Apple Sends New Mercenary Spyware Alerts to Users in 110 Countries
Apple sends new mercenary spyware alerts to users in 110 countries, urging targeted customers to take immediate steps to protect their devices and data.
Apple has sent a new round of mercenary spyware warnings to users in 110 countries, alerting people the company believes were individually targeted by sophisticated surveillance tools capable of compromising their devices.
The alerts are not ordinary security notifications. Apple says the warnings are high-confidence, based on its own threat intelligence and investigations, although receiving one does not necessarily mean an attacker has successfully compromised the device.
Apple has issued these notifications several times a year since 2021 and says it has now warned targeted users in more than 150 countries.
Apple makes spyware alerts harder to miss
Apple has updated how it delivers the warnings. Threat notifications can now appear directly on an iPhone’s Lock Screen and in Settings. At the same time, Apple also sends emails to addresses linked to the user’s Apple Account and displays a warning after the user signs in online.
The notification tells the recipient that Apple detected a mercenary spyware attack targeting their iPhone and directs them to steps to protect their device and data.
Apple warns that legitimate threat notifications will never ask users to click links, install apps or configuration profiles, open files, or provide an Apple Account password or verification code. Users can verify an alert by signing in directly to their Apple Account, where a genuine notification will also appear.
Apple recommends Lockdown Mode.
People who receive an alert are encouraged to enable Lockdown Mode, an optional security feature designed for users facing highly sophisticated attacks. The feature restricts certain device functions to reduce the number of avenues spyware can exploit.
Apple also recommends seeking expert assistance and directs affected users to AccessNow’s Digital Security Helpline for emergency cybersecurity support.
Mercenary spyware attacks are rare and typically target a small number of people because of who they are or what they do. Journalists, activists, politicians and diplomats have historically been among those targeted by commercial surveillance tools such as NSO Group’s Pegasus.
Notifications can uncover wider spyware campaigns.
Citizen Lab senior researcher John Scott-Railton saidApple’ss improved push notifications can help targeted users seek assistance more quickly. Those alerts can also lead researchers to identify additional victims and uncover broader surveillance campaigns.
Scott-Railton pointed to Poland’s Pegasus controversy as an example of how spyware notifications helped expose the targeting of political figures and others, contributing to wider scrutiny of government surveillance practices.
Apple does not disclose the technical evidence behind individual alerts because revealing its detection methods could help spyware operators avoid future detection.
For users who receive one of these warnings, the key point is simple: the alert means Apple believes an unusually sophisticated attack specifically targeted them. It should be taken seriously even if a successful compromise has not been confirmed.
What's Your Reaction?
Like
0
Dislike
0
Love
0
Funny
0
Angry
0
Sad
0
Wow
0