Full Breakdown
Apple Issues New Mercenary Spyware Threat Notifications to Users in 110 Countries
8/15/2026, 6:13:28 AM
New Wave of Threat Alerts
On Thursday, Apple sent a fresh batch of threat notifications to users it believes may have been targeted by mercenary spyware. The alerts reached customers in 110 countries, bringing the program’s total reach to more than 150 countries since it began in 2021. Apple confirmed the rollout to TechCrunch and other outlets.
Program Background
Apple introduced its “Apple Threat Notification” program in 2021 to warn individuals singled out because of their role, activities, or contacts. The company describes mercenary spyware as “highly sophisticated” tools sold to state actors and used in “zero-click” attacks that require no user interaction. Apple’s internal threat-intelligence team generates “high-confidence” alerts but does not disclose the specific evidence behind each notification.
Delivery Mechanism and Scope
The notification appears in three places:
- A lock-screen push alert and a banner in the Settings app.
- An email from threat-notifications@email.apple.com linked to the user’s Apple ID.
- A banner at the top of the Apple Account page after signing in at account.apple.com.
Apple states that genuine alerts never ask users to click links, install profiles, or provide passwords. Recipients can verify an alert by signing in to their Apple Account and checking for the banner.
Recommended Protective Actions (Official Statements & Responses)
Apple’s support page advises recipients to:
- Update devices to the latest software version.
- Secure the device with a passcode, Touch ID or Face ID.
- Enable two-factor authentication for the Apple Account.
- Turn on Stolen Device Protection where available.
- Install apps only from the App Store.
- Use strong, unique passwords or passkeys for online accounts.
- Avoid opening links or attachments from unknown senders.
The company strongly recommends enabling Lockdown Mode, which restricts certain apps, web technologies, and incoming communications. Apple adds that it has not observed a successful mercenary-spyware compromise on a device with Lockdown Mode enabled.
Apple also directs users to the Digital Security Helpline operated by the nonprofit Access Now, which offers 24/7 rapid-response assistance.
Expert Commentary (Verbatim Quotes)
- “This warning is a reminder that even tightly controlled ‘walled garden’ ecosystems are not immune to spyware,” — Bogdan Botezatu, senior director of threat research at Bitdefender.
- “Using Lockdown Mode is one of the best things people do to become harder to hack,” — John Scott-Railton, senior researcher at Citizen Lab.
These statements underscore that even controlled ecosystems can be vulnerable and that Lockdown Mode is a key defensive measure.
Data Summary
- 110 countries received the latest alerts (August 13, 2026).
- Over 150 countries have been notified since the program’s inception.
- Apple has not disclosed the exact number of individual users affected.
Contextual Impact
The alerts highlight the ongoing proliferation of state-level surveillance tools and reinforce Apple’s role as a defender of user privacy. By publicizing high-confidence detections, Apple aims to signal potential surveillance and prompt affected individuals to seek expert help.
*Apple’s threat-notification program continues to evolve, but the company maintains that most iPhone users will never be targeted by such attacks.*
