Technology

Apple Sends Mercenary Spyware Warnings to Users in 110 Countries

Martin HollowayPublished 7h ago5 min readBased on 11 sources
Reading level
Apple Sends Mercenary Spyware Warnings to Users in 110 Countries
source:apple.com

Apple has sent a new round of mercenary spyware attack notifications to users across 110 countries, the largest geographic scope recorded for the company's threat-notification program. The alerts, reported on August 14, 2026, include updated guidance on securing affected devices, notably Apple's Lockdown Mode. Firstpost

The warnings were first surfaced by Citizen Lab senior researcher John Scott-Railton, who noted that mercenary spyware such as Pegasus is used by governments to surveil targeted individuals. Apple periodically sends these notifications when its internal systems detect that a user has been individually targeted by a mercenary spyware attack. Engadget

Apple told TechCrunch that it updated the user experience around the spyware warnings to make it easier for recipients to access relevant information. The company also published a new support page (support.apple.com/en-us/102174) explaining what mercenary spyware is and what targeted users can do. Engadget

Mercenary spyware refers to sophisticated surveillance tools that commercial companies sell to state actors and governments. These tools are used to target specific individuals — journalists, activists, politicians, and diplomats. The attacks cost millions of dollars to deploy and are highly targeted, meaning most users will never be on the receiving end. But for those who are, the attacks are difficult to detect and prevent. Engadget

Apple states that its investigations can never achieve absolute certainty, but that its threat notifications are high-confidence alerts indicating a user has been individually targeted. The company says it cannot disclose how it determines who is under attack, because that information could help bad actors evade detection. Engadget

Receiving an Apple notification does not necessarily mean the user's data has been compromised. Rather, Apple detected activity on the device consistent with a mercenary spyware attack. The distinction matters: the alert is about targeting, not confirmed exfiltration (data theft). Engadget

Apple advises recipients to enable Lockdown Mode, which switches the device into an extreme protection configuration. When enabled, Lockdown Mode blocks most message attachments, FaceTime calls, invitations for Apple services, and shared photo albums. Users may receive notifications when an app or feature is limited by Lockdown Mode, and a banner in Safari indicates the mode is active. Engadget

Apple also directs targeted users to seek expert assistance, specifically naming the Digital Security Helpline operated by the nonprofit Access Now, which offers rapid-response emergency support. Engadget

The scope of Apple's notifications has expanded steadily. In April 2024, Apple warned users in India and 91 other countries of possible mercenary spyware targeting. At that time, the company dropped the term "state-sponsored attacks" from its threat notifications in favor of "mercenary spyware attack," a terminology shift that more precisely describes the commercial nature of the surveillance industry. Reuters

In December 2025, Apple sent another round of cyber threat notifications to users in 84 countries, this time joined by Google, which issued its own parallel alerts. The current round reaches 110 countries, a notable expansion in geographic coverage over roughly eight months. Reuters

The support page Apple published alongside this round of notifications is worth examining for what it reveals about the company's evolving approach to user-facing threat intelligence. Apple publishes localized versions, including separate en-us and en-ie editions, suggesting the company is tailoring its guidance to different regulatory and threat environments. The page explains the nature of mercenary spyware, the limitations of Apple's detection capabilities, and the concrete steps a targeted user should take. Apple Support

The trajectory here is clear, even if the underlying threat landscape is not fully visible. Each successive round of notifications covers more countries and reaches more users. Apple has refined its terminology, improved the notification experience, and built out a support infrastructure that points users toward both technical mitigations (Lockdown Mode) and human expertise (Access Now's helpline). The company is also careful to frame what it can and cannot promise: high-confidence detection, not certainty, and targeting alerts, not confirmed compromise.

For security professionals advising at-risk users — particularly those in journalism, activism, diplomacy, and politics — the practical takeaways are straightforward. Take Apple's threat notifications seriously; they represent high-confidence intelligence from a platform-level vantage point that most independent investigators cannot replicate. Enable Lockdown Mode on any device that receives a notification, understanding the usability trade-offs it imposes. And engage expert help rather than attempting solo forensics, since mercenary spyware is designed to be difficult to detect and persistently evasive.

The broader context is that the commercial spyware industry has matured into a persistent, well-funded ecosystem. Apple's notifications are a defensive signal in an asymmetric contest: the company can detect and warn, but the tools themselves remain in circulation, sold to state actors who deploy them against individuals whose work makes them targets. The expansion from 91 countries in 2024 to 110 in 2026 suggests either broader deployment, better detection, or both.