Apple operates a telemetry-based threat detection system that continuously monitors device signals for indicators of compromise. When evidence of a targeted attack surfaces, the company issues direct notifications to affected users. Receiving such an alert is a serious signal: it may indicate that a device has already been compromised, personal data exfiltrated, or communications subjected to comprehensive surveillance. Users who receive these warnings must act immediately to strengthen their security posture.
Warnings Dispatched to Users Across More Than 110 Countries
Apple has recently issued mercenary spyware attack notifications to users in more than 110 countries and regions worldwide. The alerts advise recipients that they have been identified as targets of commercial spyware operations, and instruct them to consult Apple’s official security guidance – covering device hardening measures and encryption practices – to safeguard their information.
The term “mercenary spyware” refers to sophisticated surveillance tools developed by private companies and leased to government-affiliated clients for targeted operations. The most notorious example is Israel’s NSO Group, whose Pegasus spyware is engineered to exploit iOS vulnerabilities and achieve near-total device surveillance. NSO Group is not alone: Israel hosts a broader ecosystem of commercial spyware vendors, and their products have been procured by government and state-level agencies across numerous countries and regions.
It bears emphasizing that the vast majority of users will never become targets of such operations. Those who do tend to occupy high-profile or politically sensitive roles – government officials, journalists, human rights defenders, and occasionally senior figures within criminal organizations targeted by law enforcement agencies seeking to gather evidence.
Apple’s Security Recommendations for Targeted Users
To help users defend against mercenary spyware, Apple has previously introduced Lockdown Mode – an advanced protection feature that deliberately restricts certain device capabilities in exchange for a substantially hardened security profile. One illustrative example is the suppression of JavaScript execution in Safari, since attackers frequently exploit WebKit vulnerabilities and deploy scripts as the initial vector of intrusion.
Beyond Lockdown Mode, Apple’s official security guidance for users who receive a threat notification includes the following recommendations:
- Update the device to the latest available software version to ensure all known vulnerabilities are patched.
- Protect the device with a strong passcode, fingerprint recognition, or Face ID.
- Enable two-factor authentication for your Apple ID and iCloud account.
- Activate the Stolen Device Protection feature.
- Do not open links or attachments from unknown or unverified senders.
- Use strong, unique passwords for all accounts – and where possible, adopt passkeys as a more secure alternative.
For anyone who receives an Apple threat notification, treating the warning as an urgent call to action – rather than a precautionary formality – is the appropriate response.
Support Our Threat Intelligence
If you find our CVE report and cybersecurity news helpful, consider supporting our work.