# FBI was not able to extract data from iPhone 13 in lockdown mode in high profile case

**URL:** https://discuss.privacyguides.net/t/fbi-was-not-able-to-extract-data-from-iphone-13-in-lockdown-mode-in-high-profile-case/35115
**Category:** General
**Tags:** website
**Created:** 2026-02-01T19:04:23Z
**Posts:** 43

## Post 1 by @iHateKYC2 — 2026-02-01T19:04:23Z

We know that iPhones (later than A14 chip) are pretty much secure in BFU. Now the question is, does **Lockdown Mode** completely remove the AFU attack vector or was this phone actually BFU. Either way it sounds like lockdown mode is very useful.:eye::eye:

> **[gov.uscourts.vaed.588772.35.0_1.pdf](https://storage.courtlistener.com/recap/gov.uscourts.vaed.588772/gov.uscourts.vaed.588772.35.0_1.pdf)**
>
> 233.12 KB

“New court record from the FBI details the state of the devices seized from Washington Post reporter Hannah Natanson”

This is high profile espionage case related to leak of TOPSECRET documents, therefore probably all possible tech was used to gain access to the devices.

Page 5:

_In the upstairs of the house, investigators located a powered-off silver MacBook Pro with a black case,_ _ **an Apple iPhone 13** _\*, a Handy branded audio recording device, and a Seagate portable hard drive. See id. ¶ 26. Investigators seized these devices. **The iPhone was found powered on and charging** , and its display noted that the phone was in “Lockdown” mode\*

Page 6:

_The Computer Analysis Response Team (CART) began processing each device to preserve the information therein. The Handy recorder and the Seagate portable drive have been processed, but no review has occurred. See id. ¶ 37._ _ **Because the iPhone was in Lockdown mode, CART could not extract that device** _\*. See id. ¶ 35. Similarly, the personal MacBook Pro could not be imaged yet. See id. ¶ 36. The Garmin watch was not processed before this Cout’s Standstill Order, and no further processing will occur until further order of the Court. See id. ¶ 37\*

[original source](https://www.reddit.com/r/privacy/comments/1qsmy8g/fbi_was_not_able_to_extract_data_from_iphone_13/)

---

## Post 2 by @KathyM — 2026-02-01T21:04:40Z

This should probably be spammed to every single journalist.

Or it’s a litmus test for how serious a journalist is. Is their iPhone on lockdown mode?

---

## Post 3 by @Quantum — 2026-02-02T01:59:25Z

Thank you for yet another fantastic update on iPhone security!

Both her iPhone and her Mac were successful in preventing exploitation of her data.

This shows how much Apple really has taken security extremely seriously the last several years.

Lockdown mode, ADP, and now MIE in new chips have created very robust and very accessible security with a few settings in their devices

---

## Post 4 by @IsItJustMe — 2026-02-02T02:28:34Z

Tinfoil hat time! Lol

On my part that is.

Maybe this kind of news is to instill a false sense of security in users that engage in high risk activities with their phones.

I would never want to put that much faith into a device.

---

## Post 5 by @KathyM — 2026-02-02T04:15:56Z

Would have been more effective to do active surveillance over time. Slowly load malware onto phones, install bugs in car etc.

Sending a message like a quick raid gets you nothing and puts all adjacent journalists on notice to conduct security reviews.

---

## Post 6 by @anonymous544 — 2026-02-02T08:44:56Z

I’m glad you acknowledge that this is very tinfoily.

---

## Post 7 by @phnx — 2026-02-02T09:40:06Z

> [@Quantum](#):
>
> Mac were successful in preventing exploitation of her data.

The personal MacBook was in BFU, so assuming she has a strong password, all bets were off regardless.

> [@IsItJustMe](#):
>
> Tinfoil hat time! Lol
> 
> On my part that is.
> 
> Maybe this kind of news is to instill a false sense of security in users that engage in high risk activities with their phones.

You should try to think critically about this. If there is any case the government will use all available tools, it’s when Top Secret information is on the line. There is no evidence, much less any plausible reason to believe there is some conspiracy to obscure their true capabilities in this case.

---

## Post 8 by @IsItJustMe — 2026-02-02T14:55:44Z

So expressing an off the cuff opinion not labeled as fact is spreading disinformation?

Under my own admission I said it was a bit tin foily. It’s not a statement of fact.

I lack social skills and say stuff all the time not meaning to offend.

Maybe there’s gurus that know fact from fiction. I don’t and wouldn’t put that much trust in a device unless I had to in a last ditch effort. Thankfully I have no need for that sort of protection. :joy:

And your point about thinking critically? I have seen things in different fields of life that were a conspiracy till it wasn’t. So I am naturally going to gravitate some of what things I do know about into this field for reference.

How can I correct my responses as not to spread FUD?

Just keep my thoughts to myself?

---

## Post 9 by @IsItJustMe — 2026-02-02T14:59:23Z

I’m trying to get better with social skills. It’s my admission that “I don’t know”. :+1:

---

## Post 10 by @CarefulMouse — 2026-02-02T16:59:09Z

> and its display noted that the phone was in “Lockdown” mode

A technology literacy gap of the individual who authored this document to the court is possible. AFAIK iPhones do not report on a locked display the status of “lockdown” mode.

Of course, it does appear the phone was in some state that thwarted data recovery efforts, but I’m skeptical we know as fact the device is in “lockdown” mode. If it is - I assume it could only be beneficial.

I’m _ **not** _ suggesting the document intentionally presents false narratives or some other conspiracy to mislead the court and/or public. Simply curious how the government knows the iPhone is in lockdown mode given only the information tendered to the court in this document.

---

## Post 11 by @phnx — 2026-02-02T17:18:01Z

> [@IsItJustMe](#):
>
> So expressing an off the cuff opinion not labeled as fact is spreading disinformation?

My apologies, I think I was too harsh. My intention was simply to demonstrate that your theory doesn’t really stand up to scrutiny imo. I’ve edited my original message.

---

## Post 12 by @IsItJustMe — 2026-02-02T18:02:41Z

You gave me a lot to think about and reflect my own state of mind, intentions, biases and views.

I could see where what I said can be defeatist and discouraging.

The way I was seeing it is, most people including myself have no evidence these devices can’t be cracked perse. I have no evidence of either side.

It’s good to talk about these things and I need to make better replies as to why a say what I am saying.

That said, positive innovations towards privacy is awesome. But I know myself well enough it’s easy to become “Too” confident and let my guard down (if I was in such a situation I needed that much anonymity) fully trusting a device made by companies with a lot of money and are part of the bigger problem with their connections and practices.

Hell, I question my own wisdom running a phone made by one of the most invasive privacy companies on the planet! Lol

But I wouldn’t discourage others because I have no evidence there’s a problem and there may not be a problem. Until I learn more and gain confidence, I can’t in good faith tell someone that something is 100% safe. But we do the best we can with what we have access to.

I guess what I am saying and my intent is, don’t be complacent and have a false sense of security unless one darn well knows what they are doing based on their threat model.

Most people don’t, including myself. Not that I need to hide anything. But are those who do for legitimate reasons.

Yes, fight for privacy and keep learning and growing and keeping up to date as best as possible. But be cautious on the possible limitations of any device or software until one learns more and not just blindly accepting something is private and or anonymous.

That’s part of the reason I made a Post about apps collecting data. Maybe it’s nothing to be worried about for most of us. But for someone else, that’s one more datum point that the device they use is exposed.

I will definitely be willing to talk more about these sort of things if what I am saying is unclear. :slightly_smiling_face:

---

## Post 13 by @Menkork — 2026-02-02T19:27:47Z

Really, it’s not a big deal. From reading this thread, this is how I viewed what just happened.

Go to YouTube or any other video hosting platform that you prefer that might have this, and look up this roughly 3 minute skit called “When a Text Conversation Goes Very Wrong - Key & Peele.”

---

## Post 14 by @IsItJustMe — 2026-02-02T19:41:06Z

Thank you! Enjoyed the video! :joy:

---

## Post 15 by @iHateKYC2 — 2026-02-02T20:56:32Z

I believe lockdown mode shows notifications with a specific hand blocking icon when it blocks something. Maybe that was a indicator. Also, we’re talking about the FBI CART here. They have lot’s of experience and based on public contracts, definitely use Magnet Forensics **Graykey** for initial access into iPhones. Explicitly saying **lockdown mode** vs **unable to extract device** are two different things.

My theories:

USB restriction bypass that graykey uses was blocked by lockdown mode  
USB could’ve been successful but lockdown mode blocked the graykey agent from being deployed.  
FBI assuming things and the new iOS 26 (Wired Accessories) feature is blocking their access.

**extra:**  
FBI consulted with Magnet Forensics support and concluded the phone was in lockdown mode.

This case is very juicy, because if there’s a case where the FBI would want to use all of it’s forensic capabilities, it’s this one, as it includes TS leaks and the president mentioning it.

---

## Post 16 by @Throwaway — 2026-02-02T22:02:47Z

The Garmin reference is interesting. Some of them allow notifications to be received on the watch. I disabled it on mine because it’s all-or-nothing and iOS doesn’t play well with non-Apple Watches.

---

## Post 17 by @camp — 2026-02-03T02:57:08Z

My personal opinion is the walls are closing in for digital forensic companies.

Even if you have exploits for the OS, you still need a way to physically get these exploits onto the device and run it. By hardening the USB port for example, you limit potential attacks.

A few well planned mitigations go a long way, and that is why Apple’s lockdown mode or GrapheneOS’s mitigations are so effective.

---

## Post 18 by @iHateKYC2 — 2026-02-03T03:21:00Z

Some interesting [slides](https://sansorg.egnyte.com/dl/CQDwRrjFF8cc) I found from the SANS DFIR Summit 2025 regarding lockdown mode. It’s mostly about macOS but mentions iOS briefly. Pay close attention to the company mentioned in the last screenshot. :eye:

 ![firefox-0-XVEt-En2vt](https://forum-uploads.privacyguidesusercontent.com/original/3X/f/d/fd4ba1072a4845e9f2413307c7b963a73da13055.png)  
 ![hm4v0d](https://forum-uploads.privacyguidesusercontent.com/original/3X/4/f/4fa2256c86f3b2401a7d0a0a7b012075b20ea779.png)  
 ![firefox-LBwo-Scl-QUB](https://forum-uploads.privacyguidesusercontent.com/original/3X/3/8/38a92d7ae8d9c57cc9d486b0abe5825c309ea9f6.png)  
I remember skimming through some iOS jailbreak discord 2 years ago and I would see people mentioning how some jailbreak devs were employed by Cellebrite, NDA’s, blah blah. Wouldn’t surprise me if Graykey and Cellebrite are using similar injection methods to jailbreaks and having the ex jb devs improve them in the shadows.

 ![image](https://forum-uploads.privacyguidesusercontent.com/original/3X/6/5/654a727434b9b5d14997aed5639fe25b9a075e1d.png)

 ![image](https://forum-uploads.privacyguidesusercontent.com/original/3X/2/4/241037b74ac6540c1c4c96e65c44efbdd702c5b0.png)|

 ![image](https://forum-uploads.privacyguidesusercontent.com/original/3X/4/3/432b31c2488c37b1afad5c8ec9f2054c0f1f009b.png)

---

## Post 19 by @Quantum — 2026-02-04T01:44:54Z

Kinda amazing to think you can go to an Apple Store, buy an iPhone, put it in lockdown mode and be resistant to the best state sponsored remote attacks _and_ the best forensics companies in the world.

Oh and you can watch Netflix and FaceTime your grandma with it too.

---

## Post 20 by @iluvprivacy — 2026-02-04T01:58:44Z

This thread just validated my decision to use my iPhone in lockdown mode all the time. I’ve noticed one website that has issues with it. Is there any way to whitelist the site or change any other setting to make it usable? Not the end of the world since it’s only one site.

Does Android or GrapheneOS have something similar to Lockdown Mode?

---

## Post 21 by @fria — 2026-02-04T02:04:07Z

> [@iluvprivacy](#):
>
> Is there any way to whitelist the site or change any other setting to make it usable?

Yes you can [disable](https://support.apple.com/en-us/105120#:~:text=How%20to%20exclude%20apps%20or%20websites%20from%20Lockdown%20Mode) it for specific sites and apps.

> [@iluvprivacy](#):
>
> Does Android or GrapheneOS have something similar to Lockdown Mode?

Regular Android has a similar feature called [Advanced Protection](https://support.google.com/android/answer/16339980?hl=en) (not to be confused with the [Advanced Protection Program](https://landing.google.com/advancedprotection/) for your Google account) that does a lot of the same things. GrapheneOS already by default has stronger versions of all the protections so a different mode isn’t necessary.

---

## Post 22 by @zbrk — 2026-02-04T12:19:42Z

On some iphones, lockdown mode causes voice call failures unless 2g/3g is kept on. What type of security issues occur in lockdown mode when keeping 2g/3g on.

Is there a fix?

What’s more secure :

lockdown mode with 2g/3g on

or

lockdown mode off

---

## Post 23 by @Shampoo — 2026-02-04T14:07:31Z

> [@zbrk](#):
>
> lockdown mode with 2g/3g on

This is the more secure option because it reduces the attack surface in other areas as well. You should not be using 2g/3g at all though. It’s unencrypted. If something isn’t working because it’s disabled that’s a good thing.

Edit: figured I should specify that 2g/3g are _t_e_chnically_ encrypted but they use encryption that was broken years ago. More info here: [Your Phone Is Vulnerable Because of 2G, But it Doesn't Have to Be | Electronic Frontier Foundation](https://www.eff.org/deeplinks/2020/06/your-phone-vulnerable-because-2g-it-doesnt-have-be)

---

## Post 24 by @iluvprivacy — 2026-02-04T14:30:28Z

How do I disable 2G/3G on iOS?

---

## Post 25 by @Shampoo — 2026-02-04T14:54:35Z

Enable lockdown mode. There’s no other way to do it.

---

## Post 26 by @Throwaway — 2026-02-04T16:29:55Z

Where do you live? In the USA those networks no longer exist.

---

## Post 27 by @iluvprivacy — 2026-02-04T17:27:18Z

That wasn’t specific to the US because I also travel, so 2G/3G may still be a problem.

---

## Post 28 by @Quantum — 2026-02-04T21:14:20Z

But devices like Stingrays can still exploit them if they are enabled on the device.

---

## Post 29 by @iluvprivacy — 2026-02-04T22:19:53Z

That’s why I want to shut them down. I want to minimize my risk as much as possible.

---

## Post 30 by @KathyM — 2026-02-05T02:26:33Z

An update if people are interested - They were able to unlock her macbook using her fingerprint

> Natanson was reminded the FBI has authority to use her biometrics to unlock the laptop and Natanson repeated that she does not use biometrics on her devices. Natanson was told she must try, in accordance with the authorization in the warrant. The FBI assisted Natanson with applying her right index finger to the fingerprint reader which immediately unlocked the laptop.

> **[FBI stymied by Apple's Lockdown Mode after seizing journalist's iPhone](https://arstechnica.com/tech-policy/2026/02/fbi-stymied-by-apples-lockdown-mode-after-seizing-journalists-iphone/)**
>
> Post reporter was compelled to unlock MacBook Pro with fingerprint, however.

---

## Post 31 by @Quantum — 2026-02-05T02:56:31Z

> [@KathyM](#):
>
> [FBI stymied by Apple's Lockdown Mode after seizing journalist's iPhone - Ars Technica](https://arstechnica.com/tech-policy/2026/02/fbi-stymied-by-apples-lockdown-mode-after-seizing-journalists-iphone/)

Interesting. This means the Mac was already powered on and logged into when they seized it as, just like with iPhones, the first login after being powered on or restarted requires a password. If her fingerprint unlocked the Mac it means she had already logged into it before it was seized.

Also if they resorted to the fingerprint, does that mean they could not access it otherwise even though it was powered on? Or did they not even attempt exploitation until trying the fingerprint?

**Edit Substantive update:** Just finished reading the entire article, turns out there are **two MacBook’s**. One owned by the Washington Post and one personally owned by the reporter. The personal laptop was powered off and they have been unable to access it. The Post-owned MacBook was powered on when seized and that is what was unlocked with her finger print.

---

## Post 32 by @zbrk — 2026-02-11T11:53:59Z

The problem is that voice calls fail in lockdown mode unless 2g/3g toggle is on. I think this started happening in iOS 26

Is there a way to turn 2g/3g off, use lockdown mode and still be able to make voice calls in 4g and use USB hotspot.

---

## Post 33 by @iluvprivacy — 2026-02-11T12:36:52Z

I have been able to make voice calls with WiFi Calling with lockdown mode on.

---

## Post 34 by @zbrk — 2026-02-11T13:06:28Z

can you make regular voice calls over 4g?

---

## Post 35 by @iluvprivacy — 2026-02-11T13:16:20Z

I don’t understand what you mean by 4G and use USB hotspot. I have my iPhone on WiFi all the time and it’s connected to any WiFi network to make WiFi calls. Your carrier has to support it in order for it to work.

---

## Post 36 by @zbrk — 2026-02-11T13:30:04Z

making calls over the cell network normally, with wifi off.

There may be a bug on some iphones. In LD, Voice calls fail and signal bars are off in lockdown mode.

Data and USB hotspot work.

---

## Post 37 by @Quantum — 2026-02-16T20:45:45Z

This seems to be something odd specific to your phone or possibly your carrier.

I’ve been daily driving lockdown mode since it was released and have had no issues with voice calls either via 4g/LTE, 5G, or WiFi.

---

## Post 38 by @iluvprivacy — 2026-02-17T22:58:32Z

Yep, same here. No issue at all. It’s very seamless and almost like as if my phone wasn’t even hardened at all.

I still don’t get why 5G is less secure than 4G. Very surprised with that info!

---

## Post 40 by @camp — 2026-02-18T16:21:21Z

> [@Quantum](#):
>
> does that mean they could not access it otherwise even though it was powered on

If your macbook has an M1 or newer apple silicon processor, it can’t be forensically analyzed even if powered on - unless they have the password.

To recover a macbook typically you insert an external drive, and boot from that drive. However user credentials are required to make the change in the settings to allow for this.

I believe the ram is encrypted by the secure enclave on M1 or above macbooks as well, meaning a ram dump isn’t possible.

---

## Post 41 by @iluvprivacy — 2026-02-19T00:49:59Z

It doesn’t have the new MTE feature that the new A19 and I believe the M5 has. If you’re a journalist and travel a lot, I would probably ensure that my iPhone and MacBook have it.

---

## Post 42 by @iHateKYC2 — 2026-03-18T15:34:16Z

With the release of the MacBook Neo, people now have the option to use the non Touch ID model which hasn’t existed on MacBook for years. Even though Touch ID for unlock is optional it’s so tempting to use when you have the sensor available.

---

## Post 43 by @KathyM — 2026-03-19T13:32:40Z

I wish biometric unlocks were protected by the law. Or at least supplemental to a shorter pin/password.
