decrypted · 7 august 2026 · ransomware and cybercrime · vulnerabilities and patching · surveillance and privacy

Apple goes back to court over the UK's iCloud backdoor

Apple has gone back to a UK tribunal to fight, for the second time, a government order demanding access to encrypted iCloud backups. It is the kind of story that rarely gets a clean ending, because the law that compels it also forbids the people involved from describing exactly what was asked for. That opacity is worth noting before the technical detail: whatever you think of the underlying aim, a legal mechanism that cannot be discussed in public is an odd foundation for public trust in security.

What Apple is actually fighting

In February 2025, the Home Office secretly ordered Apple, under a technical capability notice issued through the Investigatory Powers Act, to build a way into Advanced Data Protection, the optional end-to-end encryption Apple offers for iCloud backups. Apple withdrew ADP from new UK sign-ups that same month and filed its first challenge at the Investigatory Powers Tribunal in March 2025. After pressure from Washington, the government dropped the demand for non-UK customers in August 2025, then reissued it that October narrowed to the encrypted backups of British users only. Apple filed a second complaint at the tribunal in July, according to reporting this week from TechCrunch, 9to5Mac and MacRumors. A related case brought by Liberty and Privacy International against the use of these notices is listed for a December hearing at the same tribunal.

The Secure by Design problem with a backdoor

Advanced Data Protection is end-to-end encrypted specifically so that Apple itself cannot read it, which is what makes a "technical capability" order so awkward: there is no narrow door to build, only a general one, because the design choice that makes the service safe against everyone else is the same choice that makes it unreadable to Apple. That is the whole point of the architecture, and the whole problem with legislating around it. A backdoor sized for UK law enforcement is a backdoor sized for whoever else finds it, government or not. UK organisations building or buying end-to-end encrypted products should treat this case as a live test of whether "secure by design" and "lawful access by design" can coexist in British law, because right now that question is being settled in a tribunal, not in a spec document.

Also this week

CISA's deadline for US federal agencies to patch three actively exploited flaws lands today, and one of them is a tidy lesson in insecure defaults. Langflow, the open-source tool IBM now ships for building AI agent workflows, included an /api/v1/auto_login endpoint that handed a valid superuser token to any unauthenticated caller by default; chained with a code-execution endpoint, that becomes unauthenticated remote code execution, tracked as CVE-2026-9198 (CVSS 9.8) and fixed in version 1.10.1. CISA bundled it with an Apache Tomcat flaw that lets attackers bypass encryption between clustered servers (CVE-2026-34486) and N-able N-central's authentication bypass, CVE-2026-18556, whose incomplete fix Decrypted covered on Wednesday and which is now formally confirmed under active exploitation. None of these are exotic bugs. They are all failures to make the safe configuration the only configuration on offer.

Separately, ExfilSquad, the extortion gang behind the Police National Legal Database breach Decrypted covered on Tuesday, has confirmed something worth sitting with: no ransom was ever demanded for that data. The North East Regional Organised Crime Unit says the gang simply published it, betting that the threat of exposure does more work than a ransom note ever could. ExfilSquad now claims fifteen victims in total, though only the PNLD and Department for Education breaches are confirmed; a claimed theft from Microsoft remains unverified and should be treated as a claim, not a fact. For UK organisations, the lesson from Tuesday still holds: this was never really a ransomware story, and the absence of a ransom note doesn't make it any less of one.

If your organisation is weighing up encrypted services, AI tooling defaults, or how exposed your data really is, get in touch.

More like this

Get the next post by email: subscribe to Decrypted. Double opt-in, unsubscribe any time, or take the RSS feed.

Prefer to listen? Decrypted on Apple Podcasts, or paste the podcast feed into any app.