Apple has issued a new round of spyware threat notifications to iPhone users across 110 countries, warning individuals who may have been specifically targeted by mercenary spyware attacks. The latest alerts were confirmed by the company after users reported receiving notifications that described the threat as “highly concerning.”
Apple said it notifies targeted users directly on their iPhones and through emails sent from Apple Threat Notifications. The precise form of an alert may vary depending on a user’s device model and software version.
Apple Says Alerts Target Individually Selected Users
The company says its threat notifications are intended to inform and assist people who may have been individually targeted by mercenary spyware because of who they are or what they do.
Apple has issued similar notifications on multiple occasions. The company said mercenary spyware attacks can cost millions of dollars to develop and often have a short operational life, making them particularly difficult to detect and prevent.
While Apple says its investigations cannot achieve absolute certainty, it describes the notifications as high-confidence alerts indicating that a user has been individually targeted. The company advises recipients to take such warnings seriously.
Mercenary spyware can exploit previously unknown software vulnerabilities and, in some cases, operate through so-called zero-click attacks that require no action from the targeted person. Such attacks can arrive through messaging services and may allow an attacker to access activity on a compromised device, including communications conducted through encrypted applications.
Campaign Spans 110 Countries
The notification campaign covers 110 countries, but security experts cited in the report stressed that the alerts do not indicate that ordinary iPhone users are broadly at risk.
Adam Boynton, senior enterprise strategy manager at Jamf, said mercenary spyware is a precision tool in which individuals are targeted because of who they are, what they know and who they communicate with. He said the economics of such spyware increasingly means that potential targets can include executives, negotiators and others holding privileged access, alongside journalists and activists.
Apple’s own data shows no known compromise of a device running Lockdown Mode, according to the report. The feature is designed to provide additional protection for users who believe they could face highly sophisticated digital attacks.
Security experts advise anyone receiving one of the notifications to treat it as a security incident immediately. Rather than wiping the device, users may need to preserve it, activate Lockdown Mode and seek expert assistance.
Lockdown Mode and Updates Among Recommended Defences
For users who believe they could be targets of spyware, enabling Lockdown Mode is presented as a key protective measure. Keeping iOS updated is also important because software updates can address vulnerabilities that attackers may otherwise exploit to install spyware.
If an iPhone may already have been targeted, restarting the device can sometimes disrupt spyware activity, although it does not necessarily remove malicious software entirely.
Apple’s latest warning comes as mercenary spyware remains a highly specialised threat aimed primarily at selected individuals rather than the broader population of iPhone users. The company continues to use threat notifications to alert people when its investigations indicate they may have been individually targeted by such attacks.
