Brokers with the Federal Bureau of Investigation (FBI) briefed Capitol Hill employees just lately on hardening the safety of their cell units, after a contacts checklist stolen from the private telephone of the White Home Chief of Employees Susie Wiles was reportedly used to gas a collection of textual content messages and telephone calls impersonating her to U.S. lawmakers. However in a letter this week to the FBI, one of many Senate’s most tech-savvy lawmakers says the feds aren’t doing sufficient to advocate extra acceptable safety protections which might be already constructed into most client cell units.

A screenshot of the primary web page from Sen. Wyden’s letter to FBI Director Kash Patel.
On Might 29, The Wall Avenue Journal reported that federal authorities have been investigating a clandestine effort to impersonate Ms. Wiles by way of textual content messages and in telephone calls which will have used AI to spoof her voice. In response to The Journal, Wiles informed associates her cellphone contacts have been hacked, giving the impersonator entry to the personal telephone numbers of a number of the nation’s most influential folks.
The execution of this phishing and impersonation marketing campaign — no matter its targets might have been — advised the attackers have been financially motivated, and never notably subtle.
“It grew to become clear to a number of the lawmakers that the requests have been suspicious when the impersonator started asking questions on Trump that Wiles ought to have recognized the solutions to—and in a single case, when the impersonator requested for a money switch, a number of the folks mentioned,” the Journal wrote. “In lots of instances, the impersonator’s grammar was damaged and the messages have been extra formal than the way in which Wiles sometimes communicates, individuals who have obtained the messages mentioned. The calls and textual content messages additionally didn’t come from Wiles’s telephone quantity.”
Refined or not, the impersonation marketing campaign was quickly punctuated by the homicide of Minnesota Home of Representatives Speaker Emerita Melissa Hortman and her husband, and the taking pictures of Minnesota State Senator John Hoffman and his spouse. So when FBI brokers supplied in mid-June to transient U.S. Senate employees on cell threats, greater than 140 staffers took them up on that invitation (a remarkably excessive quantity contemplating that no meals was supplied on the occasion).
However in accordance with Sen. Ron Wyden (D-Ore.), the recommendation the FBI supplied to Senate staffers was largely restricted to remedial suggestions, corresponding to not clicking on suspicious hyperlinks or attachments, not utilizing public wifi networks, turning off bluetooth, protecting telephone software program updated, and rebooting commonly.
“That is inadequate to guard Senate workers and different high-value targets towards overseas spies utilizing superior cyber instruments,” Wyden wrote in a letter despatched at the moment to FBI Director Kash Patel. “Nicely-funded overseas intelligence businesses would not have to depend on phishing messages and malicious attachments to contaminate unsuspecting victims with spy ware. Cyber mercenary corporations promote their authorities clients superior ‘zero-click’ capabilities to ship spy ware that don’t require any motion by the sufferer.”
Wyden careworn that to assist counter subtle assaults, the FBI must be encouraging lawmakers and their employees to allow anti-spyware defenses which might be constructed into Apple’s iOS and Google’s Android telephone software program.
These embrace Apple’s Lockdown Mode, which is designed for customers who’re nervous they could be topic to focused assaults. Lockdown Mode restricts non-essential iOS options to cut back the system’s total assault floor. Google Android units carry the same function referred to as Advanced Protection Mode.
Wyden additionally urged the FBI to replace its coaching to advocate quite a lot of different steps that individuals can take to make their cell units much less trackable, together with using advert blockers to protect towards malicious ads, disabling ad tracking IDs in mobile devices, and opting out of business knowledge brokers (the suspect charged within the Minnesota shootings reportedly used multiple people-search services to search out the house addresses of his targets).
The senator’s letter notes that whereas the FBI has really useful all the above precautions in varied advisories issued over time, the recommendation the company is giving now to the nation’s leaders must be extra complete, actionable and pressing.
“Regardless of the seriousness of the risk, the FBI has but to offer efficient defensive steerage,” Wyden mentioned.
Nicholas Weaver is a researcher with the Worldwide Laptop Science Institute, a nonprofit in Berkeley, Calif. Weaver mentioned Lockdown Mode or Superior Safety will mitigate many vulnerabilities, and must be the default setting for all members of Congress and their employees.
“Lawmakers are at distinctive danger and have to be exceptionally protected,” Weaver mentioned. “Their computer systems must be locked down and properly administered, and many others. And the identical applies to staffers.”
Weaver famous that Apple’s Lockdown Mode has a monitor document of blocking zero-day assaults on iOS functions; in September 2023, Citizen Lab documented how Lockdown Mode foiled a zero-click flaw able to putting in spy ware on iOS units with none interplay from the sufferer.
Earlier this month, Citizen Lab researchers documented a zero-click attack used to contaminate the iOS units of two journalists with Paragon’s Graphite spy ware. The vulnerability could possibly be exploited merely by sending the goal a booby-trapped media file delivered by way of iMessage. Apple additionally just lately up to date its advisory for the zero-click flaw (CVE-2025-43200), noting that it was mitigated as of iOS 18.3.1, which was launched in February 2025.
Apple has not commented on whether or not CVE-2025-43200 could possibly be exploited on units with Lockdown Mode turned on. However HelpNetSecurity observed that on the identical time Apple addressed CVE-2025-43200 again in February, the corporate mounted one other vulnerability flagged by Citizen Lab researcher Invoice Marczak: CVE-2025-24200, which Apple mentioned was utilized in a particularly subtle bodily assault towards particular focused people that allowed attackers to disable USB Restricted Mode on a locked system.
In different phrases, the flaw might apparently be exploited provided that the attacker had bodily entry to the focused weak system. And because the outdated infosec trade adage goes, if an adversary has bodily entry to your system, it’s more than likely not your system anymore.
I can’t communicate to Google’s Superior Safety Mode personally, as a result of I don’t use Google or Android units. However I’ve had Apple’s Lockdown Mode enabled on all of my Apple units because it was first made accessible in September 2022. I can solely consider a single event when certainly one of my apps didn’t work correctly with Lockdown Mode turned on, and in that case I used to be ready so as to add a brief exception for that app in Lockdown Mode’s settings.
My fundamental gripe with Lockdown Mode was captured in a March 2025 column by TechCrunch’s Lorenzo Francheschi-Bicchierai, who wrote about its penchant for periodically sending mystifying notifications that somebody has been blocked from contacting you, regardless that nothing then prevents you from contacting that individual instantly. This has occurred to me at the very least twice, and in each instances the individual in query was already an accepted contact, and mentioned that they had not tried to achieve out.
Though it could be good if Apple’s Lockdown Mode despatched fewer, much less alarming and extra informative alerts, the occasional baffling warning message is hardly sufficient to make me flip it off.