Spyware attacks against journalists, human rights activists and political dissidents are no longer rare and exotic. At the beginning of 2025, WhatsApp warned about 90 users – many of them journalists and members of civil society in Europe – of being targeted by the Israeli spyware company Paragon Solutions. Months later, Apple sent threatening notifications to a new group of iOS users; forensic analysis confirmed bothboth journalists were hit by Paragon’s Graphite spyware using a zero-click attack, meaning you didn’t even have to tap a link to be compromised. These are not isolated incidents. They are the norm.
Over the past 15 years, security researchers have documented countless cases of government hackers targeting and successfully compromising journalists, human rights defenders, critics, and political opponents.
These attacks rely on expensive, sophisticated, and stealthy tools that allow their operators to hack and install spyware on computers, especially smartphones, which store virtually all information about a person’s daily life.
Spyware gives its operators virtually complete access to the target’s device and data. Government spies can record phone calls, steal chat messages, access photos, tap the device’s camera and microphone to record ambient sounds and nearby conversations. Spyware also typically tracks a person’s real-time location.
In response to these attacks, tech giants are now providing their users with better protection. In particular, Apple, Google, and Meta offer plug-in features specifically designed to counter targeted spyware attacks.
In general, these features add extra protection, sometimes by disabling or limiting some common features. It’s a trade-off, but having used these for a long time, I’ve never found them to be too heavy or annoying to use.
Tech companies, security researchers who have studied spyware for years, and we at TechCrunch recommend using these features if you suspect you might be the target of government surveillance because of who you are or what you do. Even if you’re not, these security features will better protect your data from falling into the wrong hands.
No security measure is perfect, and it’s a constant effort to prevent security flaws. Spyware makers find new ways to hack into phones and services, and software makers learn from these attacks and respond. Rinse and repeat.
But this does not mean that these functions are not worth using. On the contrary; the effectiveness of these features has been proven.
“These features are free, easy to enable, and the best defense we have today against modern spyware,” he said. Runa Sandvika security researcher who has worked to protect journalists and other at-risk communities for more than a decade. “If features get in the way of something you need to do, you can easily turn them off again, meaning it costs less to turn them on and test them.”
A summary of these features and how to turn them on.

Apple’s lock mode
Apple’s lock mode is available on all Apple devices, including iPhones. Apple says when Lock mode when activated, “your device will not function as it normally does.” In return for this inconvenience, your device will be more secure.
There is evidence that lockdowns have helped in the past. Citizen Lab found the Lockdown mode stopped a spyware attack It is implemented by NSO Group’s Pegasus program. Apple said in March never discovered Successful attack on an Apple device with Lock Mode enabled.
What is this Lock mode Changes to your device when you turn it on:
- Attachments received in iMessage are blocked by default, except for some images, videos, and audio.
- Links and previews in iMessage are blocked and appear as unrelated web addresses. (You can copy and paste the links into Safari or another browser if you like.)
- Fonts, some images, and some web technologies are blocked when browsing in Safari.
- Incoming FaceTime calls are blocked if you haven’t contacted that person in the past or in the last 30 days.
- Screen sharing, content sharing via SharePlay, and Live Photos are not available.
- Incoming invitations for Apple services are blocked unless you have previously invited that person.
- The focus function “and any associated status will not work as expected.”
- Game Center is disabled.
- Location information is removed when you share photos.
- “Shared albums have been removed from the Photos app and new Shared Album invites are blocked.”
- You must unlock the device to connect it to an accessory or computer. When connecting a Mac with Apple processors to the accessory, the computer must be unlocked and you must confirm the connection with your passcode.
- You cannot automatically connect to open or public Wi-Fi networks, and you will be disconnected from any unsecured Wi-Fi networks you were previously connected to before turning on Lockdown Mode.
- Your phone will not be able to connect to 2G or 3G mobile networks.
- You cannot install configuration profiles or register a device in Mobile Device Manager.
To turn on Lock Mode, go to Settings, then Privacy & Security, and scroll down to Lock Mode. After enabling the feature, your Apple device will restart.
I’ve used Lockdown for years. I haven’t felt that way in a while, although I’ve found some websites to be a bit confusing at first. You can also disable the feature by selecting Lock mode for specific websites and apps without turning it off completely. There are some quirksbut I’m used to them too.

Google’s Advanced Protection Program
Google launched it Advanced Protection Program In 2017. This feature is designed to make your Google account more resistant to all kinds of malicious hackers.
Advanced Protection Software includes the following features:
- Restricts certain third-party services and applications from accessing your Google account, and only with your permission.
- Enables “Gmail Deep Scans” which scans your incoming emails for phishing attacks and malicious content.
- Enables Google Safe Browsing in Chrome, which warns users who visit dangerous sites or download dangerous files.
- On Android, you can only install apps and games from legitimate app stores.
- If someone tries to sign in to your account, Google takes extra steps to verify that it’s really you.
Go here to enable Advanced Protection its official page and click “Start”. This will prompt you to sign in to your Google account. Follow the instructions there.
First, you should add a physical security key (or software key) as an additional verification factor in addition to your passwords. You’ll also need to add a recovery phone and recovery email to your account, or use a backup key or security key.

Android Advanced Protection Mode
Submitted last year and possibly inspired by Apple’s Lockdown mode, Android Advanced Protection Mode It brings similar protections to Google’s mobile operating system.
Android’s Advanced Protection Mode provides the following security features:
- Enables Google Play Protect, which protects against malware and unwanted apps and scans all apps for “malicious behavior.”
- Apps from unknown sources cannot be installed, and updates to previously installed apps from unknown sources will be blocked from running.
- Enables Memory Tagging Extension (MTE) on supported devices. MTE is a hardware-enforced feature that protects against certain types of vulnerabilities.
- The device automatically locks if it detects suspicious activity that is a “sign of theft,” such as sudden and rapid movement. It relies on data from the device’s motion sensors, Wi-Fi and Bluetooth.
- The device is automatically locked if it is offline for a long time.
- If the phone is locked for 72 hours, the device automatically reboots, making it difficult to extract data using law enforcement tools designed to unlock phones, such as those made by Cellebrite.
- When the device is locked, USB connections are blocked.
- Google scans for “unsolicited and potentially harmful messages”.
- Links sent via Messages from unknown users will be flagged.
- Connection to 2G networks is blocked.
- Google will identify spam callers.
- You will be able to automatically screen incoming calls and reject spam calls. (Only available here certain regions.)
- Enables Android Safe Browsing, which protects against malicious websites.
- Chrome will automatically apply HTTPS encryption for all sites.
- Some JavaScript functions are disabled, reducing the browser’s attack surface for potential vulnerabilities.
- You can also enable Intrusion Logging, an optional feature helps researchers investigate spyware attacks.
To enable Advanced Protection Mode on your Android device, go to Settings, then Security & Privacy, and under Other Settings, tap Advanced Protection, then tap Device Protection.

WhatsApp Strict Account Settings
WhatsApp is used by more than 3 billion people, including those at the intersection of competent government agencies.
The demand for WhatsApp targeting hack tools is so high that it is in demand exploits can cost millions of dollars – and they work. WhatsApp in 2019 was caught in a hacking campaign By NSO Group targeting around 1200 users. At the beginning of last year, WhatsApp conducted another spy operation It trapped about 90 users in Europe.
In response, WhatsApp was launched earlier this year Strict Account Settingsis an opt-in feature that, depending on the operating system, enables some privacy and security controls.
Strict Account Settings on Android and iOS enable the following features:
- Two-step verification.
- Safety noticesalerts users when a contact changes their phone number or reinstalls WhatsApp, or when an attacker takes control of their account.
- Blocks attachments and media (images and videos) from unknown senders by default.
- Link previews are disabled.
- Calls from unknown numbers are silenced.
- Your IP address is hidden in calls.
- Your profile information and activity, such as when you were last seen online, your profile picture and About information are hidden from people who are not members of your contacts or pre-created group.
- Only contacts or members of a pre-created group can add you to a group chat.
To turn on the feature, use your primary device and go to Settings, then Privacy, then scroll to the Advanced option and turn it on.
When you purchase through links in our articles, we may earn a small commission. This does not affect our editorial independence.





