Three Turkish ministers got Apple spyware warnings; nobody has examined a phone
Middle East Eye’s report rests on unnamed sources and unnamed ministers. Citizen Lab’s Serbia work, published eleven days earlier, shows what the confirmed version of this story looks like.
Middle East Eye’s Ragip Soylu reported from Ankara on 8 September that “Apple sent notifications to phones belonging to at least three Turkish ministers warning that they may have been targeted in mercenary spyware attacks, sources familiar with the matter told Middle East Eye.” The notifications, MEE understands, came in the same batch Apple sent last month to iPhone users in 110 countries, Turkey among them. Ankara believes the attempts failed, MEE reports, citing “enhanced security measures and encrypted applications.” Senior Turkish officials were previously targeted in suspected Pegasus attacks in 2021. Every load-bearing element of that account is anonymous: the ministers are unnamed, the sources are unnamed, there is no Turkish on-record statement in anything this desk retrieved, and no device has been forensically examined. An Apple threat notification is an alert that Apple’s own signals suggest targeting. Apple does not name the operator, and a notification is not evidence of infection.
The control case was published on 2 September. Citizen Lab, working with Serbia’s SHARE Foundation, analysed the iPhone of a member of the Serbian student protest movement who had received an Apple threat notification. “Our analysis confirmed that an iMessage zero-click exploit was used to infect the device with NSO Group’s Pegasus spyware,” the report states, with “high-confidence indicators of infection from a period across December 2025 – January 2026,” adding that the exploit “has subsequently been patched by Apple as of iOS 18.4.1.” SHARE has documented at least 14 people in Serbian student and civil-society circles, plus an opposition MP, who recently received notifications. That is the shape of a confirmed case: named institution, named spyware, dated infection window, identified delivery vector. The Turkey reporting is at an earlier stage of the same process, and may never reach this one.
The commercial layer moved separately. Citizen Lab reported that on 9 September a bipartisan group of US lawmakers wrote to Commerce Secretary Howard Lutnick urging him to add three Indian companies, including BellTroX, to the sanctions list, accusing the firms of “conducting targeted espionage against U.S.” — the quotation as indexed is truncated there. The signatories and the two other named firms are not yet public in anything retrieved. BellTroX is the India-based mercenary-hacking outfit documented over years as serving litigation and corporate clients, with Gulf and Israeli linkages surfacing in earlier reporting. Whether this is a US–India trade story or a Gulf story depends entirely on who the other two firms bill.
Assessment: The gap between the Turkey and Serbia items is the whole method of this desk. Both begin with the same Apple alert. One ends with a named laboratory, a named spyware product and a patched exploit chain; the other ends with three officials nobody will identify and a government briefing that the attack failed — a claim with an obvious incentive behind it, since a minister whose phone was actually compromised is a minister with a problem. Watch for either an Ankara statement on the record or a device handed to Citizen Lab or Amnesty’s Security Lab. Absent one of those, the Turkish story should not harden. On the Lutnick letter, the client list is the story, not the sanctions ask.