Apple Sends Fresh Push Alerts to iPhones When It Detects Government-Grade Spyware
Apple has sent warnings to users in 110 countries about potential mercenary spyware attacks targeting iPhones, iPads, and Macs. These alerts, confirmed by Apple, highlight the advanced nature of such threats, often aimed at specific individuals like journalists and activists. Notifications now appear directly on device lock screens for easier access.

New Delhi: Apple has issued a fresh wave of threat notifications to users in 110 countries, warning that their iPhones, iPads or Macs may have been targeted by highly sophisticated “mercenary spyware” capable of remotely compromising their devices.
The notifications were sent on Thursday, August 13, with Apple confirming that users targeted by suspected spyware attacks across 110 countries had received the alerts. The latest campaign comes as Apple continues to monitor and warn users about sophisticated spyware attacks that typically target a small number of specific individuals.
Apple's notification tells affected users: “Apple detected a mercenary spyware attack targeted at your iPhone. There are actions you can take now to protect your data and device.” The company has previously described such attacks as exceptionally sophisticated and far more complex than conventional cybercrime or consumer malware.
The latest notifications also mark an update in how Apple communicates these warnings. According to an updated Apple support document, the company can now notify users directly through a push notification on their device's lock screen, making it easier for recipients to access information about the threat and the steps they should take. Apple also sends alerts by email and through notifications associated with the user's Apple Account.
Advertisement
Apple Has Warned Users in Over 150 Countries
Apple said it has now notified customers in more than 150 countries about suspected mercenary spyware attacks since it began issuing such warnings in 2021. The company says these attacks are generally directed at individuals because of who they are or what they do, with journalists, activists, politicians and diplomats among groups that have historically faced such threats.
One of the most notorious examples of mercenary spyware is Pegasus, developed by the NSO Group. Apple does not publicly attribute individual threat notifications to specific attackers, companies or governments, saying that revealing details about its detection methods could help spyware operators adapt and evade future detection.
Advertisement
Apple describes its threat notifications as high-confidence warnings, although it acknowledges that its investigations cannot establish absolute certainty in every case. The company says it relies on its own threat intelligence and investigations to identify activity consistent with mercenary spyware attacks.
What Should Users Do After Receiving an Apple Spyware Alert?
Apple recommends that users who receive a threat notification take immediate steps to strengthen the security of their devices and accounts. These include updating devices to the latest software, using a strong passcode, enabling two-factor authentication and using a strong, unique Apple Account password.
The company also recommends installing applications only from the App Store, using strong and unique passwords or passkeys, enabling Stolen Device Protection on supported iPhones and avoiding suspicious links or attachments from unknown senders.
Apple and security researchers also recommend enabling Lockdown Mode, a security feature designed specifically to reduce the attack surface available to highly sophisticated spyware. In March 2026, Apple said it was not aware of any successful mercenary spyware attack against an Apple device that had Lockdown Mode enabled at the time of the attack.
Apple stresses that users should take genuine threat notifications seriously. At the same time, the company warns that legitimate Apple threat notifications will never ask users to click a link, install an app or profile, or provide their Apple Account password or verification code. Users can verify whether an alert is genuine by signing into their Apple Account through Apple's official website.
The latest alerts underscore the continuing global threat posed by commercial and government-linked spyware, with Apple increasingly relying on direct warnings to help individuals who may have been specifically singled out by sophisticated surveillance campaigns.