Apple's Largest Spyware Alert Wave Yet: 110 Countries Notified in a Single Batch

Apple sent out a new wave of spyware threat notifications on Friday, August 14, 2026, alerting customers in 110 countries that they had been targeted with powerful spyware (TechCrunch). Investigators who track these incidents are reporting an unprecedented number of Apple customers receiving the alerts, according to reporting by Lorenzo Franceschi-Bicchierai at TechCrunch.
The digital rights group Access Now, which operates a helpline and reviews reports from affected users, confirmed that the latest batch of notifications appears to have been the largest yet. Mohammed Al-Maskati, director of the Access Now investigation team, told TechCrunch that since Friday the organization received a record high number of people reaching out for help. The volume of inquiries was around 30% to 40% higher than what the nonprofit's investigators usually receive after Apple sends out new notifications. An unusually large number of people also publicly reported receiving the Apple spyware notifications over the weekend, according to several social media posts. The influx included people who had already received threat notifications in the past.
Apple calls the malware used in these attacks "mercenary spyware" — a term for commercially produced spyware typically sold to governments, which use it to monitor specific individuals such as journalists, activists, or political opponents. Apple's threat notifications are designed to inform and assist users who may have been individually targeted by such attacks. The company now delivers these alerts as push notifications that appear on iPhone lock screens when its internal systems detect government spyware targeting a user's device (TechCrunch). The company has alerted people in more than 150 countries with these types of spyware alerts over the last few years. Apple also maintains Lockdown Mode, a feature that significantly restricts certain device functions to protect against extremely rare and highly sophisticated cyber attacks, including highly targeted mercenary spyware.
The August 14 wave reached at least one active conflict zone. A Ukraine Armed Forces soldier who received a notification told TechCrunch he initially thought it was a scam until he verified it with Apple. He also said he is aware of other people in Ukraine's military who received the same alert. The Computer Emergency Response Team of Ukraine (CERT-UA) did not respond to TechCrunch's request for comment on whether it was aware of other Ukrainians, particularly soldiers, receiving the notifications.
John Scott-Railton, a senior researcher at The Citizen Lab, told TechCrunch that the reports show spyware attacks may be more prevalent than people realize. Citizen Lab has been tracking the mercenary spyware ecosystem closely. In June 2025, the organization published the first forensic confirmation of Paragon Solutions' iOS mercenary spyware, nicknamed "Graphite," finding that journalists were among those targeted. That forensic work followed an earlier notification event on April 29, 2025, when Apple notified a select group of iOS users that they had been targeted with advanced spyware (Citizen Lab). Prior to that, in October 2023, Amnesty International stated that a round of Apple threat notifications confirmed that the abuse of highly invasive spyware by state actors around the world continues (Amnesty International).
The broader context here is one of steady expansion. Over the past several years, the volume and geographic spread of these notifications have shifted outward from a narrow set of high-profile dissidents and journalists to a substantially wider population of targeted individuals. The 30% to 40% surge in help requests documented by Access Now provides a quantifiable data point for that shift. A frontline soldier in Ukraine dismissing a legitimate Apple spyware alert as a scam until verifying it directly with the company also illustrates a persistent gap between the sophistication of government-grade mobile surveillance and the security awareness of the individuals in its crosshairs. That an active military deployment now intersects with iOS mercenary spyware targeting suggests the attack surface has expanded well beyond traditional civil society targets.
For security teams managing fleets of iOS devices, the August 14 wave reinforces the practical value of enabling Lockdown Mode for high-risk users and establishing a verification protocol for Apple threat notifications before dismissing them as phishing attempts. There is also a more encouraging angle: Apple's ability to identify and alert users across 110 countries in a single batch indicates that device-level telemetry and threat intelligence pipelines are increasingly able to surface government-grade intrusions at scale, which in turn gives targeted individuals and their support organizations a critical window to respond, lock down, and preserve forensic evidence.


