Britain’s National Cyber Security Centre, the FBI and the Netherlands’ AIVD published a joint advisory on 15 September 2026 describing a spyware family called CHOSEN BRICK, which the three agencies say Iranian state-linked actors have used since at least 2025 to target dissidents, activists and journalists worldwide, according to the NCSC. The malware, which runs exclusively on Windows systems, is delivered through spear-phishing campaigns on WhatsApp and Telegram, where operators impersonate acquaintances or technical support staff to build rapport before sending a disguised installer, according to SecurityWeek. Once installed, the tool can harvest contacts, emails and social media messages and connects to a unique Telegram bot for each infected device to reduce the chance of detection, according to The Register.

NCSC Director of Operations Paul Chichester said the campaign shows how Iran uses digital surveillance to repress critics of the regime and urged people who believe they are at risk to follow the mitigation advice published alongside the technical report, according to the NCSC. That advisory notes that some victims’ personal details have already appeared on pro-Iranian leak sites, which the agency says increases the physical risk to those affected.

Cooperation as the default response

What distinguishes this advisory from a routine malware alert is the structure behind it. Three national security services, each with their own legal mandates and domestic oversight regimes, jointly attributed the campaign, pooled indicators of compromise and issued shared guidance under one advisory rather than three separate national statements. The advice itself extends beyond corporate networks: agencies told organisations to check personal devices belonging to staff who might be targeted, not just office equipment, according to The Register. That instruction, treated as a minor technical footnote in most coverage, effectively asks employers to extend identity and device verification into private life on the recommendation of intelligence services.

None of the three agencies has published details of the legal basis under which victim data was shared across borders, nor whether individuals whose devices were flagged were informed before their information moved between the FBI, the NCSC and the AIVD. The advisory presents this pooling as protective, and the underlying threat from Iranian state repression is real and well documented. But the precedent of three intelligence services normalising joint data collection and identity-verification guidance as the default response to a foreign threat is the kind of institutional architecture that resurfaces whenever governments propose cross-border frameworks for digital identity enforcement, where the justification is again protection and the mechanism is again shared data pools between agencies that answer to different parliaments.

How the outlets framed it

The NCSC’s own release and outlets such as Al Jazeera framed the advisory chiefly as a warning to at-risk individuals, quoting Paul Chichester’s language about Iranian repression and presenting the guidance as straightforwardly protective. SecurityWeek and The Register instead focused on the technical tradecraft, the decoy files disguised as medical scans, the Telegram bot infrastructure, and the Windows-only targeting, treating the story as a malware analysis rather than an institutional one. Neither framing examines what it means that three national intelligence services are now issuing coordinated advisories that instruct private employers to extend surveillance guidance onto employees’ personal devices, which is the part of the story with the longer institutional life.

The advisory does not name specific victims, and none of the named officials in the coverage is accused of wrongdoing. The story here is not a scandal but a pattern, and patterns in cross-border data cooperation tend to become templates.