As Apple Warns Users Over Spyware, Ireland Prepares Powers for Covert Access to Phones

Ireland plans legislation allowing covert software access to electronic devices and networks, days after Apple warned users in 110 countries about spyware.

As Apple Warns Users Over Spyware, Ireland Prepares Powers for Covert Access to Phones

The Government is preparing legislation that would, for the first time, expressly provide for covert surveillance software to gain lawful access to electronic devices and networks. It arrives in the same week Apple warned users across 110 countries that they may have been individually targeted by mercenary spyware. The two developments are not connected, but together they raise a timely question about what government hacking actually involves.

On 13 August 2026, Apple issued a fresh round of threat notifications to selected users. Apple confirmed to BleepingComputer that the latest batch went to users in 110 countries. Apple's own updated documentation states it has issued such notifications multiple times each year since 2021, and has now notified targeted individuals in more than 150 countries overall.

The notification now appears prominently on the iPhone Lock Screen and in Settings, alongside an email and an Apple Account warning. Apple does not attribute individual threat notifications to particular attackers or geographical regions, and has not said these latest attacks are Pegasus. There is no evidence the alerts relate to Ireland, GardaĂ­ or the proposed Irish legislation.

Apple says these operations use enormous resources to target very small numbers of specific individuals, typically because of who they are or what they do. It describes them as extremely expensive operations rather than indiscriminate consumer malware campaigns. Documented cases have generally involved individually selected targets rather than randomly chosen members of the public.

Apple says such attacks have historically been associated with state actors and have targeted people including journalists, activists, politicians and diplomats. It names NSO Group's Pegasus as an example of this category of technology.

Ireland's Biggest Interception Overhaul in More Than Three Decades

Separately, the Government is preparing the Communications (Interception and Lawful Access) Bill, with the policy proposal approved in January 2026.

It is intended to replace the Interception of Postal Packets and Telecommunications Messages (Regulation) Act 1993, legislation that predates smartphones, WhatsApp, Signal, iMessage and modern end-to-end encryption. The Government has said the new law will establish the principle that interception powers apply to all forms of communications, whether encrypted or not, and that interception may obtain both content and related metadata.

A briefing from the Minister for Justice in May states:

"There will also be a provision for the use of covert surveillance software to gain lawful access to electronic devices and networks…"

The briefing indicates this would be for investigating serious crime and security threats.

That single sentence is the substance of the story. The Government has confirmed it wants a statutory basis for covert software-based access to devices and networks. There is no evidence currently available that An Garda SĂ­ochĂĄna possesses Pegasus, intends to buy Pegasus, or has selected NSO Group.

The Detail Is Not Yet Public

As far as can be established from current Government and Oireachtas records, the General Scheme has not been published as of 15 August 2026, and the detailed statutory powers remain unknown. The Government has set out its policy objectives, but not the detailed statutory powers.

It is therefore not known whether Irish authorities would be permitted to activate cameras or microphones, perform zero-click infections, exploit undisclosed vulnerabilities, continuously monitor location, copy entire photo libraries or recover credentials. None of those capabilities has been confirmed as part of the proposed powers. What is confirmed is covert surveillance software providing lawful access to electronic devices and networks.

Why Encryption Changed the Problem

Traditional telephone interception relies on the network operator carrying the call. Modern communications often do not work that way. With properly implemented end-to-end encryption, the service provider may not hold a readable copy of the message at all.

There is one place where the communication necessarily becomes readable, and that is the user's own phone. Rather than attempting to defeat the encryption itself, endpoint access obtains the information after the device has decrypted it. That is what makes covert device access conceptually different from tapping a phone line.

It is also worth distinguishing three things that are frequently conflated. A backdoor is a mechanism the manufacturer deliberately builds in to allow protections or encryption to be bypassed. An exploit is a vulnerability the manufacturer never intended to exist, discovered by an attacker and used to defeat the security. Spyware is the software subsequently deployed onto a compromised device to collect information or conduct surveillance.

Pegasus has historically combined sophisticated exploit chains with the Pegasus surveillance platform. Apple's cooperation is not required for that process.

Apple's Position

Apple's response to this class of technology has been to patch exploited vulnerabilities, harden iOS, issue threat notifications and offer Lockdown Mode for unusually high-risk users. In 2021 Apple sued NSO Group, describing its Pegasus operations as sophisticated state-sponsored surveillance and seeking an injunction preventing NSO from using Apple products and services. Apple specifically documented the FORCEDENTRY zero-click exploit, which it had patched.

The tension is structural. Any undisclosed vulnerability used lawfully against a criminal suspect would still be, from Apple's perspective, a security flaw affecting its customers, and its security engineers would try to eliminate it. A warrant does not make the underlying weakness safe for every other owner of the same device.

The clearest precedent came after the San Bernardino terrorist attack of 2 December 2015, when the FBI recovered an iPhone 5c used by attacker Syed Rizwan Farook. Apple cooperated with lawful requests for information it actually possessed and provided technical assistance. The dispute began when the FBI sought Apple's help in creating modified software that could bypass security protections and facilitate brute-forcing the passcode.

Tim Cook publicly refused. Apple said the Government was effectively asking it to build a backdoor into the iPhone, and argued that once such a capability existed it could not realistically be guaranteed to remain useful only for that single device. Apple's 2016 letter specifically warned that expanded government powers might someday involve demands to intercept messages, track location, or access a phone's microphone or camera.

The FBI eventually obtained assistance from an outside party and accessed the phone without Apple's cooperation. A later US Justice Department Inspector General investigation confirmed the Bureau had not possessed the required capability when it originally sought Apple's help. Where manufacturers will not build the access mechanism, governments can instead purchase technological capabilities from specialist vendors.

What Endpoint Access Can Actually Reach

On 16 July 2026, Amnesty International published an investigation containing images of the Pegasus operator interface, drawn from internal NSO material exposed through litigation. One image shows installation attempts and their status; another shows the interface presented to an operator following a successful infection.

Amnesty says the Pegasus Investigate interface organises collected information into categories including calls, messages, emails, calendar entries, contacts, browsing information, files, applications and photographs. There is also a credentials section, which Amnesty assesses as potentially containing passwords, authentication tokens or other account credentials.

This is the clearest illustration of why compromising a device is not equivalent to listening to one telephone call. A modern smartphone is a person's correspondence, camera, microphone, photograph album, location history, contacts book, authentication device, calendar, work computer and increasingly their wallet.

What Counts as Serious Crime

Under the existing 1993 legislation, a serious offence must satisfy a two-part test. It must carry a maximum sentence of five years' imprisonment or more, and it must additionally involve loss of life, serious injury, serious property loss or damage, or serious risk of those; or result or be likely to result in substantial gain; or the particular facts and circumstances must make it a specially serious case of its kind.

A maximum sentence of five years alone is not sufficient. Equally, a serious offence is not synonymous with terrorism or murder.

Speaking in the DĂĄil, the Minister for Justice gave examples of communications evidence proving important in cases involving murder, serious child sexual abuse, serious armed robbery and violence. The Government also refers to serious and organised crime, threats to State security and terrorism.

It is not known whether the new covert software provision will inherit that 1993 definition. The eventual Bill might maintain it, narrow it, introduce a higher threshold specifically for device hacking, or use an entirely different definition. Whether secretly compromising an entire smartphone will require a higher legal threshold than conventional communications interception remains unanswered.

Raised in the DĂĄil

On 19 March 2026, Social Democrats TD Gary Gannon questioned the Minister about proposed access to encrypted communications and personal devices. Gannon raised Pegasus directly, saying comparable technology had been abused against political opposition and journalists elsewhere. He warned that whatever law Ireland creates today will still potentially be available to a different Government ten or twenty years from now, and called for careful drafting and proper Oireachtas scrutiny.

Jim O'Callaghan, Minister for Justice:

"We do not want to see a situation where the State is able to stick its nose into legitimate communications that do not involve criminal activity…"

He nevertheless argued that GardaĂ­ require access to information useful in investigating serious criminal behaviour, and said the precise type of software was not presently his concern. The priority, he indicated, was establishing a statutory regime allowing access in limited circumstances with strong safeguards.

Safeguards Promised, and Objections Raised

The Minister for Justice is currently responsible for authorising interception requests. Under the new legislation the Minister would retain a role, but for the first time there would also be judicial authorisation of interception requests. Agencies seeking interception would additionally have to identify potential issues concerning privileged material.

The Government says the regime will be based around necessity, proportionality, human rights and legal safeguards. Until the Bill exists, how strong those safeguards actually are cannot be judged.

The January announcement also proposes legal provision for electronic scanning equipment capable of locating and recording identifier data from mobile devices within particular areas, a separate technology from covert surveillance software.

Before the 2026 announcement, the Global Encryption Coalition published an open letter addressing Ireland's proposed lawful-access direction. Signatories included the Irish Council for Civil Liberties, Mozilla, The Tor Project, Blacknight and Tuta, alongside numerous security and privacy experts. Their fundamental objection is that an encryption backdoor which works for authorised investigators also creates a security mechanism that could potentially be exploited by others.

There is a nuance worth noting. The Government has not said it intends to mandate a conventional encryption backdoor. Its separate proposal for covert surveillance software potentially offers another route, targeting the particular endpoint rather than weakening encryption for everybody. Until the Bill is published, it is not clear exactly how those two concepts interact.

Apple has already engaged with Irish officials. In March 2026, The Irish Times reported that senior Apple leadership had been "alarmed" by previous comments from the Minister about access to encrypted data, and that Apple representatives had met Department of Justice officials in September 2025. The Department told the newspaper the meeting formed part of wider stakeholder engagement around updating interception and data-access legislation. No Apple statement formally opposing the 2026 Bill has been identified.

Protections for Journalists

The European Media Freedom Act explicitly describes intrusive surveillance software as a particularly invasive form of surveillance against journalists and their sources. The EU definition is remarkably broad, covering software capable of secretly recording calls or using microphones, filming or photographing, copying messages, accessing encrypted content, monitoring browsing behaviour and geolocation, collecting sensor data and tracking activity across devices.

For journalists, and for people who could potentially identify journalistic sources, deployment is heavily restricted. Where spyware can lawfully be used, the EMFA requires conditions including a proper legal basis, an overriding public-interest justification, authorisation by a judicial or independent body, a sufficiently serious offence, and a determination that less intrusive measures would not be adequate.

The Government has acknowledged in the DĂĄil that criminal justice legislation, including this interception legislation, is being worked on in connection with Ireland's obligations under EMFA protections for journalistic sources.

The Open Questions

Ireland would not be inventing the concept. The United Kingdom openly calls it equipment interference, and its current statutory code explicitly describes authorities remotely installing software onto smartphones or computers, exploiting vulnerabilities, extracting information and monitoring users. MI5 publicly explains that equipment interference allows it to interfere with phones, computers and other devices to obtain communications and other information. That does not establish that the British Government uses Pegasus specifically.

The international record is mixed. The European Parliament's Pegasus inquiry found that NSO had sold Pegasus to 22 end users in 14 EU Member States, and documented government use of Pegasus and equivalent spyware against groups including journalists, politicians, lawyers, diplomats, civil society figures and others. Citizen Lab has separately documented Pegasus operations targeting civilians, including one investigation that found 36 phones belonging to journalists, producers, presenters and executives at Al Jazeera compromised in a zero-click Pegasus campaign.

Until the General Scheme is published, several questions remain open. Which State agencies would be authorised to deploy covert surveillance software, what threshold would apply, what happens to information unrelated to an investigation that is collected from a compromised device, and whether the State would be obliged to disclose a vulnerability to the manufacturer after use or permitted to retain it for surveillance.

Follow our WhatsApp ChannelLive Alerts