Apple is fighting the UK's secret order to break iCloud encryption, again

For a year and a half the British government has been trying to force its way into end-to-end-encrypted iCloud data. Apple is now challenging a second, quieter version of that order, and UK users have already lost their strongest protection in the process. Here is the honest state of the most important encryption fight in the world.

Apple is fighting the UK's secret order to break iCloud encryption, again
TL;DR

The UK government has spent roughly a year and a half trying to compel Apple to give its security services access to end-to-end-encrypted iCloud data, using secret legal orders that Apple is forbidden by law from even acknowledging. On 3 August 2026 the Financial Times revealed that Apple has filed a fresh challenge against the latest, UK-only version of that order at a secret tribunal. The twist most coverage misses: UK users already lost their strongest cloud protection back in February 2025, when Apple pulled its opt-in end-to-end encryption rather than build a backdoor. This is the most consequential encryption fight in the world right now, and it is happening almost entirely in the dark.

There is a fight going on over whether a government can force a company to break the encryption protecting your private data, and almost everything about it is secret. The order at the centre of it cannot legally be discussed by the company that received it. The tribunal hearing the case tried to sit entirely behind closed doors. And the specifics we do know come mostly from a handful of journalists' sources, not public documents.

That secrecy is exactly why it matters. When a democracy quietly tries to weaken the encryption that hundreds of millions of people rely on, and gags everyone involved from talking about it, the details deserve daylight. Here is what is actually known, what is reported but unconfirmed, and what it means for you, with the line between those drawn honestly.

What just happened?

According to the Financial Times, in a report surfaced by TechCrunch on 3 August 2026, Apple has filed a fresh legal complaint with the UK's Investigatory Powers Tribunal (IPT), the secret court that hears challenges to Britain's surveillance powers. The complaint reportedly targets a new government order demanding access to the end-to-end-encrypted iCloud data of UK users.

Two caveats belong right here, because the honesty of this story depends on them. First, the filing itself was reportedly made in July 2026; 3 August is when the FT revealed it, via a court order it had seen. Second, essentially everything about the secret order, its existence and its UK-only scope, rests on the FT's sourcing. Apple has not confirmed it. It legally cannot, which is the whole problem.

What is a Technical Capability Notice, and why is it secret?

The instrument the UK is using is a Technical Capability Notice (TCN), issued under the Investigatory Powers Act 2016, the surveillance law critics nicknamed the "Snoopers' Charter." A TCN can compel a company to provide the government access to customer data, including data the company has encrypted.

The part that makes this so strange is the gag. Under the Act, the recipient of a TCN is legally prohibited from disclosing that the notice even exists. As MacRumors put it, "Apple and the Home Office are both legally barred from discussing TCNs." So Apple can neither confirm nor deny that it has been ordered to do anything, which is why a fight over your privacy is being reported through leaks rather than announcements. This is a matter of statute, not speculation: the secrecy is built into the law.

What is Advanced Data Protection, and what did Apple already give up?

To understand the stakes you need one distinction. By default, your iCloud data (photos, backups, notes) is encrypted, but Apple holds the keys and can hand that data to law enforcement when served with a valid warrant. Advanced Data Protection (ADP) is Apple's opt-in setting that upgrades most of iCloud to full end-to-end encryption, meaning the keys live only on your devices and even Apple cannot read your data, and therefore cannot hand it over.

Here is the twist the headlines tend to skip. In February 2025, rather than build the backdoor the original order reportedly demanded, Apple simply withdrew Advanced Data Protection in the UK. New UK users can no longer turn it on, and existing users were told to disable it themselves (Apple cannot switch it off for them). The practical result is blunt and already true: the strongest cloud protection Apple offers is no longer available to anyone in the UK. ADP was opt-in, so for the many who never turned it on, nothing changed; but for anyone who used it or would have, their iCloud data is more exposed today than it was two years ago, not because of a hack, but because a government asked.

How did we get here?

The timeline is an 18-month game of cat and mouse, and the direction of travel is what matters.

  • January 2025: The UK secretly served Apple with an order reportedly demanding access to ADP-protected iCloud data on a worldwide basis, first reported by the Washington Post.
  • February 2025: Apple pulled ADP for UK users rather than comply.
  • March–April 2025: Apple began challenging the order at the IPT, and the tribunal rejected the Home Office's attempt to keep the case entirely secret, ruling it "would have been a truly extraordinary step to conduct a hearing entirely in secret," and publicly confirmed Apple as a claimant. Privacy International and Liberty are challenging the regime too.
  • August 2025: Under pressure from the Trump administration, the UK reportedly dropped the demand as it applied to Americans. Back in February, US Director of National Intelligence Tulsi Gabbard had called the order a "clear and egregious violation" of Americans' privacy, and Trump had likened it to something "you hear about with China."
  • Autumn 2025: The UK reportedly re-issued a narrower, UK-only order, reviving the demand for British users' data. Apple's original IPT claim was dismissed in October 2025 after that "change in circumstances," which is why a second challenge became necessary.
  • July–August 2026: Apple files a fresh IPT challenge against the UK-only order, revealed on 3 August. The tribunal will reportedly hear it largely in public on "assumed facts," alongside Privacy International, Liberty and two individuals, with a case-management hearing listed for September 2026 and a substantive hearing in the related case listed for December 2026. Apple says it is "gravely disappointed" that it still cannot offer UK users its strongest encryption.

Read together, the pattern is a government that lost the global fight and is now trying the same thing on a smaller, quieter scale.

Can you build a backdoor for just one country?

This is the technical heart of the argument, and the answer from security experts is essentially no. A backdoor is not a door that only the "right" people can walk through; it is a deliberate weakness in the encryption, and once it exists, it is a target for everyone. As the Electronic Frontier Foundation put it, "breaking end-to-end encryption for one country breaks it for everyone." The EFF also warns that such an order "sets a dangerous precedent" and "provides a runway for other authoritarian governments to issue comparable orders."

That precedent point is the reason this narrow UK case has global weight. If a democracy can secretly compel a company to weaken encryption for its citizens, every other government now has a template to cite, including ones with far worse records. The uncomfortable truth is that a backdoor built for a friendly government is the same backdoor a hostile one, or a criminal, would love to find.

What does this actually mean for you?

It depends where you are, and the honest answer is more measured than either "your iCloud is wide open" or "nothing to see here."

If you are in the UK: you cannot currently turn on Advanced Data Protection, so your iCloud backups and photos are encrypted with keys Apple holds and can be compelled to use. If maximum privacy for cloud data matters to you, the practical workaround is to store the most sensitive material in services or local backups that are end-to-end encrypted by default, or to keep it off the cloud entirely. This is not paranoia; it is just working with the protection actually available to you.

If you are outside the UK: your ADP is intact, and the US intervened specifically to protect Americans' data. But the precedent is the thing to watch. How this tribunal rules could shape what other governments believe they can demand next, though a secret ruling makes a murkier template for them to cite than a public one would.

The broader lesson is the one worth holding onto. Strong encryption is not a criminal's tool; it is what protects everyone's messages, backups, health records and photos from theft and abuse. Governments have legitimate reasons to want access to some data, and there is a real debate to be had about warrants and oversight. But that debate should happen in the open, not through secret orders that the public only learns about when a journalist pries them loose. For more, see the Privacy section, and our explainer on what a VPN actually hides.

The 18-month backdoor fight, at a glance

WhenWhat happened
Jan 2025UK secretly orders access to ADP data worldwide (reported by the Washington Post)
Feb 2025Apple withdraws Advanced Data Protection in the UK rather than comply
Mar–Apr 2025IPT refuses to hold the case entirely in secret; Apple confirmed as claimant
Aug 2025Under US pressure, UK reportedly drops the demand covering Americans
Autumn 2025UK reportedly re-issues a narrower, UK-only order
Jul–Aug 2026Apple files a fresh IPT challenge (revealed 3 Aug 2026 by the FT)
Sep / Dec 2026Case-management hearing (Sept); related substantive hearing listed (Dec)