UN human rights experts called for an immediate investigation after forensic analysis found with medium to high confidence that Jeff Bezos’s iPhone was compromised in 2018 shortly after he received a WhatsApp video file from an account used by Saudi Crown Prince Mohammed bin Salman. Reports said the intrusion covertly exfiltrated more than 6 GB of data over months, and investigators assessed with reasonable certainty that the file delivered malicious code. Saudi Arabia denied responsibility and dismissed the allegations, while Apple’s security model came under renewed scrutiny because sophisticated compromises can be difficult to detect even on hardened devices.
The alleged hack was tied to a wider campaign of Saudi surveillance and pressure targeting dissidents, human rights advocates, and people connected to murdered columnist Jamal Khashoggi, with UN experts noting parallels to other cases involving commercial spyware. The incident also fed into the broader dispute around the publication of Bezos’s private messages and the National Enquirer fallout, raising questions about whether data taken from his phone contributed to the exposure of his extramarital affair and whether the operation was intended to influence or retaliate against The Washington Post coverage of Saudi Arabia.

TTPs, infrastructure, and targeting history in one profile.
11 events from the most recent confirmed update back to the earliest known activity.
Business Insider, citing The Wall Street Journal, reported that the FBI had not found proof substantiating claims that Saudi Arabia hacked Jeff Bezos's phone and had treated that theory as a low-priority line of inquiry. The report said the FBI did not examine Bezos's phone and had not resolved whether Saudi actors were involved.
A Guardian report on April 7, 2020 said litigation tied to disclosure of Bezos's extramarital affair raised further questions about who obtained and exposed his personal data, in the context of the earlier hacking allegations.
The Washington Post reported that Bezos's iPhone X was allegedly compromised by malicious code delivered through WhatsApp and argued the case highlighted how sophisticated attackers can evade detection even on Apple devices.
Following publication of the UN experts' findings, Saudi Arabia rejected the allegations and described them as absurd. NSO Group also denied its technology was used against Bezos.
On January 22, 2020, UN special rapporteurs Agnes Callamard and David Kaye said they were gravely concerned by forensic evidence indicating Bezos's phone was infiltrated via a WhatsApp account used by Mohammed bin Salman, and called for an immediate investigation by US and other authorities.
After Jamal Khashoggi was killed in October 2018, Bezos and Amazon were reportedly targeted by a large Saudi social media campaign. UN experts said the campaign appeared aimed principally at Bezos because he owned The Washington Post.
The Washington Post reported that a forthcoming UN investigation would conclude Bezos's phone was hacked in 2018 after receiving a WhatsApp message from an account purportedly belonging to the Saudi crown prince.
The Guardian reported that Jeff Bezos met FBI investigators in 2019 as part of the US response to allegations that his phone had been compromised via a WhatsApp message linked to Mohammed bin Salman. This reflects previously unlisted law-enforcement involvement in the case before the UN findings became public.
After the alleged compromise, more than 6 GB of data was reportedly covertly extracted from Bezos's device over the following months. The activity was cited by UN experts and other reporting as evidence of a sustained intrusion.
On May 1, 2018, Bezos reportedly received a WhatsApp message containing a video file from an account used by Mohammed bin Salman. Forensic analysis later assessed with medium-to-high confidence that the file delivered malicious code to Bezos's iPhone X.
According to the UN-referenced timeline, Jeff Bezos and Saudi Crown Prince Mohammed bin Salman exchanged phone numbers in April 2018, establishing the contact channel later central to the alleged compromise.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
14 references tracked. Mallory keeps watching after this page renders.
timesofindia.indiatimes.com
Open sourcebusinessinsider.com
Open sourcetheguardian.com
Open sourceweb.archive.org
Open sourceedition.cnn.com
Open sourcetechnologyreview.com
Open sourcewashingtonpost.com
Open sourceohchr.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.