Skip to main content

Mercenary Spyware and Device Forensics for UK Journalists

Pegasus and Predator are not ordinary malware, and the ordinary advice does not apply to them. This guide explains how they reach a device, what a forensic examination can and cannot prove, which protections have published evidence behind them, and who a UK journalist should actually call.

General guidance, not a forensic service. If you believe you have been targeted, do not attempt to clean or factory-reset the device — that destroys the evidence. Contact the Access Now Digital Security Helpline, which is free and operates 24/7.

Last reviewed: Next review due:

What mercenary spyware is, in plain English

‘Mercenary spyware’ describes surveillance software built by private companies and sold to state clients. Pegasus, made by NSO Group, is the best-documented example; Predator, sold by the Intellexa alliance, is the other name a journalist is most likely to encounter. Once installed, this class of software gains total access to the device: messages, photographs, location, and the microphone and camera. Amnesty International describes Predator as being operated through a web console that Intellexa calls the Cyber Operation Platform.

The reason it is treated as a distinct category is the delivery method. The Pegasus Project — a collaboration of more than 80 journalists from 17 media organisations in 10 countries, coordinated by Forbidden Stories with forensic support from Amnesty’s Security Lab — was based on a leak of 50,000 phone numbers of potential surveillance targets, and identified at least 180 journalists in 20 countries selected for potential targeting. Predator has been delivered by network injection installed at mobile operators or ISPs, silently redirecting a target to an infection server when they browse any plain-HTTP page.

Why the usual advice does not cover this

Most digital-security training is built around not clicking things. Zero-click attacks require no interaction from the target at all: Amnesty documented Pegasus delivered to a fully patched iPhone 12 running iOS 14.6, and Citizen Lab found NSO customers widely deploying at least three separate iOS 15 and iOS 16 zero-click exploit chains in 2022. Good link hygiene remains worth having — it defeats the far more common threats — but it is not a defence here.

What forensics can and cannot prove

This is the part most coverage gets wrong, and getting it wrong in either direction is harmful. Amnesty’s Mobile Verification Toolkit works by matching indicators of compromise, supplied in STIX2 format, against data extracted from a device. It is not antivirus. It does not run on a live phone, and it cannot find what no one has yet published an indicator for.

A positive result is strong evidence

Forensic attribution in this field is unusually rigorous. Citizen Lab’s findings on journalists hacked with Pegasus have been peer reviewed by Amnesty International’s Security Lab, putting two independent laboratories on the same evidence before publication.

A negative result is weak evidence

Amnesty states plainly that its tools cannot necessarily detect the newest spyware without non-public indicators, and MVT’s maintainers caution that public indicators alone are insufficient to conclude a device is clean. Predator is designed to leave no forensic traces at all.

The tooling is not built for you

MVT describes itself as a forensic research tool for technologists and investigators, explicitly not intended for end-user self-assessment. Running it yourself and finding nothing tells you very little, and may give false reassurance.

Preserve, do not clean

A factory reset destroys the forensic record. If you suspect compromise, the device itself is the evidence — stop using it for sensitive work, keep it, and get expert help rather than trying to fix it.

Protections with evidence behind them

Apple Lockdown Mode

An optional extreme protection for people who may be personally targeted by the most sophisticated threats. It blocks most Messages attachment types, restricts complex web technologies in Safari, blocks unsolicited FaceTime calls, refuses non-secure Wi-Fi networks and turns off 2G. It also prevents configuration profiles being installed and blocks Mobile Device Management enrolment, closing a known attacker route. Requires iOS 16 or later and must be enabled on each device separately. Citizen Lab found no evidence of successful PWNYOURHOME compromise against devices running it.

Apple threat notifications

Apple notifies users it believes have been individually targeted by mercenary spyware, and says it has notified users in over 150 countries since 2021. Verify any notification by signing in to account.apple.com, where it appears as a banner. A genuine one never asks you to click a link, install anything, or hand over a password or verification code.

Prompt updates

Unglamorous and genuinely effective. CPJ advises installing operating system, app and browser updates promptly, because old software carries the vulnerabilities that get exploited. Several documented exploit chains were closed by ordinary security updates.

Device separation

DCMS-commissioned research published in July 2026 recommends employers provide dedicated work phones so journalists do not use personal devices for work communication. For spyware specifically, separation limits what a single compromised device exposes.

Account hardening

NCSC’s baseline advice for high-risk individuals is two-step verification on all high-value accounts, passwords built from three random words, and prompt installation of security updates. Google’s Advanced Protection Program is the equivalent hardening route for Google accounts, and the Rory Peck Trust points freelancers to it.

The UK picture

The NCSC published a commercial cyber proliferation assessment on 19 April 2023 stating that commercial spyware has almost certainly been used by states to target journalists, at scale, with thousands of individuals targeted each year, and warning that hackers-for-hire increase the likelihood of unpredictable targeting and escalation. NCSC formally classes journalists as high-risk individuals in its Defending Democracy guidance, alongside politicians, academics and lawyers. On 9 April 2025 the NCSC and partner agencies from seven other nations published joint guidance for communities at high risk of digital surveillance.

The UK is not only a source of guidance but a documented target. Citizen Lab notified the UK Government of multiple suspected Pegasus infections on official UK networks in 2020 and 2021, including the Prime Minister’s Office and the Foreign and Commonwealth Office, with the suspected FCO infections linked to operators it associates with the UAE, India, Cyprus and Jordan.

The IPT ruling, December 2024

The Investigatory Powers Tribunal quashed a PSNI Directed Surveillance Authorisation used to monitor whether journalists Trevor Birney and Barry McCaffrey were meeting confidential sources, holding it incompatible with their Article 10 rights. It also quashed 2012 Metropolitan Police and 2013 PSNI authorisations covering their phone data, and awarded each journalist £4,000. The PSNI Chief Constable accepted the finding that no proper public-interest consideration was given before authorising surveillance touching journalistic sources.

Where journalistic material sits in statute

The Investigatory Powers Act 2016 defines journalistic material at section 264, which is the hook for the Act’s additional safeguards around confidential journalistic material. The Government has admitted that the pre-2016 regime, under which police accessed journalists’ call records to identify confidential sources, breached human rights law.

The UK as a litigation venue

The High Court in London granted journalist Rania Dridi permission to bring proceedings against the UAE over alleged Pegasus targeting, and in October 2024 allowed Yahya Assiri to serve a claim on Saudi Arabia alleging his devices were targeted with Pegasus and QuaDream spyware.

Where to raise safety concerns

The National Committee for the Safety of Journalists, established in 2020, is the UK’s cross-sector body on journalist safety and oversees the National Action Plan for the Safety of Journalists. The NUJ maintains a Safety Toolkit and Safety Tracker for members, though DCMS research found a gap in journalists’ awareness that these exist.

DCMS-commissioned research published on 24 July 2026, based on a final sample of 531 eligible journalist responses, found that 72% had experienced safety concerns, that 48% said this influenced their willingness to report certain stories, and that 79% nonetheless felt free or very free to carry out their work against 13% who felt restricted. The same research records UK journalists relying on international NGOs for device checks, with one respondent saying RSF helped check whether their phone had been hacked or placed under surveillance.

If you think you have been targeted

  • I have stopped using the device for sensitive work and for contact with confidential sources.
  • I have NOT factory-reset, wiped, or attempted to clean the device — that destroys the forensic evidence.
  • I have contacted the Access Now Digital Security Helpline, which is free, 24/7, and states it responds within two hours.
  • If I received an Apple threat notification, I verified it at account.apple.com rather than acting on the message itself.
  • I have told my editor or commissioning editor, and if I am a member, the NUJ.
  • I have moved source communication to a device the suspected compromise does not cover.
  • I have warned any source whose safety could be affected if my device history were readable.
  • I have considered whether the Investigatory Powers Tribunal is the right route, and taken legal advice before assuming it is not.

Work out whether this applies to you

Mercenary spyware is a beat-dependent threat, not a universal one. Threat modelling is how you tell the difference between a realistic risk and security theatre.

Threat Modelling for UK Journalists

Common mistakes

  • Treating a clean forensic scan as proof of safety — it means no known indicators were found, which is a much narrower claim.
  • Running MVT yourself and drawing conclusions from it, when its own maintainers say it is not built for end-user self-assessment.
  • Factory-resetting a suspected device, which destroys the only evidence that could establish what happened.
  • Acting on an ‘Apple threat notification’ that arrives by email or text without verifying it at account.apple.com — phishing exploits the real programme.
  • Assuming link hygiene protects against zero-click delivery. It does not, because there is nothing to click.
  • Enabling Lockdown Mode on the phone only, when it needs enabling on every Apple device on the same iCloud account.
  • Inflating the threat for every beat, which pushes colleagues towards impractical measures and away from the basics that protect most sources.

Related guides

Primary sources

Frequently asked questions

Can I check my own phone for Pegasus?
Realistically, no — and this is the single most common misconception about spyware. Amnesty International’s Mobile Verification Toolkit (MVT) is the best-known tool, but its own maintainers describe it as a forensic research tool for technologists and investigators that is not intended for end-user self-assessment. It does not scan a live phone the way antivirus software does; it works on a forensic extraction of the device and compares it against indicators of compromise supplied separately in STIX2 format. Without current, often non-public indicators, it cannot detect the newest spyware. Amnesty’s own advice to people who are worried is to have the device examined by reputable experts rather than attempting self-diagnosis.
If a forensic scan comes back clean, is my phone clean?
No, and it is important to be precise about this. Amnesty’s Security Lab warns that its tools cannot necessarily detect the newest spyware without non-public indicators, so a clean result is not proof that a phone was never compromised. The MVT project makes the same point: public indicators of compromise alone are insufficient to conclude that a device is clean. Predator, sold by the Intellexa alliance, is specifically designed to leave no forensic traces on the target device. A clean scan means ‘no known indicators were found’, which is a genuinely useful but much narrower statement than ‘you are not being surveilled’.
What is a zero-click attack?
A zero-click attack compromises a device without the target doing anything at all — no link to tap, no attachment to open, no mistake to make. Amnesty’s July 2021 Forensic Methodology Report documented Pegasus being delivered this way against a fully patched iPhone 12 running iOS 14.6. Citizen Lab later found that NSO Group customers widely deployed at least three separate iOS 15 and iOS 16 zero-click exploit chains during 2022. This matters for how journalists think about training: security advice built entirely around ‘do not click suspicious links’ does not address this threat, because there is nothing to click.
I received an Apple threat notification. Is it real?
Verify it before acting. Apple says a genuine threat notification can be confirmed by signing in to account.apple.com, where it appears as a banner at the top of the page. Critically, Apple states that a genuine notification will never ask you to click a link, open a file, install an app or profile, or provide an Apple Account password or verification code. Any message that does those things is a phishing attempt exploiting the existence of the notification programme. Apple describes the notifications as high-confidence alerts that should be taken very seriously, but will not explain what triggered any individual one.
Does Lockdown Mode actually work?
There is published forensic evidence that it has. Citizen Lab reported no evidence of successful compromise by one NSO exploit chain, which it named PWNYOURHOME, against devices running Apple’s Lockdown Mode, and observed that Lockdown Mode generated real-time warnings when the exploit was attempted. Apple presents it as an optional extreme protection for the small number of people who may be personally targeted by the most sophisticated digital threats, and is explicit that the device will not function as it usually does. It must be enabled separately on each device, and CPJ notes it should be turned on for every Apple device linked to the same iCloud account, not just the phone.
Is this a realistic threat for a UK journalist?
For most UK journalists on most beats, no — and inflating the risk is its own problem, because it pushes people towards impractical security theatre instead of the basics that actually protect sources. But it is not hypothetical either. The NCSC’s own published assessment states that commercial spyware has almost certainly been used by states to target journalists, at scale, with thousands of individuals targeted each year, and NCSC formally classes journalists as high-risk individuals. Citizen Lab notified the UK Government of suspected Pegasus infections on official UK networks in 2020 and 2021. The honest framing is that this is a beat-dependent threat: it concentrates on journalists covering foreign states, national security, and organised crime.
Who do I contact if I think I have been targeted?
Access Now’s Digital Security Helpline is the most widely recommended first call. It is free of charge, operates 24/7 in ten languages, and states that it responds to all requests within two hours. Apple explicitly directs users who receive its threat notifications there. Amnesty International’s Security Lab has offered a free forensic analysis service to at-risk journalists and civil society, but a notice dated 2 April 2025 said it had paused intake of new requests — check the current status before relying on that route. UK freelancers should also know the Rory Peck Trust, which publishes a Digital Security Guide and runs a Crisis Fund.
Can a UK journalist challenge state surveillance in court?
Yes. The Investigatory Powers Tribunal is the UK forum for complaints about surveillance by public authorities, and it has found for journalists. In December 2024 the IPT quashed a PSNI Directed Surveillance Authorisation used to monitor whether journalists Trevor Birney and Barry McCaffrey were meeting confidential sources, holding it incompatible with their rights under Article 10 of the European Convention on Human Rights. It also quashed 2012 Metropolitan Police and 2013 PSNI authorisations relating to their phone data, and awarded each journalist £4,000 in damages. Separately, the UK High Court has become a venue for spyware litigation against foreign states.