Skip to main content
Emerging ThreatsMalware & Ransomware

Apple Warns Users of Mercenary Spyware Attacks on iPhones

iPhone on a neutral surface with soft ambient lighting and subtle shadows.

Apple sent a new batch of threat notifications on August 13, warning some account holders that it had detected a "mercenary spyware attack targeted at your iPhone."

Apple’s August 13 notification batch

On August 13 Apple pushed another round of its so‑called threat notifications to users after its internal systems flagged highly targeted activity. The company has issued these alerts multiple times a year since 2021 when it detects suspected mercenary spyware operations against individual iPhone users. Apple says it delivers notifications by email and iMessage to the addresses and phone numbers associated with the recipient’s Apple Account.

How Apple frames "mercenary spyware" and Pegasus

Apple defines the incidents it warns about as mercenary spyware attacks: expensive, highly sophisticated operations typically aimed at a very small number of people. In its public materials Apple notes that "mercenary spyware attacks cost millions of dollars and often have a short shelf life, making them much harder to detect and prevent," and that "the vast majority of users will never be targeted by such attacks."

Apple does not identify the specific spyware involved in individual alerts, but it has cited NSO Group’s Pegasus as an historical example of the mercenary spyware class. Forensic investigations tied to earlier Apple threat notifications have confirmed Pegasus infections in some cases; the company itself, however, does not attribute a given alert to any particular government, company, or geographic region.

How Apple delivers and how to verify a genuine alert

Apple says real threat notification emails typically come from threat-notifications@email.apple.com and will also appear as an iMessage to numbers tied to the Apple Account. To help users separate authentic notices from scams, Apple warns it will never ask recipients to click a link, open a file, install an app or profile, or provide an Apple Account password or verification code as part of the notification process.

Recipients can confirm whether an alert is genuine by signing in directly at account.apple.com; if Apple delivered a threat notification it will appear at the top of the account page after login.

Apple’s assessment: high‑confidence alerts based on internal intelligence

Apple frames these messages not as generic warnings but as the product of its own threat intelligence and investigations. The company calls them "high-confidence alerts" and cautions that, while investigations "can never achieve absolute certainty," recipients should take the notifications seriously because they indicate an individual targeting event. Apple also says it cannot disclose what specific findings trigger a notification because doing so could allow mercenary spyware operators to alter techniques to evade detection.

What this means for journalists, activists, politicians, and diplomats

  • Journalists: Because Apple lists journalists among the types of potential targets, reporters who receive a notification should regard it as a strong signal of individualized targeting and follow Apple's verification and response steps.
  • Activists: Activists are explicitly named by Apple as a potential target group; receiving a notification implies an elevated risk profile and the need for immediate, specialist help.
  • Politicians and diplomats: Apple includes politicians and diplomats on its list of possible targets, underscoring that these alerts can reflect high‑value, targeted operations rather than opportunistic or mass malware campaigns.

Apple’s recommended next steps and the practical limits

Apple advises users who believe they have been affected to enable Lockdown Mode and to reach out to a cybersecurity expert. Beyond that, Apple will not publicly tie individual notifications to specific actors or regions, limiting what can be learned from each alert. The company’s emphasis on internal detection, non‑attribution, and the difficulty of detecting short‑lived, expensive mercenary tools frames these notices as both a rare and serious flag: rare because most users will never be targeted, serious because the tools and operations involved are described as highly sophisticated.

For anyone who receives one of these messages, Apple’s own guidance is straightforward: verify the notification through your Apple Account page, do not follow any unexpected links or install anything based on the message, enable Lockdown Mode, and consult a cybersecurity professional. How widely such alerts are occurring beyond the reported August 13 batch — and whether Apple will provide more public technical detail about detection criteria — remains tied to the company’s internal threat‑hunting choices and its stated concern about helping attackers adapt.

Original story