Apple Alerts Users in 110 Countries to Targeted Mercenary Spyware
The tech giant issued high-confidence warnings to high-risk individuals following a sophisticated wave of global surveillance attacks.
Apple has issued high-confidence threat notifications to a small number of users worldwide who have been individually targeted by sophisticated mercenary spyware. These alerts signal that specific devices were singled out by attackers using highly complex tools to compromise privacy and security.
According to Apple Support, these notifications are delivered through three distinct channels: a banner on account.apple.com, an email from [email protected], and a direct alert appearing on the iPhone's Lock Screen or within Settings. Apple emphasizes that these are high-confidence alerts that must be taken seriously. The company recommends that any user receiving such a warning immediately enable Lockdown Mode and seek expert security assistance to mitigate the threat.
The Nature of the Threat
Since 2021, Apple has periodically notified users in over 150 countries about the presence of mercenary spyware. These operations are characterized by extreme cost and complexity, often linked to private firms and various state actors. Unlike common malware that spreads indiscriminately, mercenary spyware is used in highly targeted operations with a short shelf life, making them nearly impossible to detect without the internal threat intelligence available to a platform provider like Apple.
High-Risk Targets
The attacks typically target individuals who are high-value targets for surveillance, including journalists, activists, politicians, and diplomats. A recent wave of these notifications in August 2026 reached users across 110 different countries, underscoring the global scale of the surveillance industry.
Why It Matters
The persistence of these attacks highlights a systemic global threat where state-sponsored actors deploy multi-million dollar tools to compromise the devices of dissidents and government officials. The shift toward proactive notification systems and the introduction of Lockdown Mode represent a critical evolution in device security. These measures are designed to protect high-risk users from "zero-click" exploits—attacks that can infect a device without any user interaction—which typically bypass standard security protocols.
What's Next
As mercenary spyware becomes more sophisticated, the battle between platform security and surveillance firms continues to escalate. Users are encouraged to remain vigilant and follow official Apple guidance if they suspect they are at risk. While Apple continues to refine its detection capabilities, the exact origin and full scope of the most recent wave of attacks remain subject to ongoing investigation.