Breaking
SecurityConfirmed

Apple Alerts Users of Spyware Targeting

New batch of Apple threat notifications flags mercenary spyware attacks, urging users to take them seriously.

··1 hour ago·3 min read
man using smartphone
Photo by Volodymyr Proskurovskyi on Unsplash

You're not alone if you just received an "Apple Threat Notification" saying it detected a "mercenary spyware attack targeted at your iPhone." Some users on Reddit report receiving these alerts today after Apple sent a new batch of threat notifications on August 13, but the feature itself is not new.

New Batch Sent August 13

Apple sent a new batch of alerts to users on August 13, as evidenced by reports on Reddit. This is part of a pattern: Apple has been sending these threat notifications multiple times a year since 2021, when it detects highly targeted mercenary spyware attacks.

It's worth pointing out that Apple does not identify the spyware behind individual alerts, so there's no evidence that today's notifications are specifically related to Pegasus. However, Apple itself cites NSO Group's Pegasus as an example of mercenary spyware historically associated with this type of attack, and forensic investigations into previous Apple threat notifications have confirmed Pegasus infections in some cases.

Who's Targeted and Where

In a support document, Apple previously confirmed it sends threat notifications to users in more than 150 countries after detecting highly targeted mercenary spyware attacks against specific iPhone users. The list of potential targets includes journalists, activists, politicians, and diplomats, who have historically been among those targeted by this type of spyware.

These attacks are expensive, highly sophisticated, and typically aimed at a very small number of people. "Mercenary spyware attacks cost millions of dollars and often have a short shelf life, making them much harder to detect and prevent," Apple explained. "The vast majority of users will never be targeted by such attacks."

Not Attributing Attacks

The company does not attribute individual alerts to a specific government, company, or geographical region. This lack of attribution can complicate investigations for users trying to understand the source of the attack, but Apple says it relies on its own threat intelligence and investigations to identify suspected mercenary spyware activity.

Apple says threat notifications should be taken seriously because they are "high-confidence alerts" and not just a regular warning. "Although our investigations can never achieve absolute certainty, Apple threat notifications are high-confidence alerts that a user has been individually targeted by a mercenary spyware attack, and should be taken very seriously," Apple noted. "We are unable to provide information about what causes us to issue threat notifications, as that may help mercenary spyware attackers adapt their behavior to evade detection in the future."

How Notifications Reach Users

If Apple detects this activity, it sends an email and iMessage notification to the email addresses and phone numbers associated with the user's Apple Account. The emails are usually from threat-notifications@email.apple.com, and Apple also warns users about fake versions of these alerts.

You can verify whether a threat notification is genuine because Apple will not ask you to click a link, open a file, install an app or profile, or provide an Apple Account password or verification code. You can also check the alert by signing in directly to account.apple.com. If Apple sent you a threat notification, it will appear at the top of the page after you're logged in.

Steps if You're Affected

If you believe you've been affected, you should enable Lockdown Mode and reach out to a cybersecurity expert. Apple recommends taking these alerts seriously because receiving one means it has high confidence that the user was individually targeted.

BleepingComputer has contacted Apple for a statement on the Threat Notifications, but we have not received a response at the time of publication.

Why It Matters for Your Security

The new batch of alerts underscores the ongoing threat posed by mercenary spyware, which can compromise a targeted iPhone despite Apple's defenses. For the small group of individuals these attacks typically target—journalists, activists, politicians, and diplomats—these notifications are a critical early warning. Even for the broader public, the existence of such surveillance tools highlights the lengths some attackers will go to, and the importance of taking precautions like enabling Lockdown Mode and verifying any alert you receive.

#apple#spyware#threat notification#mercenary spyware#pegasus

Sources

Iliyas

Editor, Xploitwire

This article was compiled from the sources listed above and checked against them for accuracy, under editorial policies set by Iliyas. Read our Editorial Policy →

← Back to all stories