Apple has withdrawn Advanced Data Protection (ADP) for iCloud in the UK after reports that the British government sought access to encrypted user data under the Investigatory Powers Act. The reported order allegedly demanded broad access to end-to-end encrypted iCloud content, including data belonging to users outside the UK, prompting Apple to remove the feature rather than create a backdoor. Apple said it was disappointed that UK customers would lose the protection at a time of increasing data breaches and privacy threats, and reiterated its long-standing refusal to weaken encryption in its products.
The change affects iCloud categories protected by ADP, including Photos, Notes, Messages backups, and device backups, while other Apple services that use end-to-end encryption in the UK — such as iMessage, FaceTime, password management, and health data — remain unaffected. Existing UK users with ADP enabled will have to disable it manually during a grace period because Apple said it cannot turn the feature off on their behalf. The move has intensified concerns among security and privacy advocates, who warn that lawful-access demands can erode protections relied on by users worldwide.

See the reporting duties and controls this puts on the clock.
2 events from the most recent confirmed update back to the earliest known activity.
Apple removed the Advanced Data Protection feature for users in the United Kingdom rather than create a backdoor, saying it remained opposed to weakening encryption. Existing UK users were told they would need to manually disable ADP during a grace period, while other end-to-end encrypted Apple services such as iMessage and FaceTime were not affected.
The UK government reportedly issued an order under the Investigatory Powers Act seeking access to encrypted iCloud content, including data protected by Apple's Advanced Data Protection and reportedly extending to users worldwide. The demand would have undermined the end-to-end encryption protections provided by ADP.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.