Apple warns targets of mercenary spyware again: the alert now lands on the Lock Screen
On 13 August Apple sent another round of threat notifications to people it believes were targeted by mercenary spyware, the commercial kind sold to governments. This wave reached users in 110 countries; across all waves since 2021 the total is above 150. What changed this time is where the warning appears: it now arrives as an alert on the iPhone Lock Screen and in Settings, not only as an email that can sit unopened for a week.
Who gets these and why they matter
Mercenary spyware is not the malware that arrives in a dodgy download. It is built to order, costs a fortune per target, and is sold to state agencies, which is why it lands on journalists, activists, lawyers, politicians and diplomats rather than on the general public. Infection often needs no action from the victim at all.
Apple is deliberately careful about the wording. It does not name the attacker or the country behind an attack, and it does not publish what triggered a particular alert, because explaining the detection would help the vendors evade it next time. So the notification says that you were probably targeted, and stops there.
How to tell a real notification from a fake one
A genuine Apple threat notification never asks you to click a link, open a file, install an app or a profile, or give a password or verification code. To check, sign in at account.apple.com: if Apple really sent you one, it is shown at the top of the page. The same alert also goes to the email addresses attached to the Apple Account, from [email protected]. Anything that arrives with a link and a sense of urgency is phishing that borrows the news.
What to do if one arrives
- Take it seriously even if you cannot imagine why you would be a target. The list of targets is decided by whoever bought the tool.
- Turn on Lockdown Mode. It removes the features these attacks lean on, and Apple says it has yet to see a device compromised while it was enabled.
- Update the system on every device you own, and restart the phone. Some implants do not survive a reboot; updates close the paths used to install them.
- Get expert help rather than improvising: Access Now runs a free Digital Security Helpline around the clock for exactly these cases.
- Change important passwords from a different, clean device, and treat everything typed on the suspect phone as read by someone else.
Why the geography keeps growing
More than 150 countries is not a statement about hackers being everywhere. It is a statement about a market: the tools are sold as products, with contracts and support, and each new customer state adds its own list of people worth watching. That is also why the alerts arrive in waves rather than continuously, and why a wave says as much about who is buying as about who is being infected.
For everyone outside that list, the practical takeaway is dull and useful: install updates promptly, restart devices sometimes, and treat any message urging you to open something right now as suspect. Lockdown Mode exists for people with a reason to expect an attack, and for them it is the single most effective switch on the device.
• About Apple threat notifications and protecting against mercenary spyware - Apple Support
• If Apple sends you a push notification alerting you to a spyware attack, take it seriously - TechCrunch
• Apple sends new Threat Notification alerts over mercenary spyware attacks - BleepingComputer
• Apple sends fresh wave of mercenary spyware warnings worldwide - 9to5Mac