Apple has initiated a worldwide wave of security warnings, notifying iPhone users in 110 countries that their devices may have been targeted by mercenary spyware. The alerts target high-risk individuals such as journalists, diplomats, and activists, bringing the total number of notified nations to over 150 since 2021.
The company began dispatching alerts globally to warn specific individuals whose devices showed signs of highly sophisticated, targeted compromise attempts.
Unlike standard malware designed to cast a wide net across millions of consumer devices, mercenary spyware is an exceptionally expensive and technically complex tool. The commercial surveillance software is deployed against carefully chosen targets. State-sponsored groups and private entities acting on behalf of government agencies typically operate these systems to siphon sensitive data from mobile hardware.
How Apple Delivers Threat Notifications to Targeted Users
The latest notification campaign reaches users through multiple channels to ensure the critical warning is seen. On supported iPhones, the alert appears directly on the lock screen and within system settings. In addition to these device-level push notifications, the company sends traditional alerts via email and iMessage tied to the user’s primary Apple account, while also displaying the warning upon logging into the account page.
While the messaging is urgent, the company deliberately avoids publishing a comprehensive list of targeted countries or disclosing the exact telemetry data that triggered the alerts. Security researchers explain that revealing detection methods would give sophisticated attackers the blueprint needed to alter their code and evade future detection systems.
Apple has discovered a mercenary spyware attack that targeted your iPhone. You can now take steps to protect your data and your device. Apple, Threat Notification Warning
Despite the high fidelity of these alerts, receiving a notification does not automatically confirm that an individual’s device has been successfully compromised. The alert indicates sufficient evidence of a targeted, professional attack attempt rather than definitive proof of a successful data breach.
Recommended Defensive Measures and the Lockdown Mode Standard
For individuals operating in high-risk professions, the tech giant strongly recommends implementing immediate device hardening. The most critical defense is the activation of the Lockdown Mode feature across all compatible Apple hardware, including iPhones, iPads, and Macs. This specialized setting disables numerous attack vectors.

Furthermore, the developer maintains that the Lockdown Mode on iPhones has never been successfully bypassed by known commercial spyware.
Beyond specialized hardware modes, general users are advised to maintain strict cyber hygiene. Essential protection steps include updating mobile software promptly, enabling two-factor authentication, utilizing passkeys, and activating Stolen Device Protection. For those who receive direct threat alerts, external assistance is available through specialized organizations.
Access Now Support and the Expanding Reach of Global Surveillance
Alongside the alert rollout, a newly updated support document points affected individuals toward external expert resources. Recipients of the warning can contact the Digital Security Helpline run by the non-profit organization Letemsvetemapplem, which provides round-the-clock tailored technical advice for targeted civil society members.

The geographic scope of these attacks continues to expand year over year. Since the threat notification system debuted in 2021, the manufacturer has alerted individuals in more than 150 nations, stepping up from prior campaigns that covered 100 countries during previous reporting cycles.
