The UK Home Office has issued a new technical capability notice (TCN) to Apple, demanding the creation of a backdoor into the company's encrypted cloud storage service, specifically targeting data belonging to British users. This latest request, reportedly transmitted in early September, follows a previous attempt in January where the Home Office sought global access to encrypted user data, which led to significant diplomatic tensions between the UK and the US. The earlier order prompted Apple to challenge the demand in court and resulted in the company withdrawing its Advanced Data Protection (ADP) service from the UK in February. As a result, Apple is currently unable to offer its most secure cloud storage option, iCloud Advanced Data Protection, to new users in the United Kingdom. Apple has publicly expressed disappointment that UK customers are deprived of these enhanced privacy protections, especially in light of increasing data breaches and threats to customer privacy. The company reiterated its longstanding position that it has never built, and will never build, a backdoor or master key for any of its products or services. The Home Office, while declining to confirm or deny the existence of the latest TCN, stated that it will always take necessary actions to ensure the safety of UK citizens. Under the Investigatory Powers Act 2016, the UK government has the authority to compel telecommunications companies to remove electronic protections on user data for evidence collection purposes. Privacy advocates have raised concerns that any attempt to weaken Apple's encryption could jeopardize the security of global customers' sensitive information, including passwords, message histories, and health data stored in iCloud. Both Apple and the Home Office are legally restricted from discussing the specifics of TCNs. The ongoing standoff highlights the broader conflict between government demands for lawful access to encrypted data and technology companies' commitments to user privacy and security. The situation has also had implications for international relations, as previous UK demands threatened to impact trade negotiations with the United States. The Home Office's renewed focus on British users' data, rather than global access, appears to be a strategic shift following the backlash from its earlier attempt. Despite the government's insistence on the necessity of such measures for national security, the move has intensified the debate over the balance between public safety and individual privacy rights. The outcome of this dispute could set a significant precedent for how governments interact with technology providers regarding encrypted services. Apple continues to resist any efforts that would compromise the security architecture of its products, maintaining that such actions would undermine the trust and safety of its user base. The lack of access to ADP in the UK leaves British users with fewer options for securing their cloud-stored data compared to users in other countries. The ongoing legal and policy battle underscores the challenges faced by multinational technology companies operating under varying national security laws and privacy expectations.

See the reporting duties and controls this puts on the clock.
1 event from the most recent confirmed update back to the earliest known activity.
The UK government, through the Home Office, renewed efforts to require Apple to provide access to encrypted cloud storage, reviving a long-running dispute over lawful access to end-to-end encrypted data. Multiple references describe this as the UK once again demanding a backdoor to Apple's protected services.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
3 references tracked. Mallory keeps watching after this page renders.
govinfosecurity.com
Open sourcebankinfosecurity.com
Open sourcearstechnica.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.