The Federal Bureau of Investigation recently conducted a briefing for Capitol Hill staff on mobile device security hardening. This session followed an incident in which attackers obtained a contacts list from the personal phone of White House Chief of Staff Susie Wiles and leveraged it to conduct a series of impersonation attacks—including text messages and phone calls—targeting U.S. lawmakers. However, one of the Senate's most technically informed members contends that the FBI's recommendations fall short of what is necessary and fail to highlight robust security tools that already exist on mainstream phones.

The Wall Street Journal reported on May 29 that federal investigators were examining a coordinated scheme to impersonate Wiles through text and voice communications, with some evidence suggesting the use of artificial intelligence to simulate her voice. According to the publication, Wiles disclosed to associates that her phone's contact list had been compromised, providing the attackers with access to confidential phone numbers belonging to some of the nation's most prominent figures.

The sophistication level of the phishing and impersonation effort—whatever its ultimate objective—indicated that the perpetrators were driven by financial incentives rather than advanced technical capabilities. The Journal noted that "it became clear to some of the lawmakers that the requests were suspicious when the impersonator began asking questions about Trump that Wiles should have known the answers to—and in one case, when the impersonator asked for a cash transfer, some of the people said." The publication further reported that "in many cases, the impersonator's grammar was broken and the messages were more formal than the way Wiles typically communicates, people who have received the messages said. The calls and text messages also didn't come from Wiles's phone number."

The impersonation campaign took on heightened urgency following the murder of Minnesota House of Representatives Speaker Emerita Melissa Hortman and her husband, as well as the shooting of Minnesota State Senator John Hoffman and his wife. In mid-June, when FBI agents offered to conduct a briefing for U.S. Senate staff on mobile security threats, attendance exceeded expectations, with more than 140 staffers participating—a notably large turnout given that refreshments were not provided.

According to Senator Ron Wyden (D-Ore.), the guidance delivered by FBI agents to Senate staff concentrated primarily on fundamental security practices. These included avoiding clicks on questionable links or file attachments, steering clear of public wireless networks, disabling Bluetooth connectivity, maintaining current phone software versions, and performing regular device restarts.

Wyden conveyed his concerns in a letter addressed to FBI Director Kash Patel, stating: "This is insufficient to protect Senate employees and other high-value targets against foreign spies using advanced cyber tools. Well-funded foreign intelligence agencies do not have to rely on phishing messages and malicious attachments to infect unsuspecting victims with spyware. Cyber mercenary companies sell their government customers advanced 'zero-click' capabilities to deliver spyware that do not require any action by the victim."

The senator emphasized that the FBI should be actively promoting the adoption of built-in anti-spyware protections available on both Apple's iOS and Google's Android operating systems to mitigate sophisticated threats.

Built-in Protection Features

Apple offers Lockdown Mode, a feature intended for users who face potential exposure to targeted cyberattacks. This mode constrains non-essential iOS capabilities to minimize the device's vulnerability to exploitation. Google's Android platform provides a comparable protective mechanism known as Advanced Protection Mode.

Wyden also recommended that the FBI expand its training curriculum to encompass additional measures that enhance mobile device privacy and reduce tracking exposure. These measures encompass the deployment of ad blockers to prevent malicious advertising, turning off ad tracking identifiers on mobile devices, and withdrawing from commercial data broker services. The suspect in the Minnesota shootings reportedly utilized multiple people-search platforms to locate the residential addresses of his victims.

Wyden's correspondence acknowledged that while the FBI has recommended these protective steps in different guidance documents over time, the current advisory being provided to national leadership requires greater depth, practical applicability, and urgency. "In spite of the seriousness of the threat, the FBI has yet to provide effective defensive guidance," Wyden stated.

Expert Assessment

Nicholas Weaver, a researcher at the International Computer Science Institute, a nonprofit organization based in Berkeley, California, believes that Lockdown Mode or Advanced Protection should serve as the standard configuration for all members of Congress and their staff, given their effectiveness against numerous vulnerabilities. "Lawmakers are at exceptional risk and need to be exceptionally protected," Weaver said. "Their computers should be locked down and well administered, etc. And the same applies to staffers."

Weaver highlighted that Apple's Lockdown Mode has demonstrated success in preventing zero-day attacks targeting iOS applications. In September 2023, researchers at Citizen Lab demonstrated how Lockdown Mode defeated a zero-click vulnerability that could have installed spyware on iOS devices without requiring any user interaction.

During the current month, Citizen Lab researchers identified a zero-click attack that had been deployed against the iOS devices of two journalists, infecting them with Paragon's Graphite spyware. The vulnerability could be triggered by simply transmitting a malicious media file to the target through iMessage. Apple subsequently revised its advisory regarding the zero-click flaw (CVE-2025-43200), confirming that it was resolved beginning with iOS 18.3.1, released in February 2025.

Apple has not disclosed whether CVE-2025-43200 could be exploited on devices running Lockdown Mode. However, HelpNetSecurity noted that when Apple addressed CVE-2025-43200 in February, it simultaneously patched a separate vulnerability identified by Citizen Lab researcher Bill Marczak: CVE-2025-24200. Apple characterized this flaw as having been leveraged in an exceptionally sophisticated physical attack targeting particular individuals, enabling attackers to circumvent USB Restricted Mode on a locked device.

In essence, the vulnerability could only be exploited if the attacker possessed physical access to the targeted device. Following the conventional wisdom of information security professionals, once an adversary gains physical access to a device, ownership of that device is typically no longer assured.

Regarding Google's Advanced Protection Mode, personal experience is limited due to non-use of Google and Android platforms. However, Apple's Lockdown Mode has remained activated on all personal Apple devices since its introduction in September 2022. There has been only one instance where an application experienced compatibility issues with Lockdown Mode enabled, and in that situation, a temporary exception could be configured within Lockdown Mode's settings.

A primary concern with Lockdown Mode was articulated in a March 2025 article by TechCrunch's Lorenzo Francheschi-Bicchierai, who highlighted its tendency to generate periodic notifications indicating that someone has been prevented from contacting you, despite nothing actually preventing direct contact with that person. This has occurred at least twice, and in both instances the individual in question was already an approved contact who claimed they had not attempted to reach out.

While it would be preferable if Apple's Lockdown Mode generated fewer alerts that were less alarming and more informative, the occasional confusing notification hardly justifies disabling the feature.

Source: Krebs on Security