
The hacking of Jeff Bezos's phone, the founder and CEO of Amazon, shook the digital world and major technology companies . The controversy erupted when Facebook directly pointed to iOS, Apple's operating system, as responsible for the security breach, exonerating WhatsApp. Following this incident, debates have opened up about the security of mobile operating systems, the reliability of end-to-end encryption, and the risks of next-generation spyware.
The background to the Jeff Bezos hack: What really happened?

It all started with a 4,4 MB video file that Jeff Bezos received via WhatsApp , allegedly sent from the account of Saudi Crown Prince Mohammed bin Salman. Forensic sources indicate that, shortly after receiving the video, Bezos's iPhone showed an unusual increase in outgoing data volume: from an average of 430 KB per day, the transfer rose to 126 MB daily, with even higher peaks.
Suspicions of espionage quickly spread, especially given Bezos's role at The Washington Post—a newspaper highly critical of Saudi Arabia following the murder of Jamal Khashoggi. The forensic details were analyzed by FTI Consulting and reviewed by UN investigators, who deemed an infiltration facilitated by advanced spyware tools highly probable.
The Bezos case served to expose the limitations of mobile security, even in systems renowned for their supposed robustness, such as iOS . The chain of events included extortion, leaks of private data, and an international media storm that damaged the reputations of Apple, Facebook, and WhatsApp.
Facebook responds: "It's not WhatsApp, it's iOS."

In response to accusations regarding WhatsApp's security, Facebook decided to defend itself publicly . Nick Clegg, Facebook's Vice President of Global Affairs and Communications, stated in an interview with the BBC that WhatsApp's end-to-end encryption is "unbreakable," suggesting that the vulnerability lay in Apple's iOS operating system and not in the messaging app itself.
"It sounds like something in the system, you know, what they call operating, operating on the phone itself. It couldn't have been anything at the time the message was sent, in transit, because it's end-to-end encrypted on WhatsApp."
Clegg likened the attack to opening a malicious email : the real problem arises only when the recipient executes the infected file, allowing the malware to be deployed.
Other senior Facebook executives, such as Nicola Mendelsohn, reinforced this position, stating that the hack "highlights potential hidden vulnerabilities in phone operating systems." These statements imply that, while WhatsApp was the entry point, the critical flaw was in the insecure structure of iOS, which allowed the malicious file to compromise the device.
Despite Facebook's strong statements, Apple has largely remained publicly silent on the incident, simply emphasizing the continued importance of security in all its updates.
Technical details of the attack: How the Bezos iPhone hack worked

The attackers' entry point was a video file sent via WhatsApp . According to the forensic analysis conducted by FTI Consulting, this file contained additional encrypted code, which complicated its evaluation by investigators: no conventional malware or domains related to malicious traffic were detected, nor was jailbreaking or other known iOS exploits. However, the anomalous change in data traffic and the subsequent leak of private information demonstrated the attack's effectiveness.
Cybersecurity experts, consulted by the UN and organizations such as Citizen Lab, explain that, although WhatsApp's end-to-end encryption prevents messages from being manipulated during transit, it does not protect against the execution of malicious files once they are opened by the user.
The sophisticated attack allegedly exploited several vectors simultaneously: a vulnerability in the way WhatsApp handles media files, and an exploitation of weaknesses in iOS's sandboxing protection, which seeks to isolate app processes. A flaw in this protection would have facilitated the malware's leap from WhatsApp to the rest of the operating system, allowing access to all information stored on the device.
These attack mechanisms are usually reserved for high-value targets , due to their high costs and the complexity of developing "zero-day" vulnerabilities, for which millions of dollars can be paid in underground markets.
The role of Pegasus and other spyware in advanced espionage

The Jeff Bezos case highlighted the role of advanced spyware like NSO Group's Pegasus . This spyware is notorious for its ability to exploit previously unknown (zero-day) vulnerabilities in systems like iOS and Android, allowing for virtually total control over the target device: from accessing messages and documents to activating microphones, cameras, or even accessing the cloud.
The forensic investigation pointed to Pegasus as the most likely tool used in the intrusion. However, NSO Group has repeatedly denied involvement in this specific case and threatened legal action for any suggestion of such involvement. According to NSO, its software is sold only to governments and is intended for "the fight against terrorism and serious crime." However, multiple journalistic investigations have documented the use of Pegasus to spy on journalists, activists, and high-profile figures around the world.
During the same period as the Bezos hack, WhatsApp sued NSO Group for using its platform as an infection route through missed calls or specially crafted files. The vulnerability allowed attackers to install spyware without the victim having to interact with the suspicious message or call.
Other spyware programs, such as Hacking Team's Galileo, have also been mentioned as possible tools used in high-profile operations, although in Jeff Bezos's scenario, Pegasus remains the prime suspect.
Institutional reactions and global consequences of the attack
The controversy following the hack quickly reached international organizations. The UN intervened, requesting an investigation into the spying on Jeff Bezos , considering the case an example of the dangers involved in the unrestricted commercialization and use of sophisticated spyware.
UN Special Rapporteur Agnes Callamard described the spying on Bezos as "informed surveillance," allegedly carried out through software sold without judicial oversight by private companies to governments. These findings, along with the fact that UN officials were banned from using WhatsApp for sensitive communications after the hack, underscore the significance of the incident.
The Saudi Arabian embassy called the reports linking the kingdom to the hack "absurd" and called for an independent investigation to clarify the facts. For his part, Jeff Bezos responded symbolically, participating in tributes to Jamal Khashoggi and demonstrating his commitment to transparency in the investigation.
Who's really to blame? The clash of opinions between Facebook, Apple, and the expert community
The debate over responsibility for the attack has divided the tech community:
- Facebook argues that WhatsApp's encryption makes it impossible to intercept or manipulate messages in transit, shifting responsibility to the iOS operating system and its management of apps and files.
- Apple has generally avoided direct statements, but defenders of its platform insist that successful exploitation of iOS requires zero-day vulnerabilities, which are extremely difficult to find and are usually quickly patched after discovery.
- Independent experts They agree that the crucial problem lies in the combination of multiple vulnerabilities – in the messaging software, the operating system and the file protection protocols – which multiplies the risk despite the apparent robustness of each component separately.
Mobile device security increasingly depends on the weakest link in the digital chain . Even the most secure platforms can be compromised when high-level exploits, developed by state actors or groups with substantial resources, are combined.
Could I be a victim of a similar hack? Risks and protection for the average user
The magnitude and sophistication of the attack on Jeff Bezos has raised concerns about the security of regular users of apps like WhatsApp on iPhones and other popular smartphones.
Experts cited by international media outlets explain that for most ordinary users, the risk is very low due to the high costs and sophistication required to develop and deploy exploits like those used in the Bezos case. These types of attacks are usually directed at high-profile targets: businesspeople, journalists, activists, or government officials.
However, the case highlights the universal need to keep applications and operating systems updated, avoid opening files from dubious sources, and be alert to potential phishing campaigns.
- Keep all applications updated to their latest version
- Do not open attachments or links from unknown contacts, even if they seem harmless.
- Use strong passwords whenever possible
- Make regular backups and review your app permissions.
Implications for global privacy and security
The hacking of Jeff Bezos's phone has shaken confidence in the security of mobile technology and raised concerns about the use of spyware in international conflicts and the surveillance of public figures . Countries like Mexico, Uganda, Mozambique, and others have made headlines for using Pegasus and similar tools to spy on political opponents, journalists, and even ordinary citizens involved in social causes.
The case also underscores the fundamental role of transparency in investigating cybersecurity incidents. Legislators and international organizations have required technology companies to provide the widest possible cooperation to help uncover vulnerabilities and prevent similar attacks in the future.
At the judicial level, the lawsuits filed by WhatsApp and Facebook against NSO Group have opened a new chapter in the regulation of the global spyware market, potentially setting a precedent for the scope and limitations of these tools.
The story of Jeff Bezos's iPhone hack has sparked an unprecedented debate about the strength of encryption, the responsibility of Big Tech, and the urgent need for new cybersecurity policies. The case illustrates how, in the digital age, even senior executives at the most influential companies on the planet can fall victim to extremely sophisticated attacks.
Key lessons learned include the importance of not blindly relying on the security reputation of an operating system or application, the need to develop better vulnerability update and response mechanisms, and the urgency of leading effective oversight of the spyware market through regulation.
The intrusion into Jeff Bezos's phone transcends the simple debate between Facebook and Apple : it's a reminder that absolute security doesn't exist, and that the sophistication of attacks grows in parallel with technological advancements and global interconnectedness. Surveillance, privacy, and the protection of personal data have become priorities not only for large corporations, but for any individual who uses a mobile device today.