TodayFriday, August 14, 2026

Apple Warns iPhone Users in 110 Countries About Mercenary Spyware Attacks

Apple sent threat notifications to iPhone users in 110 countries about mercenary spyware, a warning from the surveillance industry's latest victims.
August 14, 2026
Photo illustration of the Apple logo displayed on a smartphone screen
Apple's Hide My Email, part of iCloud+, is designed to keep a user's real address private. Researchers say a flaw has undermined that promise for over a year. [Image Source: Cheng Xin/Getty Images]

SAN FRANCISCO — The notification arrived without ceremony: a message from Apple, occupying the same row on the lock screen as calendar alerts and unread texts, informing the recipient that their iPhone had been targeted by mercenary spyware. This week, that message appeared on devices in 110 countries.

Apple confirmed Thursday that it had issued a fresh wave of mercenary spyware threat notifications to users across iPhones, iPads, and Macs, the largest single notification round in a program that has, since its 2021 launch, touched more than 150 countries in total, TechCrunch reported.

The notification text has not changed. It reads: “Apple detected a mercenary spyware attack targeted at your iPhone.” It is a sentence calibrated to alarm without informing: no attacker is named, no specific tool identified, no government implicated. Apple’s support page, updated Thursday alongside the notification wave, advises users to enable Lockdown Mode and to reach out to Access Now’s Digital Security Helpline, a nonprofit that provides emergency security assistance to at-risk individuals.

Mercenary spyware is a category of commercial surveillance technology manufactured by private companies and sold to state actors under contracts that generally prohibit resale or deployment outside approved targets. The business model has been described by industry participants as lawful surveillance for lawful purposes; the documented record shows a different pattern. The technology has been deployed against journalists, opposition politicians, human rights lawyers, activists, and diaspora communities in more than forty countries. In no documented case has a licensed user been publicly prosecuted for abuse.

The most widely investigated tool in this ecosystem is Pegasus, developed by NSO Group, an Israeli company. Pegasus is capable of silently compromising an iPhone with no user interaction required. After its methods were documented by Citizen Lab researchers and an international consortium of investigative journalists in 2021, NSO was placed on the United States Commerce Department’s Entity List, sued by Apple and Meta, and ordered by a federal court to stop targeting WhatsApp users. A contempt motion filed by Meta’s legal team this year alleges the hacking continued after the court order.

An NSO Group display stand at a defence and security expo in Israel
An NSO Group stand at a defence and security expo in Tel Aviv. The Israeli spyware maker’s Pegasus tool has been documented in Apple threat notification cases globally. [Image Source: Reuters]

John Scott-Railton, a senior researcher at the Citizen Lab at the University of Toronto, has called Apple’s notification system a meaningful advance over the era before 2021, when mercenary spyware compromise often went undetected for months or years. “Notifications create a critical signal that a community is being targeted,” Scott-Railton said. He cited Poland as an example: Apple threat notifications enabled researchers to identify a cluster of targets that exposed the government’s use of Pegasus against opposition figures and investigative journalists, producing a parliamentary inquiry and criminal proceedings against former security officials.

Apple began issuing threat notifications in November 2021, and has sent multiple waves since. Earlier rounds prompted investigations by Citizen Lab, Amnesty International’s Security Lab, and Access Now that produced specific attribution, connecting the targeting to named governments and to particular commercial products, including Paragon Solutions’ Graphite spyware, which was documented targeting journalists in Italy. This week’s notifications have not yet generated comparable attribution in public reporting.

Apple has offered two explanations for why it does not name attackers in its notifications. The company says that attribution requires disclosing detection methods, which would allow sophisticated adversaries to adapt and evade. It also says it cannot meet the evidentiary standard required to publicly identify a named government or vendor based solely on technical signals. The notifications therefore express “high confidence” that the targeting is real while explicitly stopping short of accusation.

Lockdown Mode is Apple’s most aggressive response to the mercenary spyware threat. When enabled, it restricts the iPhone’s attack surface by disabling certain web technologies, limiting message attachments, blocking wired data connections to unknown devices, and restricting some iCloud and App Store features. Apple has stated that Lockdown Mode has prevented every known compromise by mercenary spyware when active. The trade-off is reduced functionality for a device designed around convenience.

The pattern of who receives these notifications contains information that the notifications themselves do not. Apple’s threat alerts have not produced documented waves of targeting directed at ordinary consumers or corporate executives managing financial data. The consistent pattern across multiple alert rounds has been targeting concentrated in groups that governments have demonstrated motivation to monitor: journalists working on sensitive topics, political opposition figures, lawyers involved in human rights cases, and members of diaspora communities who speak publicly about conditions in their countries of origin. The pattern describes an industry. It does not name a specific government in any individual case.

The 110-country figure marks the geographic reach of this wave, not a count of affected users. Apple does not disclose how many individuals received notifications, and the number of countries reached says nothing about saturation. In each country, alerts go only to individuals the company has identified through technical analysis as probable targets. That the analysis spans 110 countries suggests that no region Apple operates in has been excluded from the mercenary spyware industry’s reach.

The push notification Apple sent this week is twelve words. It gives a person information they would not otherwise have: that someone with the resources of a government may be trying to read what they write, see where they go, and hear what they say. Before Apple built this system, that information often took years to surface, if it surfaced at all. What the notification does not give a person is the name of the government, the name of the tool, or an answer to the question most likely running through their mind when they read it: why me.

Amanda Graham

Amanda Graham

Amanda Graham is a journalist at The Eastern Herald covering economy, politics, business, and current affairs from around the world.

Leave a Reply

Don't Miss