Apple has issued a large-scale wave of security warnings to users worldwide believed to be targeted by mercenary spyware, marking the largest distribution of such alerts since its threat notifications system was launched in 2021.
Apple has issued an unprecedented wave of security alerts to users it believes may have been singled out by mercenary spyware operators, according to Apple’s support guidance and reporting from technology sites tracking the issue. The notifications reached users in 110 countries, taking the total number of countries covered by Apple’s threat-notification system to more than 150 since it launched in 2021. Apple does not disclose how many people are affected, but investigators who follow spyware campaigns say this is the largest distribution of alerts yet.
The company says the warnings are meant for people who may have been individually targeted by highly sophisticated attacks, rather than for users facing routine account abuse. Apple delivers the alerts by email, iMessage and a prominent banner on the Apple ID website, and tells recipients to act quickly to secure their devices and accounts. The company stresses that a notification does not prove a phone has been compromised, only that its analysis found strong evidence of a credible, highly targeted attempt.
Mercenary spyware is a different class of threat from ordinary malware. It is typically built by private firms and sold to governments or government-linked entities for surveillance operations. In recent years, that market has been associated with tools such as Pegasus from NSO Group and Graphite from Paragon, both of which have featured in public discussion of digital spying against journalists, activists, lawyers, diplomats and human rights defenders.
Apple has generally avoided naming specific vendors or governments in these alerts, preferring the broader label of “mercenary spyware”. That caution reflects the difficulty of attribution in these cases, where the same techniques can be used by different operators and the evidence is often handled quietly to avoid helping attackers adapt. Even so, researchers who work on spyware cases say Apple’s telemetry gives it a strong basis for flagging suspicious activity.
For users who receive one of the alerts, Apple recommends immediate steps including turning on Lockdown Mode, keeping the operating system fully updated, checking the security of the Apple ID account and enabling two-factor authentication. Apple has recently said it is not aware of any case in which a device with Lockdown Mode already enabled was successfully compromised by mercenary spyware. For those in high-risk roles, specialists in digital forensics may also be needed to assess whether a device has been targeted.
Disclaimer: This content is intended for informational purposes only. Readers are advised to exercise their own judgement, conduct due diligence, or consult a qualified expert before acting on any information provided.





