Apple Sent Spyware Warnings to People in 110 Countries — Here's What That Means

Apple sent out a new wave of spyware threat notifications on Friday, August 14, 2026, alerting customers in 110 countries that they had been targeted with powerful spyware (TechCrunch). Investigators who track these incidents say an unprecedented number of Apple customers received the alerts, according to reporting by Lorenzo Franceschi-Bicchierai at TechCrunch.
The digital rights group Access Now, which runs a helpline and reviews reports from affected users, confirmed that this latest batch of notifications appears to have been the largest yet. Mohammed Al-Maskati, director of the Access Now investigation team, told TechCrunch that since Friday the organization received a record high number of people reaching out for help. The volume of inquiries was around 30% to 40% higher than what the nonprofit usually sees after Apple sends out new notifications. An unusually large number of people also publicly reported receiving the alerts over the weekend, according to several social media posts. The influx included people who had already received threat notifications in the past.
Spyware is a type of malicious software that lets someone secretly monitor what you do on your phone — reading your messages, tracking your location, even turning on your camera. Apple calls the kind used in these attacks "mercenary spyware," meaning it is built by companies and sold to governments, which use it to watch specific people such as journalists, activists, or political opponents. Apple's threat notifications are designed to tell users when the company believes they have been individually targeted by such attacks. The company now sends these alerts as push notifications that pop up on iPhone lock screens (TechCrunch). Over the last few years, Apple has alerted people in more than 150 countries with these types of warnings. Apple also offers a feature called Lockdown Mode, which shuts down certain phone functions to make it much harder for sophisticated spyware to work.
The August 14 wave reached at least one active conflict zone. A soldier in the Ukraine Armed Forces who received a notification told TechCrunch he initially thought it was a scam until he verified it with Apple. He also said he is aware of other people in Ukraine's military who received the same alert. The Computer Emergency Response Team of Ukraine (CERT-UA) did not respond to TechCrunch's request for comment on whether it was aware of other Ukrainians, particularly soldiers, receiving the notifications.
John Scott-Railton, a senior researcher at The Citizen Lab, told TechCrunch that the reports show spyware attacks may be more common than people realize. Citizen Lab has been tracking the mercenary spyware world closely. In June 2025, the organization published the first forensic confirmation of spyware made by a company called Paragon Solutions, nicknamed "Graphite," finding that journalists were among those targeted. That work followed an earlier event on April 29, 2025, when Apple notified a select group of iOS users that they had been targeted with advanced spyware (Citizen Lab). Before that, in October 2023, Amnesty International said that a round of Apple threat notifications confirmed that governments around the world continue to use highly invasive spyware against people (Amnesty International).
The broader context here is one of steady expansion. Over the past several years, these notifications have moved outward from a small group of high-profile dissidents and journalists to a much wider set of people. The 30% to 40% surge in help requests to Access Now puts a number on that growth. A frontline soldier in Ukraine dismissing a real Apple spyware alert as a scam until he checked with the company also shows a gap between how sophisticated this surveillance technology is and how aware its targets are that they might be in its sights. That a soldier on active military duty is now receiving these alerts suggests spyware targeting has spread well beyond the journalists and activists who were once the typical targets.
For anyone managing a group of iPhones, the August 14 wave reinforces two practical steps: turn on Lockdown Mode for users who face elevated risk, and set up a way to verify whether an Apple threat notification is real before treating it as a phishing scam. There is also a more hopeful side to this. Apple's ability to identify and alert users across 110 countries in a single batch means the company's detection systems are getting better at catching these government-grade intrusions at scale. That gives the people who are targeted, and the organizations that support them, a critical window to respond, lock down their devices, and preserve evidence.


