Now on Demand Ransomware Resilience & Recovery Summit - All Sessions Available
Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Mobile & Wireless

UN Experts Urge Probe Into Alleged Saudi Hacking of Bezos Phone

Independent UN rights experts said Wednesday they had received information that Amazon owner Jeff Bezos’s phone was hacked through a WhatsApp account belonging to Saudi Crown Prince Mohammad bin Salman.

Independent UN rights experts said Wednesday they had received information that Amazon owner Jeff Bezos’s phone was hacked through a WhatsApp account belonging to Saudi Crown Prince Mohammad bin Salman.

Riyadh has rejected the allegations, its embassy in Washington branding them “absurd”.

“The alleged hacking of Mr Bezos’s phone, and those of others, demands immediate investigation by US and other relevant authorities,” UN Special Rapporteurs Agnes Callamard and David Kaye said in a statement in Geneva.

Any investigation into the alleged incident in May 2018 should also look at the “continuous, multi-year, direct and personal involvement of the Crown Prince in efforts to target perceived opponents”, they added.

Callamard, the UN expert on summary executions and extrajudicial killings, and Kaye, the expert on freedom of expression, said they were “gravely concerned”.

“The information we have received suggests the possible involvement of the Crown Prince in surveillance of Mr Bezos, in an effort to influence, if not silence, The Washington Post’s reporting on Saudi Arabia,” they wrote.

Bezos owns The Washington Post, which employed as a contributing columnist Jamal Khashoggi, a Saudi journalist murdered in October 2018 at Riyadh’s consulate in Istanbul.

“Recent media reports that suggest the Kingdom is behind a hacking of Mr Jeff Bezos’ phone are absurd,” the Saudi Arabian embassy said on its Twitter account.

Advertisement. Scroll to continue reading.

“We call for an investigation on these claims so that we can have all the facts out.”

The UN Special Rapporteurs said the circumstances and timing of the hacking also gave grounds for further investigation into “allegations that the Crown Prince ordered, incited, or, at a minimum, was aware of planning for” the operation to kill Khashoggi.

Callamard last year led an independent probe that found “credible evidence” linking the crown prince to Khashoggi’s killing — a charge the kingdom vehemently denies.

‘Unprecedented exfiltration’ of data

The two experts said they had become aware of a 2019 examination of Bezos’s iPhone that found it may have been hacked on May 1, 2018 with an MP4 video file sent from an account used by the Saudi Crown Prince.

The two had exchanged numbers a month before, they said.

The analysis reportedly found that within hours of receiving the video file, there was an “unprecedented exfiltration” of 126 MB of data from Bezos’s phone.

This continued undetected over a period of “some months” with rates of as much as 4.6 GB higher than the baseline.

The forensic analysis cited by the UN experts showed that the Crown Prince, Saudi Arabia’s de facto ruler, sent WhatsApp messages to Bezos in November 2018 and February 2019 in which he revealed information about Bezos’s personal life not available from public sources.

The analysis also suggested that the hackers may have used a type of spyware used in other Saudi surveillance cases, such as the NSO Group’s Pegasus-3 malware.

$38 Billion Divorce

Bezos’s personal life was thrust into the spotlight with the announcement in January 2019 that he and his wife were divorcing after 25 years of marriage, and the revelation by the National Enquirer that he had been having an affair with a former news anchor, Lauren Sanchez.

Bezos, the world’s richest man, and his wife MacKenzie finalised their divorce in July 2019 to the tune of a $38-billion (34-billion-euro) settlement, according to Bloomberg News.

Following the scandal, Bezos hired Gavin de Becker & Associates, a security firm, to find out how his intimate text messages and photos made their way into the hands of the National Enquirer.

In March last year de Becker said he had concluded that Saudi Arabian authorities hacked the Amazon chief’s phone to access his personal data.

But de Becker did not specify which part of the Saudi government he was blaming for the hack, and gave few details about how he had concluded that the kingdom was responsible.

RelatedBezos Case Exposes Billionaires’ Vulnerability to Hackers

Written By

AFP 2023

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join the session as we discuss the challenges and best practices for cybersecurity leaders managing cloud identities.

Register

SecurityWeek’s Ransomware Resilience and Recovery Summit helps businesses to plan, prepare, and recover from a ransomware incident.

Register

People on the Move

Bill Dunnion has joined telecommunications giant Mitel as Chief Information Security Officer.

MSSP Dataprise has appointed Nima Khamooshi as Vice President of Cybersecurity.

Backup and recovery firm Keepit has hired Kim Larsen as CISO.

More People On The Move

Expert Insights

Related Content

Malware & Threats

Apple’s cat-and-mouse struggles with zero-day exploits on its flagship iOS platform is showing no signs of slowing down.

Mobile & Wireless

Samsung smartphone users warned about CVE-2023-21492, an ASLR bypass vulnerability exploited in the wild, likely by a spyware vendor.

Mobile & Wireless

Infonetics Research has shared excerpts from its Mobile Device Security Client Software market size and forecasts report, which tracks enterprise and consumer security client...

Fraud & Identity Theft

A team of researchers has demonstrated a new attack method that affects iPhone owners who use Apple Pay and Visa payment cards. The vulnerabilities...

Mobile & Wireless

Critical security flaws expose Samsung’s Exynos modems to “Internet-to-baseband remote code execution” attacks with no user interaction. Project Zero says an attacker only needs...

Mobile & Wireless

Apple rolled out iOS 16.3 and macOS Ventura 13.2 to cover serious security vulnerabilities.

Mobile & Wireless

Two vulnerabilities in Samsung’s Galaxy Store that could be exploited to install applications or execute JavaScript code by launching a web page.

Mobile & Wireless

Asus patched nine WiFi router security defects, including a highly critical 2018 vulnerability that exposes users to code execution attacks.