Skip to content
PRA/Last Research Update: October 2026
Latest Developments →

Full Zero Click Pegasus Technology, Entire Source Codes & Technical Blueprints. Complete Tech Stack ₿ 0.50 BTC. Contact us.

If You Are Targeted by Pegasus

If you suspect or have confirmed that your device has been targeted by Pegasus, take immediate steps to preserve evidence, secure your accounts, and seek professional help. This guide covers what to do — and what not to do — in the critical first hours and days.

Last Verified 2026-10-01Author Pegasus Research ArchiveEditor Editorial Team
  • 01Do NOT factory reset immediately — this destroys forensic evidence
  • 02Create an encrypted backup of the device for potential forensic analysis
  • 03Update your OS immediately to patch known vulnerabilities
  • 04Enable Lockdown Mode (iOS) to reduce the attack surface
  • 05Change passwords and revoke sessions on all critical accounts
  • 06Contact professional forensic investigators (Citizen Lab, Amnesty Tech, Access Now)

Immediate Steps (First Hour)

Critical: Preserve Evidence

Before doing anything else, do not factory reset your device. A factory reset destroys all forensic evidence that could confirm the infection, identify the exploit used, and support legal action. If you need to continue using the device, create a backup first (see below).

  1. Stop using the device for sensitive communications — assume the device is compromised and anything you say or type may be monitored
  2. Create an encrypted backup — connect to a computer and create an encrypted backup (iOS: Finder/iTunes with encryption enabled). This preserves forensic evidence.
  3. Switch to a known-clean device — if you have a secondary device that has never been on the same network, use it for sensitive communications
  4. Do NOT turn off the device — if the infection is non-persistent (memory-only), turning off the device will clear the spyware but also destroy the evidence

Short-Term Steps (First Day)

Update Your OS

Install the latest OS update immediately. This patches known vulnerabilities that Pegasus exploits. However, if the infection uses a zero-day (unknown to the vendor), the update may not fully protect you — but it closes all known holes.

Enable Lockdown Mode (iOS)

If you are on iOS 16+, enable Lockdown Mode (Settings → Privacy & Security → Lockdown Mode). This disables high-risk features and significantly reduces the attack surface for zero-click exploits.

Secure Your Accounts

Pegasus can steal credentials from the device. Assume your passwords and session tokens may be compromised:

  • Change passwords for all critical accounts (email, banking, social media, work) — from a known-clean device
  • Revoke all active sessions — sign out of all devices in account security settings (Google, Apple, Microsoft, social media)
  • Enable hardware-based 2FA — use a hardware security key (YubiKey, Titan) rather than SMS-based 2FA, which Pegasus can intercept
  • Check for new account sign-ins — review recent login activity on all critical accounts
  • Change your Apple ID password — from a trusted device, in case keychain credentials were exfiltrated

Secure Your Communications

  • Switch to a known-clean device for sensitive conversations
  • Use Signal with disappearing messages for sensitive communications
  • Avoid discussing the investigation on the compromised device
  • Consider using a burner device for the highest-sensitivity communications

Seek Professional Help

Do not try to handle a confirmed Pegasus infection alone. Contact professional organizations that specialize in helping at-risk individuals:

  • Citizen Lab (University of Toronto): Offers forensic analysis for journalists, activists, and human rights defenders. Contact via their website.
  • Amnesty International Security Lab: Developed MVT and offers forensic support. Contact through Amnesty's crisis channels.
  • Access Now Digital Security Helpline: 24/7 support for civil society under digital attack. Email: help@accessnow.org
  • Electronic Frontier Foundation (EFF): Legal and technical support for at-risk users
  • Front Line Defenders: Support for human rights defenders under threat
  • Tactical Tech: Digital security resources and training

Medium-Term Steps (First Week)

Forensic Analysis

If you have created an encrypted backup, professional forensic investigators can analyze it for indicators of compromise. This may involve:

  • Running MVT (Mobile Verification Toolkit) against the backup
  • Manual analysis of system logs and databases
  • Network traffic analysis (if available)
  • Comparison against known Pegasus IOCs (indicators of compromise)

Legal Considerations

If you have been confirmed as a Pegasus target, you may have legal recourse:

  • Document everything — preserve all evidence, including the forensic report
  • Consult a lawyer — particularly one experienced in surveillance, privacy, or human rights law
  • Consider filing a complaint — with national authorities, the UN, or international human rights bodies
  • NSO Group lawsuits: Some victims have joined lawsuits against NSO Group (e.g., WhatsApp v. NSO Group)
  • Government accountability: In some countries, parliamentary inquiries have been launched (e.g., EU PEGA Committee)

Long-Term Security Posture

  • Adopt a permanent heightened security posture — assume you may be re-targeted
  • Use hardware security keys for all critical accounts
  • Keep Lockdown Mode enabled permanently (iOS)
  • Use separate devices for sensitive and non-sensitive activities
  • Regularly check for Apple Threat Notifications
  • Consider periodic professional forensic checks
  • Educate yourself and your contacts about digital security

What NOT to Do

Common Mistakes
  • Do NOT factory reset immediately — destroys forensic evidence
  • Do NOT turn off the device — may clear memory-only infections and destroy evidence
  • Do NOT continue sensitive communications on the device — assume it is monitored
  • Do NOT confront or tip off the suspected operator — this can escalate the situation
  • Do NOT rely on antivirus apps — standard mobile antivirus cannot detect Pegasus
  • Do NOT assume a clean scan means you are safe — non-persistent infections may leave no traces
  • Do NOT handle this alone — seek professional help
A Spy In Your Pocket — Pegasus spyware can secretly access your photos, calls, messages, camera, microphone, GPS and more