Apple adds on-device iPhone alerts for mercenary spyware

Apple has expanded its mercenary spyware warning program by pushing high-risk alerts directly to the iPhone Lock Screen and a prominent banner in Settings, making it far harder for targets to overlook what could be a life‑altering security message.[1][9][10] A fresh wave of Apple Threat Notifications was sent this week to selected iPhone users who the company believes were individually targeted in mercenary spyware campaigns, underscoring that these attacks remain an active risk for high‑profile and high‑risk communities.[9][10]

According to Apple’s updated guidance, a genuine threat notification now appears in three places: as an on‑device alert on the Lock Screen and in Settings, as an email from its dedicated threat notifications address, and as a banner at the top of the user’s Apple Account page after sign‑in.[1][9][12][15] Apple describes these as “high‑confidence alerts” that someone has been individually targeted by a mercenary spyware attack, typically because of who they are, what they know, or the work they do, and stresses that recipients should take them extremely seriously.[1][3][9] Security organizations working with recipients note that the on‑device alert is especially important for users who may miss or mistrust email in environments where phishing and spam are common.[9][12]

Mercenary spyware refers to highly sophisticated surveillance tools sold by commercial vendors to government and state‑linked customers, with families like Pegasus and Predator widely documented in past Apple threat notifications.[3][15] Apple’s program began in 2021 and has since notified users in more than 150 countries that they were likely targeted, reflecting the global scale of these operations.[3][14] Rights groups point out that a threat notification means Apple has detected activity consistent with a mercenary spyware attack against a device, but it does not prove that the attack succeeded; only a detailed forensic investigation can confirm whether spyware was actually implanted.[3] Even so, the alerts can provide the first indication that a journalist, activist, lawyer, or political figure has come under surveillance pressure.[3][12]

While mercenary spyware is not aimed at the average iPhone owner, the exploit techniques used against a few high‑value targets have a history of spreading once vulnerabilities become better understood.[3][15] Exploit chains developed for tightly focused operations can be reused, resold, reverse‑engineered or copied by other surveillance vendors, and eventually adapted by criminal groups and less sophisticated actors.[3][15] This means that zero‑day bugs first weaponized in secret against carefully chosen devices can later power broader campaigns once details leak through public research, patch analysis or underground markets, raising the baseline risk for everyone.[3][15] The expansion of Apple’s alerts is therefore as much about protecting those currently in the crosshairs as it is about signaling how serious these attacks are for the wider ecosystem.[1][9]

For defenders, Apple’s advice starts with hygiene: keep iPhones, iPads and Macs updated to the latest software releases, turn on automatic updates, use a strong device passcode with Touch ID or Face ID, and secure the Apple Account with a strong password and two‑factor authentication.[1] The company also urges users to turn on its Stolen Device Protection, install apps only from its official store, and rely on strong, unique passwords or passkeys rather than reusing credentials across services, steps that reduce the opportunities for attackers to pivot or deepen access if a device is compromised.[1] For those at elevated risk—such as investigative reporters, political opposition figures, human rights defenders or lawyers—Apple and independent researchers strongly recommend enabling Lockdown Mode across all Apple devices associated with the same account.[6][11][15] Apple says it is not aware of any successful mercenary spyware attack against a device with Lockdown Mode enabled, and researchers have documented at least one attempted spyware intrusion that the feature blocked, making it one of the most effective defenses currently available.[6][11]

Anyone who receives an Apple Threat Notification is urged not to ignore it, but also not to panic or immediately wipe their phone, since a factory reset can destroy evidence needed to understand what happened.[2][9][15] Experts advise first verifying the alert by signing in to the official Apple Account website, where a genuine notification will be clearly displayed, rather than relying solely on email or messaging, which scammers may try to spoof.[1][9][12][15] Apple directs recipients to seek specialist help from trusted digital security teams, including the Digital Security Helpline operated by civil society group Access Now, which offers 24/7 support to people facing targeted digital threats.[9][12] From there, responders typically guide victims through preserving logs, reviewing account and device settings, enabling Lockdown Mode, and warning close contacts whose communications may have been exposed, recognizing that mercenary spyware attacks rarely end with a single compromised phone.[2][9][12][15]

References

  1. About Apple threat notifications and protecting against mercenary …
  2. Apple Warns iPhone Users of Mercenary Spyware Attacks
  3. Apple threat notifications: What they mean and what you can do
  4. Apple claims a 100% protection rate with Lockdown Mode
  5. Apple issues new mercenary spyware alerts to targeted …
  6. iPhone spyware alert: What Apple customers need to know
  7. Apple’s Lockdown Mode is good for security — but its notifications …
  8. Access Now’s Digital Security Helpline and Apple threat notifications
  9. What is Apple threat notification & why is it creating a furore
  10. So You’ve Got an Apple Threat Notification, What Now? – iVerify

Comments

No comments yet. Why don’t you start the discussion?

Leave a Reply