Back to Home Apple Sends Mercenary Spyware Alerts to Targets in 110 Countries Technology

Apple Sends Mercenary Spyware Alerts to Targets in 110 Countries

Published on August 14, 2026 0 views

Apple sent a new wave of threat notifications on Thursday, August 13, to customers it believes were individually targeted by mercenary spyware, reaching users in 110 countries. The company confirmed the campaign to TechCrunch and published updated guidance explaining that affected iPhones can now display a direct warning on the Lock Screen and in Settings. The alerts may also concern iPads or Macs linked to a targeted user.

Apple describes the notices as high-confidence findings based solely on its internal threat intelligence and investigations. A warning means the recipient was specifically targeted because of who the person is or what the person does, but it does not by itself prove that the device was successfully compromised. Apple did not disclose the number of recipients, the spyware involved, the suspected operators or the countries where targets were located.

The revised delivery system places an alert on the iPhone Lock Screen and in Settings, sends an email to addresses associated with the Apple Account, and shows a banner after the user signs in at account.apple.com. Apple said the more visible route is intended to help recipients reach protective guidance quickly. Since 2021, the company has issued such notifications several times a year and has now warned users in more than 150 countries overall.

Mercenary spyware operations are rare but exceptionally expensive and sophisticated, according to Apple. They concentrate large resources on a small number of people, commonly journalists, activists, politicians and diplomats. Public investigations have historically linked such campaigns to state actors and private surveillance vendors, including the maker of Pegasus, but Apple said it does not attribute this alert wave to any attacker or region and withholds detection details to prevent evasion.

Apple urged notified users to enable Lockdown Mode, install the latest software on every device and seek expert help from Access Now's Digital Security Helpline, which operates around the clock. Recipients can verify an alert by signing in directly at account.apple.com. Genuine Apple threat notices never ask users to follow a link, open a file, install an app or configuration profile, or provide an account password or verification code by email or phone.

Citizen Lab senior researcher John Scott-Railton told TechCrunch that the new push alerts are a major improvement because one warning can prompt an investigation that exposes additional targets. He cited the discovery of spyware abuse connected to Poland's election as an example of the wider accountability such notices can trigger. The immediate priority is helping recipients preserve evidence and secure their devices while researchers determine whether the latest targeting produced successful infections.

Sources: Apple Support, TechCrunch, Citizen Lab

Comments