Bitget App
Trade smarter
Buy cryptoMarketsTradeFuturesEarnSquareMore
Apple notifies exploit creator that their iPhone was attacked using state-sponsored spyware

Apple notifies exploit creator that their iPhone was attacked using state-sponsored spyware

Bitget-RWA2025/10/21 16:03
By:Bitget-RWA

Earlier this year, a developer was stunned when a notification appeared on his personal device: “Apple has identified a mercenary spyware attack targeting your iPhone.”  

“I started to panic,” said Jay Gibson, who requested anonymity due to concerns about possible repercussions, in a conversation with TechCrunch.  

Gibson, who until recently developed surveillance tools for the Western government hacking contractor Trenchant, may be the first known instance of a spyware and exploit creator becoming a target of such attacks themselves. 

“What is happening? I honestly had no idea how to process it,” Gibson recalled, explaining that he immediately powered down his phone and set it aside on March 5. “I went out and bought a replacement right away. I called my father. Everything was chaotic. It was a total disaster.”  

While at Trenchant, Gibson’s work involved discovering iOS zero-day vulnerabilities and crafting tools to exploit them—flaws that remain unknown to the manufacturer, such as Apple, of the affected devices or software.  

“I’m torn between feeling this is just sad and being extremely frightened, because once things escalate to this point, there’s no telling what could come next,” he told TechCrunch.  

However, Gibson may not be the only exploit engineer who has been targeted. Three individuals familiar with these incidents told TechCrunch that other spyware and exploit developers have also received Apple notifications in recent months, warning them of spyware targeting. 

Apple did not reply to TechCrunch’s request for comment. 

The attack on Gibson’s iPhone highlights how the spread of zero-day exploits and spyware is beginning to affect a broader range of individuals.  

Makers of spyware and zero-days have long insisted their products are used solely by authorized government clients against criminals or terrorists. Yet, over the last ten years, researchers from Citizen Lab at the University of Toronto, Amnesty International, and other groups have documented numerous cases in which governments used these tools to surveil activists, journalists, human rights advocates, and political opponents worldwide.   

The most comparable public incidents of hackers targeting security researchers occurred in 2021 and 2023, when North Korean state hackers were found to be going after vulnerability researchers. 

Suspect in leak investigation 

Two days after receiving Apple’s warning, Gibson reached out to a forensic specialist with significant experience in spyware investigations. The expert’s preliminary review of Gibson’s phone found no evidence of compromise, but still advised a more thorough forensic examination of the device.  

A comprehensive forensic review would have required Gibson to send a full backup of his device to the expert, something he was unwilling to do.  

“Lately, forensic investigations are getting more challenging, and sometimes we find nothing. It’s possible the attack didn’t fully proceed after the initial stage, but we can’t be sure,” the expert told TechCrunch. 

Without a complete forensic analysis—ideally one that uncovers traces of the spyware and its creator—it remains unclear why Gibson was targeted or who was behind it.  

Still, Gibson told TechCrunch he suspects the Apple alert is linked to the circumstances surrounding his exit from Trenchant, where he claims he was blamed for a damaging internal leak.  

Apple issues threat notifications when it has credible evidence that an individual has been targeted by mercenary spyware. Such surveillance tools are often secretly and remotely installed on a victim’s device by exploiting software vulnerabilities, which can be extremely valuable and take months to create. Typically, only law enforcement or intelligence agencies have the legal authority to use spyware, not the companies that develop it. 

Sara Banda, a representative for Trenchant’s parent company L3Harris, declined to comment when contacted by TechCrunch prior to publication.  

Roughly a month before receiving Apple’s notification, while still employed at Trenchant, Gibson said he was invited to the company’s London office for a team-building gathering.  

Upon arriving on February 3, Gibson was promptly called into a meeting room for a video conference with Peter Williams, then Trenchant’s general manager, known internally as “Doogie.” (In 2018, defense contractor L3Harris acquired Azimuth and Linchpin Labs, two zero-day startups that merged to form Trenchant.) 

Williams informed Gibson that the company suspected him of holding a second job and was therefore suspending him. All of Gibson’s work-related devices would be seized and examined as part of an internal probe into these claims. Williams could not be reached for comment. 

“I was stunned. I didn’t know how to respond because I couldn’t quite believe what I was hearing,” Gibson said, adding that a Trenchant IT staffer later went to his home to collect his company equipment.  

About two weeks later, Gibson said Williams called to inform him that, following the investigation, the company was terminating his employment and offering a settlement and payment. Gibson said Williams refused to disclose what the forensic review of his devices had revealed, and essentially told him he had no option but to accept the agreement and leave. 

Feeling he had little choice, Gibson said he agreed and signed the documents.  

Gibson told TechCrunch that he later heard from ex-colleagues that Trenchant believed he had leaked undisclosed vulnerabilities in Google’s Chrome browser—tools developed by Trenchant. However, Gibson and three former coworkers told TechCrunch he never had access to the company’s Chrome zero-days, as he was solely part of the iOS zero-day and spyware development team. According to them, Trenchant teams only have access to tools relevant to their specific platform.  

“I know I was made a scapegoat. I wasn’t at fault. It’s that straightforward,” Gibson said. “All I did was work hard for them.”  

Three former Trenchant staffers with direct knowledge independently confirmed the events surrounding Gibson’s suspension and dismissal.  

Two of these ex-employees said they were aware of the details of Gibson’s trip to London and the suspicions regarding leaks of sensitive company tools. 

All requested anonymity but believe Trenchant’s conclusion was mistaken. 

0
0

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.

PoolX: Earn new token airdrops
Lock your assets and earn 10%+ APR
Lock now!

You may also like

COAI Token Fraud: Insights for Cryptocurrency Investors During Times of Regulatory Ambiguity

- COAI token's 88% collapse in late 2025 exposed systemic risks in AI-driven DeFi ecosystems, with $116.8M investor losses. - Governance flaws included 87.9% token concentration in ten wallets, untested AI stablecoins, and lack of open-source audits. - Panic selling accelerated by AI-generated misinformation and CEO resignation, amid conflicting global crypto regulations. - Lessons emphasize scrutinizing token distribution, demanding transparent audits, and avoiding jurisdictions with regulatory ambiguity.

Bitget-RWA2025/12/14 06:00
COAI Token Fraud: Insights for Cryptocurrency Investors During Times of Regulatory Ambiguity

Renewable Energy Training as a Key Investment to Meet Future Workforce Needs

- Farmingdale State College's Wind Turbine Technology program aligns with surging demand for skilled labor in decarbonizing economies, driven by U.S. renewable energy targets. - Industry partnerships with Orsted, GE Renewable Energy, and $500K in offshore wind funding validate the program's role in addressing workforce shortages in expanding wind sectors. - Hands-on training with GWO certifications and VR simulations prepares graduates for high-demand, high-salary roles ($56K-$67K annually), reducing corpo

Bitget-RWA2025/12/14 06:00
Renewable Energy Training as a Key Investment to Meet Future Workforce Needs

The Revival of STEM Learning as a Driving Force for Tomorrow’s Technology Investments

- Emerging STEM universities are driving tech innovation through interdisciplinary curricula and industry partnerships, focusing on AI, biotech , and advanced manufacturing. - U.S. programs like STEM Talent Challenge and NSF Future Manufacturing allocate $500K-$25.5M to bridge skills gaps and fund projects in quantum tech and biomanufacturing. - Leadership-focused STEM programs at institutions like Florida State and Purdue boost startup success rates (75-80%) and align with venture capital trends favoring

Bitget-RWA2025/12/14 05:28
The Revival of STEM Learning as a Driving Force for Tomorrow’s Technology Investments

Assessing KITE’s Price Prospects After Listing as Institutional Interest Rises

- Kite Realty Group (KRG) reported Q3 2025 earnings below forecasts but raised 2025 guidance, citing 5.2% ABR growth and 1.2M sq ft lease additions. - Institutional investors showed mixed activity, with Land & Buildings liquidating a 3.6% stake while others increased holdings, reflecting valuation debates. - Technical indicators suggest bullish momentum (price above 50/200-day averages) but a 23.1% undervaluation vs. 35.1x P/E, exceeding sector averages. - KRG lags peers like Simon Property in dividend yie

Bitget-RWA2025/12/14 05:08
Assessing KITE’s Price Prospects After Listing as Institutional Interest Rises
© 2025 Bitget