Apple Warns iPhone Users Targeted by Mercenary Spyware
A fresh Apple threat-notification wave is aimed at individually targeted users, with alerts now appearing directly on iPhone Lock Screens and in Settings.
What you need to know
- Apple has issued a fresh round of high-confidence alerts for people it believes were individually targeted by mercenary spyware.
- Genuine alerts can appear on an iPhone Lock Screen, in Settings, on the Apple Account website and by email.
- Most iPhone owners are not at risk, but Apple says recipients should update devices and enable Lockdown Mode.
Apple has issued a fresh batch of threat notifications to people it believes may have been individually targeted by mercenary spyware attacks, updating its public guidance on Thursday 13 August. The warnings are designed for a small group of high-risk users rather than the wider iPhone-owning public, but Apple’s revised process now puts alerts directly on an iPhone’s Lock Screen and in Settings.

The company describes these as high-confidence warnings of attacks using exceptional resources against specific people. Apple says mercenary spyware operations are “vastly more sophisticated than regular cybercriminal activity”, and warns that recipients should take a genuine notification seriously.
Apple has not named the spyware involved in this latest notification wave, the people or organisations behind it, any government sponsor, or the locations of affected users. It has also not confirmed how many people received the latest alerts. Reports that the wave reached users in 110 countries have been attributed to TechCrunch, but that figure does not appear in Apple’s current support document.
Where a real Apple spyware warning will appear
Apple’s updated support page sets out several places where a legitimate threat notification may appear. Most visibly, it can arrive as an alert on an iPhone Lock Screen or within Settings. Users may also see a banner at the top of their Apple Account page after signing in at account.apple.com.
In addition, Apple says it sends an email from Apple Threat Notifications, currently using the address threat-notifications@email.apple.com. Notification types can vary according to a person’s device model and software version, so a user may not necessarily see every form of alert listed by the company.
The important caveat is that an Apple threat notification will not ask someone to click a link, open an attachment, install an app or configuration profile, or hand over an Apple Account password or verification code. That detail matters because security warnings are a familiar route for phishing attempts.
Anyone who receives a message claiming to be from Apple should avoid using links within it to check whether it is genuine. Apple advises users to sign in directly at account.apple.com instead. A matching alert on the account page, or one displayed on the device itself, is a much stronger indication that it is authentic.
What Apple says recipients should do
Apple’s first recommendation is to update iPhones and other Apple devices to the latest available software, which includes security fixes. It also tells people who receive a notification to enable Lockdown Mode, Apple’s additional protection option for individuals who have a specific reason to believe they could be targeted by sophisticated digital attacks.
The company recommends seeking specialist support too, including the Digital Security Helpline operated by Access Now. Apple says the service offers assistance around the clock, seven days a week.
“Although our investigations can never achieve absolute certainty, Apple threat notifications are high-confidence alerts that a user has been individually targeted by a mercenary spyware attack, and should be taken very seriously.”
Apple does not reveal the technical indicators that cause it to send a notification. Its reasoning is straightforward: publishing those details could help spyware operators adapt their methods and evade detection.
A long-running programme with a new delivery method
Apple has sent these alerts multiple times a year since 2021. The company says it has notified users in more than 150 countries over that period. Earlier warnings were commonly described as relating to “state-sponsored” attackers, while Apple now uses the term “mercenary spyware attacks”.
There have been publicly reported waves before. TechCrunch reported that Apple warned users in 92 countries in April 2024. In spring 2025, Engadget reported that recipients said a similar Apple warning referred to attacks affecting users in 100 countries, with Italian journalist Ciro Pellegrino and Dutch commentator Eva Vlaardingerbroek among reported recipients.
The new aspect of the current guidance is the addition of direct device alerts. Previously, the Apple Account site and email were central routes for these notices; a Lock Screen and Settings alert should make the warning more immediate for someone whose phone is in regular use.
What this means for UK iPhone owners
For the overwhelming majority of UK iPhone users, this is not evidence of a broad attack on consumer devices. Apple says such operations are targeted at a very small number of individuals and notes that spyware campaigns can cost millions of dollars while often having a short operational lifespan. Historically, people at elevated risk have included journalists, activists, politicians and diplomats.
“The vast majority of users will never be targeted by such attacks.”
That does not make everyday security habits irrelevant. Keeping an iPhone, iPad and Mac updated remains Apple’s central advice because updates bring security fixes. But there is no suggestion that ordinary users should enable Lockdown Mode purely because of this news, or panic if no official warning appears.
If an alert does arrive, treat it as urgent but verify it through Apple’s own account portal rather than a message link. Apple’s guidance is clear: update devices, enable Lockdown Mode, and seek specialist help. The crucial distinction is between a serious, individually targeted notification and a convincing-looking scam trying to exploit the same anxiety.
Why it matters
This is not a warning that ordinary UK iPhone owners are facing a widespread spyware outbreak. However, the new on-device delivery makes a genuine alert harder to miss for people at particular risk, while also giving scammers another security-themed message to imitate. The sensible response for most buyers remains routine software updates and checking any alarming message directly through Apple’s account portal rather than following a link.

