The UK government reportedly moved to withdraw a secret order that would have forced Apple to provide access to encrypted iCloud data, reversing a demand issued under the Investigatory Powers Act that sought blanket access to user content stored worldwide. The order targeted Apple's Advanced Data Protection feature, which extends end-to-end encryption to additional iCloud categories, and drew sharp criticism because it could have enabled access to data belonging to users outside the UK without their governments' knowledge.
Apple resisted the demand by refusing to weaken its security architecture, removing Advanced Data Protection from the UK market, and pursuing a legal appeal instead of building a global backdoor into iCloud. The dispute became a broader flashpoint over lawful access and encryption, with privacy advocates warning that any mandated backdoor would undermine security for all users, while UK authorities argued the capability was needed for terrorism and child sexual abuse investigations; U.S. officials and reporting later indicated London agreed to rescind the order, though formal notification was still reportedly pending.

See the reporting duties and controls this puts on the clock.
3 events from the most recent confirmed update back to the earliest known activity.
According to U.S. Director of National Intelligence Tulsi Gabbard and Financial Times sources, the UK agreed to rescind the order seeking access to encrypted iCloud user data. At the time of reporting, the withdrawal was said not to be formally completed and Apple had reportedly not yet received official notice.
Rather than create a backdoor, Apple reportedly responded by withdrawing its Advanced Data Protection encrypted storage feature from the UK and pursuing a legal appeal against the order. This preserved its broader security architecture while contesting the government's demand.
The UK government reportedly served Apple with a technical capability notice under the Investigatory Powers Act requiring access to encrypted iCloud content, including data protected by Advanced Data Protection. The demand was described as applying broadly, potentially affecting users worldwide rather than only UK accounts.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
3 references tracked. Mallory keeps watching after this page renders.
macrumors.com
Open sourcemacrumors.com
Open sourcewashingtonpost.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.