Maker of 'GrayKey' iPhone Unlocking Box Suffers 'Brief' Data Breach, Receives Money Demands

Grayshift, the company that makes the GrayKey iPhone unlocking boxes that have been sold to multiple law enforcement agencies across the United States, recently suffered a data breach that allowed hackers to access a small portion of the GrayKey code, reports VICE's Motherboard.

graykey1


Last week, unknown hackers leaked portions of the GrayKey code and demanded two bitcoin from Grayshift with the threat of additional data being leaked. According to Motherboard, the code in question "does not appear to be particularly sensitive," but Grayshift did confirm that a "brief" data leak had occurred.

Indeed, Grayshift told Motherboard in a statement "Due [to] a network misconfiguration at a customer site, a GrayKey unit's UI was exposed to the internet for a brief period of time earlier this month."

"During this time, someone accessed the HTML/Javascript that makes up our UI. No sensitive IP or data was exposed, as the GrayKey was being validation tested at the time. We have since implemented changes to help our customers prevent unauthorized access," the statement added.

Grayshift says that no sensitive IP or data was exposed, and Motherboard confirms that the leaked code appears to be related to the user interface that displays messages on the GrayKey, but it's clear that Grayshift security is not airtight, raising questions about what kind of data might be accessible to hackers.

The GrayKey is a small, portable gray box equipped with dual Lightning cables. An iPhone is plugged into one of the cables to install proprietary software that's able to guess the passcode to an iPhone in as little as a few hours to a few days, based on the strength of the passcode.

GrayKey, which is priced starting at $15,000, can crack the latest iPhones running modern versions of iOS, including iOS 11. While the box is designed to provide law enforcement officials with easy access to locked iPhones for criminal investigations, there have been fears that the GrayKey technology could fall into the wrong hands.

The box has been sold to multiple law enforcement agencies across the country, and the data breach that Grayshift suffered, however inconsequential, is not at all reassuring for those who are worried about the security of the GrayKey boxes. The underlying functionality that allows the GrayKey to crack iPhones could be discovered and replicated, and the GrayKey boxes themselves are said to download data from cracked iPhones, which could also be at risk in a data breach.

According to Motherboard, Grayshift has not paid the extortionists their two bitcoin fee, as the Bitcoin addresses provided have received no funds. An additional Bitcoin address promising to provide interested parties with GrayKey information has also not received funds.

Grayshift says that "changes" have been made to help customers prevent unauthorized access to GrayKey boxes in the future, but Motherboard discovered another exposed GrayKey device broadcasting similar code.

Using the computer search engine Shodan, Motherboard found a seemingly exposed GrayKey device, broadcasting similar chunks of code to the open internet.

"To brute force a complex alphanumeric passcode, upload a custom password dictionary. If a dictionary is not uploaded, GrayKey will not attempt to brute force custom alphanumeric passcodes," one section of the apparent device's code reads.

The technology used for the GrayKey will likely be outdated at some point through updates to the iOS operating system, but as far as we know now, it's still functional for even the latest versions of iOS and the newest iOS devices, including the iPhone X.

Those worried about GrayKey and similar technologies can implement stronger and more secure passcodes and passwords that are more difficult to guess through brute forcing to prevent these kinds of tools from working. A 6-digit numeric passcode, Apple's default, can be guessed in as little as 11 hours, but an 8-digit numeric code can take over a month, while a 10-digit numeric code can take years.

Security experts recommend alphanumeric passcodes that are at least seven characters long with numbers, upper and lowercase letters, and symbols included. The longer the password, the more secure it is from GrayKey-style guessing methods. For more information on Grayshift's data breach, check out Motherboard's full report.

Note: Due to the political nature of the discussion regarding this topic, the discussion thread is located in our Politics, Religion, Social Issues forum. All forum members and site visitors are welcome to read and follow the thread, but posting is limited to forum members with at least 100 posts.

Popular Stories

iPhone 17 Pro Blue Feature Tighter Crop

iPhone 17 Pro Launching in Three Months With These 12 New Features

Saturday June 14, 2025 5:45 pm PDT by
The iPhone 17 Pro and iPhone 17 Pro Max are three months away, and there are plenty of rumors about the devices. Below, we recap key changes rumored for the iPhone 17 Pro models as of June 2025:Aluminum frame: iPhone 17 Pro models are rumored to have an aluminum frame, whereas the iPhone 15 Pro and iPhone 16 Pro models have a titanium frame, and the iPhone X through iPhone 14 Pro have a...
apple watch ultra 2 new black

Apple Watch Ultra 3 Finally Coming After Two-Year Hiatus

Monday June 16, 2025 8:45 am PDT by
Apple will finally deliver the Apple Watch Ultra 3 sometime this year, according to analyst Jeff Pu of GF Securities Hong Kong (via @jukanlosreve). The analyst expects both the Apple Watch Series 11 and Apple Watch Ultra 3 to arrive this year (likely alongside the new iPhone 17 lineup, if previous launches are anything to go by), according to his latest product roadmap shared with...
apple watch ultra snow

6 Features Coming to the Apple Watch Ultra 3

Tuesday February 25, 2025 9:00 am PST by
The Apple Watch Ultra 3 is expected to launch later this year, arriving two years after the previous model with a series of improvements. While no noticeable design changes are expected for the third generation since the company tends to stick with the same Apple Watch design through three generations before changing it, there are a series of internal upgrades on the way. By the time the ...
terminal macos tahoe

Apple's Terminal App Gets Colorful Redesign in macOS Tahoe

Monday June 16, 2025 4:12 am PDT by
Apple's Terminal app is getting a visual refresh in macOS Tahoe, and it's the first notable design update since the command-line tool debuted. The updated Terminal will support 24-bit color and Powerline fonts, according to Apple's State of the Platforms presentation at WWDC25. The app will also adopt the new Liquid Glass aesthetic with redesigned themes that align with macOS 26's broader...
iOS 26 on Three iPhones

Apple Says iOS 26 Won't Be Available on These iPhone Models

Tuesday June 10, 2025 6:58 am PDT by
Apple this week revealed that iOS 26 is compatible with the iPhone 11 series and newer. That means that iOS 18 is the end of the road for the iPhone XS, iPhone XS Max, and iPhone XR, which were all released in 2018. However, those devices will continue to receive security updates for at least a few more years. iOS 26 is compatible with the following iPhone models: iPhone 16e iPhone...
new iphone lockscreen ios 26

iOS 26: Five Changes Coming to Your iPhone Lock Screen

Tuesday June 17, 2025 8:46 am PDT by
With iOS 26, Apple has made some additions to the iPhone Lock Screen that aim to make it more customizable than ever. Of course, things can always change before the software makes its way to the general iPhone-owning public, but here are five new things iOS 26 can do on the Lock Screen as of the current developer beta. Widgets Top or Bottom In iOS 18, the row of widgets on your Lock...
iOS 18

Apple Releases iOS 18.6 Public Beta

Wednesday June 18, 2025 10:24 am PDT by
Apple today seeded the first betas of upcoming iOS 18.6 and iPadOS 18.6 updates to public beta testers, with the betas coming just a few days after Apple provided the betas to developers. Testers who have signed up for beta updates through Apple's beta site can download iOS 18.6 and iPadOS 18.6 from the Settings app on a compatible device by going to General > Software Update. When the...

Top Rated Comments

rictus007 Avatar
93 months ago
That’s exactly why the iPhone, et al... should not have a back door
Score: 78 Votes (Like | Disagree)
tooloud10 Avatar
93 months ago
This is far beyond irony or karma, this is exactly what we've been screaming the warnings about for years now about why backdoors are an incredibly bad idea.
Score: 47 Votes (Like | Disagree)
lkrupp Avatar
93 months ago
Oh, and this technology will be exclusive to law enforcement and will never get in the hands of bad actors. Right.
Score: 40 Votes (Like | Disagree)
Quu Avatar
93 months ago
This is exactly why Tim Cook said you shouldn't build back-doors into products. Hackers will get at those back-doors one way or another.
Score: 40 Votes (Like | Disagree)
HiRez Avatar
93 months ago
Sure, let's build a "secure" government back door into all customer data and communications, what could go wrong?
Score: 34 Votes (Like | Disagree)
charlesdayton Avatar
93 months ago
I just want Apple to fix this bug so the stupid boxes become expensive paperweights.

Users have a right to privacy.
Score: 27 Votes (Like | Disagree)