Security
Apple warns iPhone users in 110 countries about spyware
Apple has warned users in 110 countries about suspected mercenary spyware targeting, urging recipients to enable Lockdown Mode and seek expert help.
Apple sent a new wave of Threat Notifications on August 13, 2026, warning an unspecified number of users that their iPhones may have been targeted by mercenary spyware. BleepingComputer reports that users began sharing the alerts on Reddit, while 9to5Mac says Apple confirmed the latest notifications cover 110 countries.
The feature is not new. Apple has issued these warnings several times a year since 2021 when it detects highly targeted attacks aimed at specific iPhone users. Apple says the latest notifications bring the total number of countries where it has issued such warnings over the past few years to more than 150.
Apple does not identify the spyware, government, company, or geographic region behind an individual alert. There is therefore no evidence that this particular notification wave is specifically tied to Pegasus, although Apple has cited NSO Group’s Pegasus as a historical example of mercenary spyware and forensic investigations have confirmed Pegasus infections in some earlier cases.
Potential targets include journalists, activists, politicians, and diplomats. Apple describes these attacks as expensive, sophisticated campaigns that usually affect a very small number of people.
“Although our investigations can never achieve absolute certainty, Apple threat notifications are high-confidence alerts that a user has been individually targeted by a mercenary spyware attack, and should be taken very seriously.”
— Apple
Apple says it cannot disclose what triggers an alert because that information could help attackers evade detection. Notifications are sent by email and iMessage to the addresses and phone numbers linked to a user’s Apple Account. Users can verify an alert by signing in directly at account.apple.com; a genuine notification appears at the top of the page.
The company will not ask recipients to click a link, open a file, install an app or configuration profile, or provide an Apple Account password or verification code. Anyone who receives a warning should enable Lockdown Mode and seek expert assistance. Apple recommends contacting Access Now’s Digital Security Helpline, which offers rapid-response security advice 24 hours a day, seven days a week.
Apple’s broader recommendations include updating devices, using a passcode or biometric authentication, enabling two-factor authentication and Stolen Device Protection, installing apps from the App Store, using unique passwords or passkeys, and avoiding links or attachments from unknown senders. Apple emphasizes that the vast majority of users will never be targeted by this type of spyware.
BleepingComputer said it contacted Apple for additional comment but had not received a response at publication time.