Case File

The Exploit That Needed No Click At All

Every other case in this series involves some decision, however small, that opened a door for an attacker. This one is the exception. It is worth understanding exactly why that makes it more concerning, not less.

What Happened

In 2021, researchers at the Citizen Lab documented an NSO Group exploit named FORCEDENTRY, delivered through Apple's iMessage to install Pegasus spyware on the phones of journalists and human rights defenders. Unlike a phishing attack, it required no interaction from the victim whatsoever. No link to click, no attachment to open, no message to reply to.

The Damage Caused

Once installed, Pegasus gave its operator effectively complete access to the device: messages, call records, location history, camera and microphone, all retrievable without the phone's owner ever seeing a prompt or warning. Several of the confirmed targets were journalists covering topics sensitive to their governments, at real personal risk once their sources and movements became visible to a hostile party.

What Caused the Breach

FORCEDENTRY exploited a flaw in how iMessage processed a specific file type, a vulnerability that existed for some time before Apple identified and patched it. Nothing about the victim's behaviour mattered. A phone simply had to be reachable by iMessage, which describes almost every iPhone in the world.

This is worth sitting with, because most of the cases in this series involve some human decision that opened the door: a reused password, a SIM swap, an oversharing habit. This one did not. Zero-click exploits are rarer and far more expensive for an attacker to develop and deploy than the alternatives, which is precisely why they tend to be reserved for high-value targets rather than opportunistic crime.

What Could Have Been Done to Avoid the Issue

Apple's response to this class of threat was Lockdown Mode, a restricted device configuration that disables many of the message-processing features attackers rely on, at some cost to everyday convenience. For individuals who are plausible targets of state-level surveillance (journalists, activists, executives with geopolitical exposure), enabling it on a primary device or maintaining a separate hardened device for sensitive work closes a meaningful part of this attack surface.

Regular operating system updates matter more here than almost anywhere else in this series, since patches close the exact class of vulnerability FORCEDENTRY relied on. No configuration eliminates the risk of a zero-click exploit entirely. Reducing the attack surface available to one narrows the field considerably.

Every security measure involves a trade-off between protection and convenience. Where that balance should sit depends on the resources a realistic attacker would bring to bear against you specifically. For most people, a handful of consistent habits closes the majority of that gap. For those whose assets or profile make a determined, well-funded attacker plausible, a more considered approach becomes worth the investment.

At Executive Privacy Advisors, we build that approach around your specific threat profile rather than a generic checklist. We extend the same thinking to your whole household, not just one set of accounts.

Need your digital life secured?

Request an Assessment

Published by Executive Privacy Advisors.

This article is for general informational purposes only and does not constitute security, legal or risk advice. Services described are subject to assessment, licensing and availability in your area. Your circumstances may differ and you should seek a professional assessment before making decisions.

← Back to all Case Files