Illustrative image generated with AI
New Apple Warnings About Mercenary Spyware: What They Mean and How to Verify Their Authenticity
On August 13, 2026, some users reported on Reddit that they had received new Apple Threat Notifications —alerts Apple sends to iPhone owners when it
Text generated by artificial intelligence, published without human review. AI transparency
User Reports and the Meaning of the Alert
On August 13, 2026, some users reported on Reddit that they had received new Apple Threat Notifications—alerts Apple sends to iPhone owners when it believes they have been targeted by mercenary spyware.
These are not generic security notifications. Apple describes them as high-confidence alerts, based on investigative activity and threat intelligence. The company does not guarantee absolute certainty, but indicates that recipients are highly likely to have been individually selected as targets.
Apple has issued notifications of this kind several times a year since 2021. The new campaign therefore does not signal the introduction of a recent feature, but rather a new round of alerts sent to potential targets.
The company has not publicly attributed the notifications to any specific government, criminal group, company, or geographic region. Based on the alert alone, it is therefore impossible to determine who conducted the operation.
Who Is Targeted and Why These Attacks Are Different
Mercenary spyware is typically used in highly targeted operations against a limited number of individuals. Potential targets include journalists, activists, politicians, and diplomats—in other words, people who may handle sensitive information or carry out activities viewed as undesirable by interested governments and organizations.
According to Apple, these campaigns can require investments in the millions of dollars. Operators use sophisticated tools, often for short operational periods, while attempting to reduce the likelihood that the attack will be detected and analyzed.
The vast majority of iPhone users are not targeted by this type of activity. Receiving an alert is nevertheless different from receiving a standard security recommendation: it indicates that Apple has observed evidence consistent with individual targeting.
Apple cites NSO Group and its Pegasus spyware as a historical example of mercenary spyware. In some previous cases, forensic analysis confirmed Pegasus infections after recipients received a Threat Notification. This does not, however, show that the alerts distributed on August 13 concern Pegasus.
Apple does not publicly link every individual notification to the spyware used.
What Is Affected and How the Alert Is Delivered
The alerts primarily concern the user’s ecosystem, rather than a specific publicly identified iOS version. The products and services involved are:
- iPhone;
- Apple Account;
- Apple Threat Notification;
- Lockdown Mode;
- the
account.apple.comportal.
The exact software versions affected have not been disclosed. The case has not been presented as a vulnerability involving a list of affected versions, but as targeting activity detected through Apple’s threat intelligence.
The company says it sends these alerts to users in more than 150 countries. They are delivered through:
- email addresses associated with the Apple Account;
- iMessages sent to phone numbers linked to the account.
The sending addresses normally originate from [email protected]. However, this alone is not enough to prove that a message is genuine: phishing campaigns can imitate the sender, design, and language of Apple communications.
To prevent spyware operators from adapting their tools, Apple does not disclose the technical criteria used to issue a Threat Notification. The company must therefore balance two requirements: alerting the affected person quickly while avoiding disclosure of the indicators that led to the detection.
How to Distinguish a Genuine Alert from a Phishing Attempt
An authentic notification does not ask users to take immediate action through the message itself. In particular, Apple does not ask users to:
- click links in the email or iMessage;
- open attachments;
- install applications, profiles, or certificates;
- provide their Apple Account password;
- share verification codes.
Verification should be performed by manually signing in to account.apple.com, without using links contained in the communication. After authentication, a genuine alert appears at the top of the page.
This step is essential because a fake message could exploit the seriousness of the issue to steal credentials or multi-factor authentication codes, or to authorize the installation of malicious components. Even a message apparently sent from the correct address should not be considered valid until it has been verified through Apple’s portal.
The message also does not necessarily identify the spyware and, by itself, is not forensic proof that an infection has succeeded. Rather, it indicates that the user has been considered a high-priority target and that Apple has detected sufficient signals to issue a warning.
What to Do After Receiving the Alert
Anyone who receives a Threat Notification should treat it as a possible case of compromise or targeted activity, not as an ordinary informational email.
The first step is to verify the alert directly at account.apple.com. If the notification is present, avoid interacting with any links, attachments, profiles, or credential requests contained in the messages received.
Apple also recommends enabling Lockdown Mode on the iPhone. This mode reduces certain features and limits attack surfaces that can be exploited by highly sophisticated threats. It may affect the user experience, but it is specifically designed for people who believe they may be exposed to targeted operations.
It is also advisable to consult a cybersecurity professional to analyze the device and Apple Account. A professional investigation can help preserve evidence, assess potential signs of compromise, and review other connected accounts or devices.
Apple is not known to have provided specific technical details about the new alert distribution. Public indicators associated with this campaign—such as hashes, domains, exploits, or a signature attributed to a particular spyware—are therefore unavailable. The notification displayed in the account and subsequent device analysis remain the most relevant elements for distinguishing a genuine risk from an imitation attempt.
Sources
This article is an original reworking based on the sources below.
