Decoding the world of cybersecurity

Apple spyware alerts reach 110 countries

Apple has sent a fresh wave of mercenary-spyware threat notifications across 110 countries and expanded how high-risk users are warned about targeted attacks.

Apple spyware alerts reach 110 countries
Summary
  • Apple describes its threat notifications as high-confidence indications that an individual has been specifically targeted by mercenary spyware.
  • The latest wave reached targeted users in 110 countries, while notifications have reached users in more than 150 countries since 2021.
  • An alert identifies targeting activity but does not by itself establish successful compromise or identify the spyware operator.

Apple has sent a new wave of mercenary-spyware threat notifications to targeted users across 110 countries, while expanding the channels through which high-risk individuals are warned about highly targeted attacks.

Apple updated its notification process on 13 August, adding warnings directly to the iPhone Lock Screen and Settings alongside email and alerts shown through a user’s Apple Account.

The company describes the notifications as high-confidence indications that an individual has been specifically targeted by a mercenary-spyware attack, although it acknowledges that its investigations cannot provide absolute certainty. Apple does not disclose the technical triggers behind individual warnings because that information could help spyware operators alter their methods.

The latest wave reached users targeted in 110 countries. Since 2021, Apple has issued threat notifications several times each year and says users in more than 150 countries have received them in total.

An alert does not automatically prove that the device was successfully compromised. Target selection, exploit delivery, and successful infection are separate stages, and the notification indicates that Apple has detected activity consistent with a highly targeted mercenary-spyware attempt against the individual.

Apple also does not attribute individual warnings to specific spyware vendors, governments, or geographical regions. Commercial surveillance tools have been linked through independent investigations to government customers in numerous jurisdictions, but a fresh Apple alert does not establish which product or operator was responsible.

European institutions have spent several years confronting the consequences of commercial spyware. Pegasus and other surveillance tools have triggered European Parliament inquiries, national investigations, court proceedings, and scrutiny of the relationship between commercial developers and state customers.

Researchers disclosed in July that former MEP Stelios Kouloglou had been infected with spyware while serving on the European Parliament committee investigating Pegasus-related surveillance abuses. Such cases show how compromise of one mobile device can expose communications, contacts, source relationships, location information, and institutional conversations extending well beyond the individual owner.

Mercenary spyware operates differently from mass-market malware. The attacks are expensive, highly targeted, and designed to bypass security controls on modern mobile devices, leaving very small victim numbers capable of carrying disproportionate political, diplomatic, legal, or organisational consequences.

John Scott-Railton, senior researcher at Citizen Lab, has described the role of provider notifications in mapping these campaigns: “Notifications create a critical signal that a community is being targeted.” Alerts can prompt forensic examination that subsequently identifies additional victims, infrastructure, and campaign links.

Apple’s updated threat-notification guidance directs recipients towards Lockdown Mode and specialist assistance from Access Now’s Digital Security Helpline. It also explains how users can verify a genuine alert, reducing the risk that the notification process itself is imitated for phishing or social engineering.

The 110-country distribution does not mean 110 governments are operating spyware, nor does it establish that every recipient was successfully compromised. It does show that highly targeted commercial surveillance remains geographically broad, with technology providers continuing to surface campaigns that may otherwise remain undetected around the organisations and institutions connected to individual targets.

×