Apple has sent its largest wave of spyware threat notifications yet, warning iPhone users in 110 countries that they’ve likely been individually targeted by mercenary spyware. For the first time, the alert doesn’t just arrive by email, it now shows up directly on the Lock Screen and in Settings, making it much harder to miss or dismiss as spam.
Apple has run this threat notification program since late 2021, but this is the biggest single batch of warnings it has ever sent, and the first time the alert has appeared as an on-device notification rather than only through email, iMessage, and a banner on the user’s Apple Account page.
What the warning actually means
Apple describes these as “high-confidence alerts that a user has been individually targeted by a mercenary spyware attack, and should be taken very seriously.” That phrasing matters: this isn’t a generic security tip or a routine phishing warning, it’s Apple telling a specific person that its threat intelligence believes someone paid to surveil them specifically. Apple says these attacks are historically linked to government-backed actors using spyware built by private companies, NSO Group’s Pegasus being the best-known example, and typically aimed at journalists, activists, politicians, and diplomats rather than ordinary users.
How to know it’s real
Because the wording sounds alarming, it’s also exactly the kind of message scammers love to fake. Apple has been explicit about what a genuine threat notification will never do: it will never ask you to click a link, open a file, install an app or a configuration profile, or hand over your Apple Account password or verification code. To confirm a notification is legitimate, sign in directly at account.apple.com and check whether the same warning appears at the top of the page. Genuine notifications also arrive by email from threat-notifications@email.apple.com.
What to do if you get one
Apple’s own guidance for anyone who receives a real alert is straightforward: turn on Lockdown Mode, which sharply restricts message attachments, FaceTime calls, and shared album invitations to cut off common spyware entry points, then seek expert help through a resource like Access Now’s Digital Security Helpline. Access Now says it’s already seeing a record number of people reaching out since this latest wave went out. Beyond that, Apple recommends the same baseline hygiene that helps against spyware generally, keeping the device on the latest software update, locking it with a passcode, Face ID, or Touch ID, and turning on two-factor authentication with a strong, unique Apple Account password.
Why 110 countries at once
The scale of this batch is what’s drawn the most attention. A warning reaching users across 110 countries in a single wave suggests either a broad, coordinated surveillance campaign or multiple separate campaigns detected around the same time, rather than an isolated incident. Apple hasn’t named the specific spyware operators or attributed the campaigns to particular governments, which is consistent with how it has handled past waves, but the size of this one is unprecedented for the program.
Bottom line
Realistically, almost nobody reading this will ever get one of these notifications, mercenary spyware is expensive and targeted, not something used against the general public. But if you do receive one, treat it as genuine unless you can’t verify it through account.apple.com, don’t tap any links, and go straight to Lockdown Mode and expert help rather than trying to handle it alone.
