Apple alerts suspected mercenary spyware targets in 110 countries

Apple has sent a fresh round of threat notifications to customers it suspects were targeted by mercenary spyware in 110 countries. The company did not disclose how many people received the alerts, but said it has notified customers in more than 150 countries since beginning the programme in late 2021.
The iPhone maker characterises these notifications as high-confidence alerts that a user has been individually singled out in a mercenary spyware attack. Apple urged recipients to take the warning seriously.
Warnings for a narrow set of targets
Mercenary spyware attacks generally focus on a very small number of people because of who they are or what they do. Apple identified journalists, activists, politicians and diplomats as examples of people who may be targeted.
Such operations differ from ordinary cybercrime in their cost, sophistication and international reach. Spyware vendors devote substantial time and resources to developing exploits that can be used to install surveillance payloads on specific devices.
Apple said it does not attribute attacks or its resulting notifications to particular attackers or geographical regions. It also does not reveal the technical signals that trigger an alert, because public detail could allow spyware operators to refine their tactics. The wider threat landscape also includes the vulnerabilities, ClickFix chains and AI-agent incidents tracked in vulnerabilities, ClickFix chains and AI-agent incidents, underscoring the variety of techniques security teams must monitor.
How Apple delivers a threat notification
Users may see an Apple Threat Notification on their iPhone Lock Screen and in Settings. Apple also sends a message to email addresses associated with the user’s Apple Account; the sender is threat-notifications@email.apple.com.
In addition, a threat notification banner appears at the top of the Apple Account page when the customer signs in at account.apple.com. Receiving confirmation through more than one of these channels can help users distinguish a genuine warning from an unsolicited message impersonating Apple.
Steps for organisations and individuals
Apple advises users to install the latest software, protect devices with a passcode, Touch ID or Face ID, and enable two-factor authentication for their Apple Account. It also recommends Stolen Device Protection, applications from trusted sources only, Lockdown Mode, and caution with links or attachments from unknown senders.
For businesses supporting higher-risk staff, the practical implication is to ensure these protections are enabled in advance and to maintain a clear escalation process for any Apple threat notification, rather than treating it as routine phishing.

