Published Oct 01, 2026 by Xiph
A compromised phone holds other people’s secrets too. For clients, colleagues, sources and family members, the consequences can begin on a device they have never touched — and continue long after its owner discovers the intrusion.
In January 2022, the Citizen Lab and Access Now reported that Pegasus spyware had successfully infected the phones of 35 journalists and members of civil society in El Salvador. The infections spanned July 2020 to November 2021. Among those affected were staff at the investigative outlet El Faro.
Thirty-five is a count of people whose phones were found to be infected. It cannot tell us how many other people’s information was exposed through their conversations, documents and contacts.
Consider what a reporter carries. Messages from a source who has asked for anonymity. Photographs of documents. An editor’s questions. Family arrangements mixed into the same working day. A phone puts those relationships within reach of the person holding it. Spyware can put them within reach of someone else.
The person named in a forensic report is where the investigation starts. The circle of people who may need protection extends much further.
Your conversation lives on someone else’s phone
Imagine sending a sensitive message to your solicitor. You use an encrypted app, keep your phone updated and protect your accounts carefully. A readable copy still has to appear on your solicitor’s device. If sufficiently capable spyware controls that device, your precautions cannot stop it reading what your solicitor can read.
End-to-end encryption protects a conversation between its endpoints. The phones at those endpoints must decrypt it for the participants. Compromising a phone can therefore expose messages without breaking the encryption that protected their journey.
Depending on the spyware and the access it obtains, exposure can include stored messages, contacts, photographs and location information. Capabilities documented for Pegasus also include activating a microphone or camera. A meeting may therefore put people at risk even when they have exchanged no electronic messages with the phone’s owner.
The distinction matters: appearing in someone’s contacts does not mean your own phone has been infected. Your information can be compromised through their copy. A group conversation can expose several participants through a single member’s device.
Nor does proof of infection establish that every available file was stolen. Investigators may recover evidence of an intrusion without a complete record of what the operator collected. That uncertainty has to inform the response; it cannot be treated as proof that everyone else’s information stayed private.
The client who was never the target
The danger to professional confidentiality has already reached a courtroom.
In a 2021 judgment concerning Princess Haya and Sheikh Mohammed bin Rashid Al Maktoum, the High Court in England found that Pegasus had successfully compromised Haya’s phone. It also found that her solicitors, Baroness Fiona Shackleton and Nick Manners, had probably been successfully hacked.
The judgment was careful about the limits of the evidence: without the relevant network logs, it was impossible to know what information, if any, had been harvested from the solicitors’ phones. That qualification is essential. The court established a serious intrusion without claiming to possess an inventory of stolen legal advice.
The wider lesson applies to any professional handling other people’s affairs. A solicitor may hold information about several unrelated clients. An accountant may discuss business purchases and family finances on one handset. An executive assistant may have access to an entire leadership team’s movements.
Compromising that person can expose conversations far beyond the matter that attracted the attacker. Clients may have chosen their adviser carefully, complied with every security request and still have no visibility of the intrusion. Their confidentiality depends partly on decisions made inside another organisation.
The circle can become the route in
People around a target can also become deliberate targets themselves.
In July 2026, Amnesty International’s Security Lab published an analysis drawing on internal NSO Group material disclosed in the WhatsApp litigation. The documents described “close-circle infection”: targeting people connected to someone who is difficult to reach directly, including where that person avoids smartphones or is particularly security conscious.
That turns proximity into intelligence value. A partner may know travel plans. A colleague may receive draft negotiations. A friend may hear concerns that never appear in a corporate email. Someone with a modest public profile can hold information an attacker wants about a much more prominent person.
For organisations, protecting the chief executive while ignoring the assistant or external adviser leaves a predictable gap. For families, it means security conversations should include the people who arrange daily life. Their involvement should bring support and practical help. Treating them as the weak link simply shifts responsibility onto people who never chose the risk.

When a breach changes what people will say
The most immediate consequence may be exposure of a name or a conversation. What follows can be harder to repair.
A source who suspects a reporter’s phone has been monitored may stop speaking. A client may withhold information their adviser needs. Colleagues can become reluctant to discuss mistakes or raise concerns. The resulting silence can damage the work long after the compromised device has been replaced.
The personal consequences depend on the circumstances. A conversation may reveal a relationship, a medical concern or plans to leave an abusive partner. Even an apparently mundane calendar entry can become dangerous when it tells the wrong person where somebody will be.
These are possible consequences, not an account of what happened in every documented spyware case. They explain why counting infected devices is an inadequate measure of harm. The people with the most to lose may never receive a threat notification, because their own phones were never attacked.
Protection has to include the people around you
Keep the scale of the threat in perspective. Apple describes mercenary spyware as exceptionally sophisticated, expensive attacks directed at a small number of people. Most users will never be targeted. The case for additional protection is strongest where someone’s work, relationships or circumstances create a credible risk.
For those people, start by mapping where sensitive conversations actually happen. Include advisers, assistants and relevant family members. Agree how confidential material will be exchanged, who needs access and how an urgent request will be verified. A policy confined to company email misses conversations that have moved into personal messaging.
Continue using reputable end-to-end encrypted communications. Keep devices and apps updated. For people facing sophisticated targeting, Apple’s Lockdown Mode reduces exposure by restricting certain features; its limitations need to be understood and planned around. It is an additional protection, not a guarantee.
Reduce the history available on a travelling handset. Keep necessary business records in appropriately controlled systems and avoid unnecessary copies in chat threads and downloads. Disappearing messages can reduce retained history, but they cannot prevent an active intruder capturing messages while they are readable. Recordkeeping and legal preservation requirements still apply.
Make these arrangements easy enough for the whole group to follow. Supplying a suitable device, helping an adviser configure it or agreeing a safer process for sensitive meetings is more useful than expecting everyone to become a mobile security specialist.
A suspected compromise is a shared incident
If a credible spyware alert arrives, use a separate, trusted device to seek specialist assistance. Apple recommends expert help for recipients of its threat notifications. Obtain advice promptly on containment and preserving evidence before making changes that could erase useful forensic traces.
The investigation should consider who else’s information was accessible during the suspected period. Review conversations and attachments, group memberships and business access. Identify people who could face immediate physical, professional or financial harm, while keeping the information gathered during that assessment tightly restricted.
Contact those people through a safer channel with clear information about what is known and what remains uncertain. Sending a detailed incident discussion into the potentially compromised group chat may reveal the response to the intruder.
Australian organisations covered by the Privacy Act also need to assess their notification obligations. Under the Notifiable Data Breaches scheme, an eligible breach generally requires notification to the OAIC and affected individuals where serious harm is likely and remedial action has not prevented that risk. The assessment concerns people’s information, including information on a phone.
A final word
A phone is personal equipment with shared consequences. It carries words entrusted to its owner by people who may know nothing about the threats facing them.
The sensible response is to protect those relationships together. Choose communications carefully, limit unnecessary copies and make sure an incident response looks beyond the person whose handset was compromised. The people on the other side of the conversation deserve a place in the plan.
Xiph Cyber helps individuals and organisations assess digital exposure, strengthen mobile security and establish safer communications. If your work involves sensitive clients, confidential sources or people who depend on your discretion, get in touch to discuss protection that accounts for the wider circle.
Further reading
Posted in: Security