Apple Explains Threat Notifications for Mercenary Spyware Attacks

Apple has updated its guidance on how it alerts users who may be targeted by highly sophisticated mercenary spyware.

In a support document published August 13, 2026, Apple explained that its Threat Notifications are intended for people who may have been individually targeted because of their identity, profession, public role, or activities. These attacks are rare, highly targeted, and significantly more advanced than the cyberthreats most people encounter.

Mercenary spyware is generally developed using substantial financial and technical resources and can be designed to secretly access or monitor a person’s device. Public research has previously connected this type of technology with state-sponsored surveillance operations and commercial spyware companies, including NSO Group, the developer of Pegasus.

Apple says journalists, activists, politicians, diplomats, and other high-profile individuals have historically been among those targeted by these types of attacks. However, the company emphasizes that the overwhelming majority of Apple users are unlikely to ever encounter mercenary spyware.

How Apple Warns Targeted Users

When Apple detects activity that it believes is consistent with a mercenary spyware attack, the company may notify the affected person in several ways.

A warning can appear directly on an iPhone’s Lock Screen or inside Settings. Apple may also send an email to addresses connected to the person’s Apple Account. Users who sign in at account.apple.com may also see a prominent threat notification at the top of their account page.

As of 2026, Apple says email alerts are sent from [email protected].

Apple describes these warnings as high-confidence notifications, although the company notes that no security investigation can provide absolute certainty. Apple also does not publicly disclose the technical indicators that trigger an alert because doing so could help spyware developers change their methods and avoid future detection.

Since introducing the notification system in 2021, Apple says it has warned targeted users in more than 150 countries.

What to Do If You Receive a Warning

Apple advises anyone who receives a threat notification to take it seriously.

One of the protections the company recommends is Lockdown Mode, an optional security setting available on Apple devices that limits certain features and communications that could potentially be exploited in a sophisticated cyberattack.

Apple also recommends seeking assistance from cybersecurity experts. The company specifically points users toward Access Now’s Digital Security Helpline, which provides emergency security support to people at risk.

Users should also be cautious of scams pretending to be Apple security warnings.

According to Apple, a genuine threat notification will not ask someone to click a link, download a file, install an app or configuration profile, or provide an Apple Account password or verification code by email or phone.

Anyone who wants to confirm whether an alert is legitimate can sign in directly to account.apple.com. If Apple has issued a threat notification, the warning should appear after the user signs in.

Security Steps Everyone Can Take

Even though mercenary spyware affects only a small number of people, Apple recommends that all users follow standard cybersecurity practices.

Users should keep their devices updated with the latest software and security fixes, protect devices with a passcode and biometric security such as Face ID or Touch ID, and enable two-factor authentication for their Apple Account.

Apple also recommends turning on Stolen Device Protection, downloading applications from the App Store, using strong and unique passwords or passkeys, and avoiding unexpected links or attachments from unfamiliar senders.

People who believe they face an elevated risk of targeted surveillance can also enable Lockdown Mode even if they have not received an Apple threat notification.

The broader message is simple: an Apple threat notification is not a routine security alert. It is designed for rare situations in which Apple believes a specific individual may have been targeted by one of the most sophisticated forms of commercial spyware.


Comments Section

Leave a Reply

Your email address will not be published. Required fields are marked *



,
Back to Top - Modernizing Tech