Apple expands push alerts for mercenary spyware targets

Apple has sent a new batch of threat notifications to customers in 110 countries whom it suspects were targeted by mercenary spyware capable of compromising iPhones, iPads or Macs. The company said the alerts, issued on Thursday, are intended for people facing highly targeted attacks commonly associated with government use of surveillance tools.
Apple says it has now notified customers in more than 150 countries. Its revised notification experience places a push alert on the iPhone lock screen and directs the recipient to information on actions that can help protect both the device and the data stored on it.
A more visible warning for targeted users
The lock-screen message states: “Apple detected a mercenary spyware attack targeted at your iPhone. There are actions you can take now to protect your data and device.” Apple also sends the warning by email and displays it when the user signs in to their account.
The notice is not proof that a device has been successfully hacked. It is, however, an indication that Apple suspects a targeted attempt and that the recipient should act promptly. The guidance opened by the alert includes information on whom to contact for help securing the device.
Lockdown Mode is part of the response
Apple advises recipients to enable Lockdown Mode, a security feature designed to make sophisticated spyware attacks substantially harder to carry out. The company says it has not seen a case in which a person’s device was hacked while Lockdown Mode was enabled.
That advice sits alongside Apple’s wider security work, including iPhone message extraction security fixes fixes for iPhone message extraction, which show why device protection depends on both timely software updates and a clear response when a threat warning appears.
Why notifications can have wider significance
Spyware attacks are generally rare, but surveillance technology has increasingly been used by governments against critics and members of civil society. Citizen Lab senior researcher John Scott-Railton said the newer push notifications are a significant improvement because they encourage recipients to seek support in securing their devices.
Scott-Railton noted that an individual alert can also reveal that a wider community is being targeted, prompting investigations that identify additional cases. He cited the Polish scandal involving alleged spyware use by the former government against rivals as an example of the value of such notifications.
For businesses and organisations, the practical implication is to prepare an escalation process for high-risk employees: keep Apple devices updated, identify trusted incident-response contacts, and ensure staff know that a mercenary spyware notification requires immediate review rather than routine dismissal.

