Apple expands alert system to combat targeted mercenary spyware in 110 countries

Apple has unveiled an expanded warning system, now displaying Lock Screen alerts alongside emails and banners, to notify users in 110 countries of potential mercenary spyware threats, marking a significant escalation in its protective efforts against sophisticated surveillance campaigns.

Apple has sent a new wave of mercenary spyware threat notifications to users in 110 countries, one of its broadest campaigns since it began issuing the warnings in 2021, according to reporting by TechCrunch and Apple’s own support material. The company says these alerts are reserved for people it believes may have been singled out by highly sophisticated surveillance operations rather than ordinary criminal attacks.

This round also changes how the warning reaches users. Apple says the notice now appears on the iPhone Lock Screen and in Settings, in addition to the email sent from its threat-notifications address and the banner shown on account.apple.com after sign-in. That is a notable shift: a message buried in an inbox can go unseen for days, while a Lock Screen alert is immediate and difficult to ignore.

Apple describes the alerts as high-confidence detections based on internal threat intelligence. It does not identify the attacker, the country involved or the software used, a deliberate choice intended to avoid helping operators adjust their methods. The company has said it has notified users in more than 150 countries since 2021, underlining how far these campaigns can spread. Reuters-style reporting on previous waves has shown that recipients have included journalists, activists, politicians and diplomats, the small group most often targeted by mercenary spyware such as NSO Group’s Pegasus.

For anyone who receives a warning, Apple’s advice is to verify that it is genuine by signing in to account.apple.com, where a real alert will also appear. Apple says it never asks users to click links, open files, install profiles or share passwords or verification codes in response to these notices. If the alert is authentic, the company recommends turning on Lockdown Mode and contacting the Digital Security Helpline run by Access Now. Apple says it is not aware of a successful mercenary spyware attack against a device with Lockdown Mode enabled. For everyone else, the basic precautions remain the same: keep iOS updated, use two-factor authentication, enable Stolen Device Protection and download apps only from the App Store.

Disclaimer: This content is intended for informational purposes only. Readers are advised to exercise their own judgement, conduct due diligence, or consult a qualified expert before acting on any information provided.