Apple Issues Unprecedented Spyware Alerts to Users Worldwide, Experts Warn

TL;DR
- Apple has reportedly sent mercenary spyware threat notifications to users in a large number of countries in its latest wave, which security researchers describe as one of the broadest alerts the company has ever issued.
- The alerts target individuals including journalists, activists, politicians, and dissidents who are at higher risk of sophisticated, state-sponsored spyware like Pegasus and Predator.
- Apple warns that these attacks are exceptionally costly and sophisticated, urging recipients to immediately update devices, enable Lockdown Mode, and seek expert help.
An Unusually Large Wave of Warnings
In recent days, Apple has issued a new round of threat notifications warning users that they may have been targeted by mercenary spyware, and cybersecurity investigators say the sheer scale of this wave is what makes it stand out. While Apple regularly notifies at-risk users when it detects activity consistent with a state-sponsored attack, researchers note that this latest distribution appears to have reached users across an unusually wide geographic footprint, spanning well over 90 countries.
Apple first launched its threat notification system in 2021 to alert users when it has high confidence they have been individually targeted by mercenary spyware. Unlike mass malware or phishing campaigns, these attacks are highly personalized, expensive to develop, and often deployed by private companies contracted by government clients. Apple does not disclose how it detects such activity, but says it uses internal threat intelligence and investigations to identify attacks that far exceed the capabilities of ordinary cybercriminals.
Who Is Being Targeted?
According to investigators and recipients who have shared their notifications online, the alerts are not aimed at the general public. Instead, they have been sent to a specific profile of high-risk individuals.
Early reports indicate the notifications have reached journalists and media workers, human rights activists and NGO staff, opposition politicians and political aides, lawyers, and civil society figures. In many cases, recipients have links to sensitive political or investigative work, which aligns with the historical targeting patterns of commercial spyware tools such as NSO Group's Pegasus and Intellexa's Predator.
Cybersecurity experts say the breadth of countries involved suggests multiple customers of spyware vendors may be active simultaneously, rather than a single campaign. That diversity is one reason researchers are calling this wave unprecedented, as it points to the continued proliferation of the mercenary spyware industry despite public scrutiny and U.S. sanctions against several vendors.
Why Experts Call This Moment Unprecedented
Security researchers say two factors make this wave different from previous ones. First is the volume and reach. While Apple has sent similar alerts twice a year since 2021, this latest batch appears to be among the largest in terms of both number of users notified and number of countries represented.
Second is the timing and persistence. Experts note that spyware vendors have become more resilient, adapting their zero-click exploits to bypass security patches and shifting infrastructure to evade detection. The fact that Apple is still detecting successful or attempted compromises at this scale, even after major iOS security upgrades, underscores how advanced and well-funded these operations remain.
John Scott-Railton and other researchers who track mercenary spyware have previously warned that the market has grown from a handful of vendors to a sprawling ecosystem of companies selling intrusion capabilities to governments with limited oversight. This wave, they argue, is evidence that demand remains high.
What Apple's Warning Actually Means
Apple is careful to note that a threat notification does not mean a device is definitely infected, but rather that the company detected activity consistent with a mercenary spyware attack with high confidence. The company states it has never attributed the notifications to a specific attacker or spyware family, and that false positives, while possible, are rare.
The notification itself urges recipients to take the warning seriously, even if they notice no obvious signs of compromise. Mercenary spyware is designed to be invisible, often requiring no interaction from the victim through so-called zero-click exploits delivered via iMessage, WhatsApp, or other messaging platforms. Once installed, it can access messages, emails, calls, photos, location, and even encrypted app data.
Apple advises all users who receive a notification to seek help from rapid-response security organizations such as Access Now's Digital Security Helpline or Amnesty International's Security Lab, which offer free forensic support for at-risk civil society members.
How to Secure Your Apple Devices Right Now
Whether or not you received a notification, Apple and security experts recommend several steps to harden your devices against this class of attack:
Enable Lockdown Mode for High-Risk Protection
Lockdown Mode is an optional, extreme protection feature designed for the very small number of users who may be targeted by sophisticated spyware. When enabled on iPhone, iPad, and Mac, it blocks many common attack vectors, including most message attachments, link previews, and wired connections when locked. Apple says it has strengthened Lockdown Mode in recent iOS versions specifically to counter mercenary spyware.
Keep Devices Fully Updated
Update to the latest version of iOS, iPadOS, and macOS immediately. Apple frequently patches the zero-day vulnerabilities that spyware vendors exploit, and running the newest software closes many known entry points. Enable automatic updates where possible.
Practice Digital Hygiene and Seek Expert Help
Restart your device regularly, avoid clicking links or opening attachments from unknown senders, and use passkeys and two-factor authentication on Apple ID and other critical accounts. If you believe you are at risk or have received a threat notification, do not attempt to investigate the device yourself. Contact a trusted digital security expert and avoid discussing sensitive matters on the potentially compromised device until it has been checked.
The Bigger Picture for Apple Users
Apple's latest alerts are a reminder that for most users, the risk of mercenary spyware remains extremely low. These are not mass surveillance tools but precision weapons aimed at a tiny fraction of users. However, experts warn that the continued expansion of the commercial spyware market means no platform is immune, and the techniques developed for high-end espionage can eventually trickle down.
For now, Apple's notification system remains one of the few public windows into an otherwise secretive industry, offering at-risk users a rare chance to defend themselves before further harm is done.
Get All The Latest Updates Delivered Straight To Your Inbox For Free!