• Home
  • AI news
  • Apple Sends Mercenary Spyware Warnings to Users in 110 Countries
Apple warns users in 110 countries about mercenary spyware attacks

Apple Sends Mercenary Spyware Warnings to Users in 110 Countries

Apple has sent a new wave of threat notifications to users in 110 countries, warning that their iPhones, iPads or Macs may have been targeted by sophisticated “mercenary spyware.”

The alerts are aimed at people Apple believes may have been individually targeted because of who they are or what they do. The company has been sending these warnings periodically since 2021, and says it has now notified users in more than 150 countries in total.

The latest campaign is another reminder that highly advanced commercial spyware remains a global cybersecurity problem, particularly for journalists, activists, politicians, researchers and other people who may be considered high-value targets.

What Did Apple Warn Users About?

The notification tells affected users that Apple detected activity consistent with a targeted mercenary spyware attack.

The important word is targeted.

This is not the same as a normal malware campaign trying to infect thousands or millions of random devices.

Mercenary spyware is typically developed and sold for highly targeted surveillance operations. These attacks can involve expensive exploits and significant technical resources.

Apple says such attacks can cost millions of dollars and are considerably more sophisticated than ordinary consumer malware.

Apple does not publicly identify the attacker behind an individual notification.


What Is Mercenary Spyware?

Mercenary spyware is highly sophisticated surveillance software developed by private companies and sold to governments or other customers.

One of the best-known examples is Pegasus, developed by NSO Group.

Other spyware operations have also been linked to companies such as Paragon Solutions, whose Graphite spyware was found on devices belonging to journalists who had previously received Apple threat notifications.

These tools can potentially give attackers access to sensitive information stored on a device.

Depending on the spyware and the vulnerability being exploited, attackers may be able to access things such as:

  • Messages
  • Photos
  • Contacts
  • Files
  • Location information
  • Communications
  • Other sensitive device data

Some attacks can also be zero-click attacks, meaning the victim may not need to click a malicious link or install anything for the attack to work. Researchers previously confirmed a sophisticated zero-click attack involving Paragon’s Graphite spyware.


Why Is Apple Sending These Warnings?

Apple monitors its ecosystem for signs of highly targeted attacks.

The company says its threat notifications are based on its internal threat intelligence and investigations.

Apple does not reveal exactly what evidence triggers a notification because doing so could help attackers change their techniques and avoid detection.

The company describes these alerts as high-confidence warnings.

However, receiving one does not necessarily mean that a device was successfully compromised.

It means Apple believes the user was individually targeted by an attack consistent with mercenary spyware.


Why 110 Countries?

The latest wave is particularly notable because Apple sent notifications to affected users across 110 countries.

That does not mean that every country has the same spyware campaign or that the same attacker is responsible everywhere.

Apple has specifically said that it does not attribute its threat notifications to specific attackers or geographic regions.

The large geographic reach instead highlights how global the commercial spyware industry has become.

Apple has previously sent notifications to users in dozens of countries during individual campaigns. For example, it warned users in 92 countries in April 2024 and 98 countries in July 2024.


Who Is Usually Targeted?

Mercenary spyware attacks tend to focus on a small number of specific people.

Historically, targets have included:

  • Journalists
  • Human rights activists
  • Political figures
  • Diplomats
  • Researchers
  • Government officials
  • Business leaders
  • People involved in sensitive investigations

Apple says the attacks are often linked to who a person is or what they do.

This makes the latest warning different from a normal security alert.

The attacker may not be interested in stealing random passwords or money.

They may specifically want information from a particular person.


Apple Does Not Say Who Is Behind the Attacks

One of the biggest questions after receiving an alert is:

Who is trying to spy on me?

Apple generally does not answer that question.

The company says revealing details about how it identifies attacks could help spyware operators improve their methods.

It also avoids publicly attributing threat notifications to specific countries or attackers.

Security researchers may sometimes identify the spyware after analyzing an affected device.

For example, researchers from Citizen Lab previously confirmed that two journalists who received Apple’s 2025 notification had been targeted with Paragon’s Graphite spyware.


What Should You Do If You Receive the Alert?

Apple says users who receive a genuine threat notification should take it seriously.

One of the most important steps is to enable Lockdown Mode.

Lockdown Mode is Apple’s high-security feature designed for people who may face extremely sophisticated digital attacks.

It restricts or changes the behavior of several device features to reduce potential attack surfaces.

Apple also recommends keeping devices and applications fully updated.

Users should also:

  • Update iOS, iPadOS or macOS
  • Use a strong device passcode
  • Enable two-factor authentication
  • Keep applications updated
  • Avoid suspicious links and attachments
  • Seek professional security assistance

Apple recommends that people who receive these alerts seek expert help, including from Access Now’s Digital Security Helpline.


Be Careful of Fake Apple Spyware Alerts

There is another important security issue.

Scammers can imitate Apple’s threat notifications.

A genuine Apple threat notification will not ask you to:

  • Click a suspicious link
  • Install an unknown application
  • Install a configuration profile
  • Provide your Apple Account password
  • Give someone your verification code

Apple says the safest way to verify a notification is to manually sign in to account.apple.com and check whether the threat notification appears there.

This is especially important because a fake security warning could itself be an attempt to steal your account information.


Does This Mean Regular iPhone Users Are at Risk?

For most people, no.

Apple says the vast majority of users will never be targeted by mercenary spyware.

These attacks are expensive and highly targeted.

However, that does not mean ordinary iPhone users should ignore cybersecurity.

Regular malware, phishing, stolen passwords and scams remain much more common threats.

Keeping your device updated, using strong passwords and enabling two-factor authentication are still important for everyone.


Why These Warnings Matter

Apple’s notification system has become an important source of information for cybersecurity researchers.

In several cases, researchers have used Apple’s alerts as the starting point for investigating spyware campaigns.

TechCrunch reported that Apple’s notifications have helped researchers document spyware abuse in countries including India, El Salvador and Thailand.

This creates an important chain:

Apple detects suspicious activity → user receives warning → security researchers investigate → spyware campaign may be identified.

That can help expose surveillance operations that would otherwise remain hidden.


The Bigger Problem With Commercial Spyware

The biggest concern is not one particular spyware company.

It is the growth of an entire industry selling powerful surveillance capabilities.

Governments have legitimate reasons to investigate serious crimes and security threats.

But human rights organizations and security researchers have repeatedly raised concerns about commercial spyware being used against journalists, activists and political opponents.

The technology is particularly controversial because it can provide extremely invasive access to personal devices.

And as smartphone security improves, spyware developers are increasingly looking for sophisticated vulnerabilities that can bypass those defenses.


Apple’s Security Battle Is Getting Harder

Apple has invested heavily in protecting the iPhone from advanced attacks.

Features such as Lockdown Mode are specifically designed for people who face unusual security risks.

Apple has also continued improving the underlying security architecture of newer iPhones and operating systems.

But the spyware industry is evolving at the same time.

Researchers have recently documented new hacking tools capable of targeting iPhones, including campaigns that exploited users running older versions of Apple’s software.

This creates an ongoing race:

Apple improves security → attackers discover new vulnerabilities → Apple fixes them → attackers develop new techniques.


The Bigger Picture

Apple’s latest warning campaign shows that mercenary spyware is no longer an isolated cybersecurity issue.

The company has now warned users across more than 150 countries over time, with the latest campaign reaching users in 110 countries.

For the people who receive these notifications, the message is serious: someone may have specifically chosen them as a target.

But the broader lesson is equally important.

Modern smartphones contain enormous amounts of personal and professional information, making them valuable targets for sophisticated surveillance.

Apple’s warning system cannot prevent every attack, but it gives potential victims something extremely valuable:

early warning.

And in a spyware attack, knowing that you may be targeted can give you the opportunity to secure your device, seek expert help and prevent a sophisticated attack from becoming a silent long-term compromise.

Related Posts

AI-Powered Cyberattacks Are Becoming a Real Threat: Taiwan Targeted in Unusual Attack

Taiwan has disclosed an unusual cyberattack in which hackers used AI-assisted tools to target government agencies, highlighting a…

ByByBuild Bevy Aug 14, 2026

Jeff Dean’s New AI Startup Reportedly Targets a $10 Billion Valuation

Former Google chief scientist Jeff Dean is reportedly in talks to raise around $1 billion for his new…

ByByBuild Bevy Aug 14, 2026

AI Pricing War Gets Serious as OpenAI and Anthropic Cut Costs

The AI industry is entering a new price war. OpenAI and Anthropic are cutting the cost of some…

ByByBuild Bevy Aug 14, 2026

Databricks Raises $5 Billion at $190 Billion Valuation as AI Business Booms

Databricks has raised $5 billion in new funding, pushing its valuation to $190 billion. The latest investment shows…

ByByBuild Bevy Aug 14, 2026
Scroll to Top