Apple warns iPhone users in 110 countries they were targeted by Spyware
- Evelyn Carter

- 1 day ago
- 4 min read
On August 13, 2026, Apple confirmed a new round of threat notifications sent to users targeted by sophisticated spyware across 110 countries. Apple has not disclosed the number of recipients, the specific spyware involved, the threat actor, or any related CVE. Recipients are advised to update their devices, consider enabling Lockdown Mode, and seek expert assistance.
An alert appearing directly on an iPhone’s Lock Screen does not necessarily mean the device has been successfully compromised. However, it should not be treated as an ordinary security notification. Apple says its Apple Threat Notifications are designed to inform users when internal threat intelligence provides high-confidence evidence that an individual has been targeted by highly sophisticated spyware.

For businesses, the risk becomes more significant when the affected device belongs to an executive, finance or legal professional, system administrator, or another employee with access to sensitive information. A smartphone used for corporate email, documents, and business accounts can form an important part of an organization’s attack surface.
What happened in Apple’s latest spyware warning?
On August 13, 2026, Apple issued a new round of Apple Threat Notifications to users the company assessed as having been targeted by mercenary spyware. Apple confirmed to TechCrunch that recipients of this round were located across 110 countries.
Mercenary spyware refers to commercially developed surveillance software backed by substantial resources and typically used in highly targeted operations. According to Apple, these attacks are significantly more sophisticated than conventional cybercrime, focus on a very small number of specific individuals, and can cost millions of dollars to develop and operate.
Apple says it has issued threat notifications several times a year since 2021 and has notified users in more than 150 countries. People facing elevated risk have historically included journalists, activists, politicians, and diplomats.
Information | Confirmed Status |
Date of latest Apple warning | August 13, 2026 |
Scope of latest notification round | 110 countries |
Countries notified since 2021 | More than 150 |
Number of individual recipients | Not disclosed |
Specific spyware involved | Not disclosed |
Specific threat actor | No attribution by Apple |
Related CVE | Not disclosed |
Apple can display these warnings directly on the iPhone Lock Screen and in Settings, send an email to the address associated with the user’s Apple Account, and display a notification after the user signs in to their Apple Account.
Why is the spyware highlighted by Apple particularly dangerous?
Unlike malware distributed indiscriminately, mercenary spyware is typically designed to compromise specific, high-value targets. Apple describes these campaigns as exceptionally well-resourced operations that continuously evolve their techniques and are considerably more difficult to detect than common cyber threats.
NSO Group’s Pegasus is one of the best-known historical examples of commercial spyware. However, Apple has not confirmed that Pegasus or any other specific spyware was involved in the August 13, 2026 warning campaign. Apple has also not attributed this round of notifications to a particular government, country, or threat actor.
Who within an organization may face greater risk?
Apple says the overwhelming majority of users will never be targeted by mercenary spyware. However, a low likelihood of attack does not necessarily mean a low business impact when an organization employs individuals whose roles make them particularly valuable targets.
Organizations should prioritize risk assessment for people who use mobile devices to access large volumes of sensitive information, including:
senior executives and board members;
finance, legal, and M&A personnel;
administrators with privileged accounts;
employees handling intellectual property or customer data;
personnel who frequently travel internationally;
individuals with public-facing roles or involvement in sensitive matters.
Corporate smartphones are commonly used to access email, documents, ERP, CRM, and internal business applications. In BYOD environments, unmanaged or inadequately updated devices can increase the risk of unauthorized access and data exposure.
Organizations can use Mobile Device Management with Microsoft Intune to centrally enforce device policies, manage applications, and control access to corporate resources.
However, an Apple Threat Notification received by an executive or privileged employee should be treated as a potential trigger for the organization’s Security or Incident Response process rather than something the individual is expected to handle alone.
What should users do after receiving an Apple Threat Notification?
Apple advises recipients to take the notification seriously. The company also emphasizes that a legitimate threat notification will never ask users to click a link, open a file, install an application or configuration profile, or provide an Apple Account password or verification code by email or phone. Xác minh Apple Threat Notification trực tiếp qua Apple Account.
Verify the Apple Threat Notification directly through the Apple Account.
Do not follow suspicious links or provide passwords in response to unexpected emails.
Update the iPhone and other associated Apple devices to the latest available software.
Consider enabling Lockdown Mode if a notification has been received or the user faces elevated risk.
Notify the IT or Security team if the device can access corporate resources.
Review active sessions, email accounts, and associated business accounts for unusual activity.
Limit sensitive activity on the potentially affected device until the risk has been assessed.
For high-risk cases, consider specialist mobile device forensic assistance.
There is also an important consideration for organizations using MDM. Apple states that devices already enrolled in MDM before Lockdown Mode is enabled remain managed, while devices operating in Lockdown Mode cannot be newly enrolled in MDM until the mode is temporarily disabled.
What does IPSIP Vietnam’s cybersecurity perspective suggest?
Mobile devices should be incorporated into the organization’s broader endpoint risk management program. Companies with high-value users should establish a predefined response process for Apple Threat Notifications instead of handling incidents on an ad hoc basis.
Organizations should first maintain an inventory of devices that access corporate information and identify employees who may face elevated targeting risk. Policies should define minimum operating system versions, MFA requirements, device-based access controls, and escalation procedures for serious security alerts.
Device management, software updates, identity controls, and security monitoring should be connected to a clearly defined incident response process. When an Apple Threat Notification appears, the priority should shift from routine prevention to verifying the alert, assessing the device, and determining whether corporate accounts or data may also be at risk.
References
Apple Support - About Lockdown Mode
The Citizen Lab, University of Toronto - Espionage Against the European Parliament: Member of Committee Investigating Spyware Hacked with Pegasus









Comments