"The extreme cost, sophistication, and worldwide nature of mercenary spyware attacks make them some of the most advanced digital threats in existence today," Apple said Thursday, as it pushed a fresh round of warnings to people it suspects have been individually targeted.
Apple's latest notification sweep: 110 countries, part of a multi-year effort
Apple said it has alerted an unspecified number of users in 110 countries in this most recent batch of warnings, and that it has notified customers in more than 150 countries overall since it began sending threat notifications in late 2021. The company described these messages as high-confidence alerts that a user has been singled out by a mercenary spyware attack, and it urged recipients to take the notifications seriously.
Who Apple says is typically targeted
According to Apple, notifications usually go to people who may have been individually targeted because of "who they are or what they do." The company specifically lists journalists, activists, politicians, and diplomats as the kinds of individuals who tend to be singled out. Apple added that these campaigns "tend to focus on a very small number of specific individuals and their devices," distinguishing mercenary spyware operations from broader, lower-effort cybercrime.

Nobody's watching your logs at 2 AM.
Full SOC coverage without building one. Nubivance deploys and manages Rapid7 InsightIDR and MDR for organizations that need detection and response, not another dashboard.
Get coverageHow Apple delivers its threat notifications
Apple sends its warnings through three distinct channels to reach affected users:
- An Apple Threat Notification alert appears directly on the user's iPhone, visible on the Lock Screen and in Settings.
- An email is sent to the addresses associated with the user's Apple Account; the message is dispatched from "threat-notifications@email.apple[.]com."
- A threat notification banner is displayed at the top of the user's Apple Account page after signing in to account.apple[.]com.
The multi-channel approach aims to make sure an affected individual sees the alert even if one pathway is missed or unavailable.
Why Apple will not name attackers or publicize technical triggers
Apple stated it does not attribute the attacks or resulting threat notifications to any specific attackers or geographical regions. The company explained that it cannot share specifics on what causes it to issue the alerts, because doing so "may help the spyware attackers refine their tactics in response to public disclosure." In short, Apple presents the notices as a defensive, confidentiality-sensitive tool rather than a public forensic report.
What this means for journalists, activists, and diplomats
- Journalists: Those who receive a notification should treat it as a high-confidence signal of targeted surveillance and follow Apple’s protective steps rather than waiting for public attribution or technical details.
- Activists: The private, individualized nature of these alerts means activists may be warned without broader disclosure; the company’s emphasis on confidentiality is designed to avoid amplifying attacker tradecraft.
- Diplomats: For officials working with sensitive information, the notice is intended to be actionable immediately—Apple frames the warning as cause to implement device and account protections without needing attacker attribution.
Apple also warned about the capabilities of the mercenary spyware market: vendors invest substantial time and resources to develop exploits that deliver surveillance payloads, making these operations "much more advanced than regular cybercrime activity."
To mitigate risk, Apple advised users who receive a threat notification to take a set of concrete steps: update devices to the latest software version; secure devices with a passcode, Touch ID, or Face ID; enable two-factor authentication for the Apple account; turn on Stolen Device Protection; install apps only from trusted sources; enable Lockdown Mode; and refrain from opening links or attachments from unknown senders.
Apple’s public messaging frames these warnings as a narrowly targeted defensive measure: high-confidence alerts to a small group of likely-at-risk individuals, delivered by three channels, and accompanied by specific, actionable protections. The company’s refusal to attribute or to disclose the technical triggers for its alerts is explicit and framed as necessary to avoid enabling attackers.
Apple began this notification program in late 2021 and, by its account, has expanded it to over 150 countries — with the latest round covering 110 countries. The practical question the record leaves is concrete: when an individual receives one of these high-confidence notices, will institutions and networks they touch be prepared to act quickly on the limited but urgent guidance Apple provides?




