← Back to Feed

Apple Warns Users in 110 Countries They May Be Targets of Mercenary Spyware

August 14, 2026 · The Hacker News · Severity: MEDIUM

Apple has issued fresh warnings to users in 110 countries who may be targeted by mercenary spyware, part of an ongoing effort since 2021 that has now reached over 150 countries. The company describes these as some of the most advanced digital threats, typically aimed at high-profile individuals such as journalists, activists, politicians, and diplomats. Apple emphasizes the sophistication and cost of these attacks, which are far beyond regular cybercrime. Apple alerts users through multiple channels: a notification on the iPhone's lock screen and Settings, an email from a specific Apple address, and a banner on the user's Apple Account page. The company cannot share specific reasons for the alerts to prevent attackers from adapting. It advises users to take the warnings seriously and follow security best practices, such as updating software, enabling two-factor authentication, and using Lockdown Mode.

Apple on Thursday sent a fresh batch of notifications to customers whom it suspects may have been targeted by mercenary spyware attacks. In a statement shared with TechCrunch, the iPhone maker said it alerted an unspecified number of users targeted in 110 countries and that it has notified customers in over 150 countries to date. Apple began sending threat notifications to users in late 2021. "The extreme cost, sophistication, and worldwide nature of mercenary spyware attacks make them some of the most advanced digital threats in existence today," the tech giant said . "As a result, Apple does not attribute the attacks or resulting threat notifications to any specific attackers or geographical regions." Typically, such notifications are sent to people who may have been individually targeted because of "who they are or what they do," including journalists, activists, politicians, and diplomats. They tend to focus on a very small number of specific individuals and their devices, and are much more advanced than regular cybercrime activity owing to the amount of time and resources that are sunk in by spyware vendors to develop exploits that can be wielded to deliver the surveillance payload. Apple described its threat notifications as high-confidence alerts that a user has been singled out by a mercenary spyware attack, urging users who receive them to take the threat seriously. It also said it cannot share specifics on what causes it to issue the alerts, as doing so may help the spyware attackers refine their tactics in response to public disclosure. Users are notified in three different ways - An Apple Threat Notification alert appears on the user's iPhone, on the Lock Screen and in Settings. A notification is sent to the email addresses associated with the user's Apple Account. The email is sent from "[email protected][.]com." A threat notification banner is displayed at the top of the user's Apple Account page after they sign in to account.apple[.]com. To stay safe, it's advised to update devices to the latest software version, secure devices with a passcode, Touch ID, or Face ID, enable two-factor authentication (2FA) for the Apple account, turn on Stolen Device Protection , install apps only from trusted sources, turn on Lockdown Mode , and refrain from opening links or attachments from unknown senders. Found this article interesting? Follow us on Google News , Twitter and LinkedIn to read more exclusive content we post.

Key Takeaways

  • Apple has sent threat notifications to users in 110 countries about potential mercenary spyware attacks, with over 150 countries notified since 2021.
  • These attacks target specific individuals like journalists and activists, using advanced exploits that require significant resources to develop.
  • Apple provides high-confidence alerts through multiple channels but withholds specific detection methods to avoid aiding attackers.
☕ Buy a Coffee