in the 2024 attempted attacks, as a growing number of private surveillance companies now offer capabilities comparable to Pegasus for government clients.

Despite the confirmed targeting attempts, a senior Turkish official speaking to Middle East Eye on condition of anonymity emphasized that the hacking attempts were ultimately unsuccessful. The official also declined to disclose the identities of the three ministers impacted by the attempted surveillance.

The official explained that the ministers targeted in this campaign had long used devices pre-equipped with enhanced security protocols, alongside purpose-built encrypted communication applications designed to safeguard sensitive government information. Immediately following Apple’s official alert, Turkey’s newly created Presidency of Cyber Security launched a full forensic review of the ministers’ devices, replaced the compromised hardware, and rolled out additional layered security safeguards to block future threats, the official added.

The official noted that sustained attempts to infiltrate the devices of politicians, ministers, prominent business leaders and other high-profile public figures have become a routine threat across the Middle East region. As a result, senior Turkish officials now operate under the persistent assumption that they may be targeted at any time. “There does not need to be a specific trigger for these attacks. We all have a responsibility to remain constantly vigilant,” the official stated.

Cybersecurity experts have outlined a range of measures that public officials can adopt to harden their devices against surveillance. Back in 2021, for example, Turkish officials swapped out all their personal and official devices and changed their private phone numbers to eliminate any potential foothold that mercenary spyware could have exploited.

For its part, Apple offers a specialized high-security tool called Lockdown Mode, built specifically to defend users against extremely sophisticated cyber attacks, including the category of threats known as zero-click exploits. These attacks are capable of compromising a smartphone without requiring any action from the user, such as clicking a malicious link, to trigger the breach. Pegasus, infamously, exploited an unpatched vulnerability in Apple’s iMessage platform to gain full access to all data stored on target iPhones.

While sources based in Ankara say that a broad array of domestic and international political and economic interest groups could be behind the latest attempted attacks, definitively tracing the origin of these surveillance campaigns remains an enormous challenge. Many local analysts have pointed fingers at countries including Israel and Greece as potential actors, but it is important to note that Pegasus has been sold to dozens of national governments across the Middle East and broader region.

Complicating attribution efforts further, updating an iPhone’s iOS operating system can often erase residual forensic evidence of an attack. Even when traces of a breach remain, they often only lead investigators to an IP address tied to a specific country, which does not confirm the true origin or sponsor of the attack, as malicious actors frequently route their activity through third-party servers to cover their tracks.