

Apple has sent threat notifications to customers in 110 countries after detecting activity linked to mercenary spyware. The alerts warn users that attackers may have targeted their iPhones, iPads, or Macs.
The warning does not confirm that spyware entered a device. Still, Apple treats each notification as a high-confidence alert that requires action. The company has notified users in more than 150 countries since launching the program in 2021.
Apple sent the new alerts on Thursday, according to TechCrunch. The company now places a notification on an iPhone’s Lock Screen and inside Settings. It also emails the addresses linked to the user’s Apple Account.
A banner also appears after the recipient signs in at account.apple.com. The lock-screen message reads, “Apple detected a mercenary spyware attack targeted at your iPhone. There are actions you can take now to protect your data and device.”
Apple says it updated the warning process to make security guidance easier to reach. The company relies on its own threat intelligence and investigations when identifying suspected targets. It does not disclose the activity behind an alert, as those details could help attackers avoid detection.
Mercenary spyware campaigns differ from common online scams. Operators spend large sums targeting a small group of people. Past campaigns have focused on journalists, activists, politicians, and diplomats. Apple does not link its alerts to named attackers or countries.
Apple advises recipients to confirm a warning by signing in directly at account.apple.com. A genuine notice will appear at the top of the account page. Users should type the address themselves instead of following an unexpected link.
Official threat notifications never ask recipients to open files, install apps, or add configuration profiles. They also never request an Apple Account password or verification code through email or telephone calls. These checks can help users avoid messages that copy Apple’s warning format.
After confirming an alert, users should update Apple devices to the newest software. Apple also recommends strong account passwords, two-factor authentication, device passcodes, and Stolen Device Protection. Users should avoid unknown links and attachments.
Apple encourages notified users to seek specialist support. Its guidance points recipients toward Access Now’s Digital Security Helpline, which offers emergency assistance around the clock. Security experts can assess individual risks and provide advice suited to each case.
ALSO READ: Google Pixel 11 Brings Gemini Intelligence to Market Before Apple’s Siri
Apple recommends enabling Lockdown Mode after a threat notification. The optional setting reduces features that sophisticated spyware could exploit. It limits some messages, web technologies, incoming invitations, wired connections, and other services.
Users can enable it through Settings, Privacy & Security, and Lockdown Mode on an iPhone or iPad. Mac users can find the same option under Privacy & Security in System Settings. Each supported device requires separate activation.
Apple told TechCrunch that it has not seen a successful device compromise while Lockdown Mode was active. The setting can restrict normal functions, so Apple designed it for the small number of people facing highly targeted attacks.
Citizen Lab researcher John Scott-Railton called the new push alerts a “big improvement.” He said such notifications often lead recipients to seek help. Those requests can then help researchers identify other people targeted in the same surveillance campaign.