Cybersecurity

Apple Sends New Threat Notifications to Users Targeted by Mercenary Spyware in 110 Countries

Apple confirmed sending a new batch of threat notifications on August 13 to users targeted by mercenary spyware attacks, noting that these alerts are based on high-confidence indicators. The company does not link this batch to any specific spyware program or particular government entity.

2026-08-13
3 min read
7 views
فريق تحرير certi.news
Apple Sends New Threat Notifications to Users Targeted by Mercenary Spyware in 110 Countries

Apple confirmed to BleepingComputer that on August 13 it sent a new batch of threat notifications to users targeted in 110 countries after detecting indicators of mercenary spyware attacks targeting specific iPhones. Some users reported receiving the alerts on Reddit, but Apple clarified that the feature is not new, as it has sent these notifications several times a year since 2021.

The message tells the user that Apple detected a “mercenary spyware attack targeting” their iPhone. The company does not disclose the program used in each case, so there is no evidence specifically linking the August 13 notifications to Pegasus. However, Apple cites the Pegasus program operated by the NSO Group as a historical example of this type of software, and previous digital forensic investigations confirmed that some devices were infected with Pegasus after their owners received notifications from Apple.

Notifications Target Specific Groups

Apple said in a previous support document that it sends threat notifications to users in more than 150 countries when it detects highly targeted attacks against specific individuals. Groups historically targeted include journalists, activists, politicians, and diplomats, while these attacks are usually costly, sophisticated, and directed at a very limited number of people.

Apple explains that mercenary spyware attacks may cost millions of dollars, and their operational lifespan is often short, making them more difficult to detect and prevent. At the same time, the company emphasizes that the vast majority of users will not be targeted by this type of attack.

Why Should the Alert Be Taken Seriously?

Apple relies on its own threat intelligence and the investigations it conducts to identify suspicious activity, so it describes these messages as “high-confidence” alerts rather than general warnings. The company says the alert means it has high confidence that the user themselves was targeted in an attack of this type, although it cannot reach absolute certainty in every investigation.

Apple does not attribute individual notifications to a specific government, company, or geographic region, nor does it disclose the detailed reasons that led it to issue each alert, explaining that publishing this information could help attackers modify their behavior to avoid detection in the future. The company also announced an updated threat notification experience to make it easier to access important information and follow the recommended steps to protect accounts and devices.

How to Verify the Message’s Authenticity

When it detects this activity, Apple sends an email and an iMessage notification to the email addresses and phone numbers associated with the Apple Account. Emails usually come from threat-notifications@email.apple.com, but the company warns about fake messages impersonating these alerts.

  • Check the account: Open account.apple.com and sign in; if Apple sent a genuine alert, it will appear at the top of the page.
  • Review the message content: Apple messages will not ask you to click a link, open a file, install an app or configuration profile, or provide your Apple Account password or verification code.
  • Protect your devices: Apple recommends enabling Lockdown Mode, updating devices to the latest software versions, and contacting a cybersecurity expert if you believe you have been affected.
News source
BleepingComputer
Open original source ↗
ف
Author

فريق تحرير certi.news

In the same category

You may also like

View all news