Apple Issues New Wave of 'Mercenary Spyware' Threat Notifications to iPhone Users
Apple has recently dispatched a fresh series of 'Threat Notifications' to iPhone users globally, signaling highly targeted mercenary spyware attacks. These alerts, a recurring measure since 2021, indicate a high-confidence detection of sophisticated cyber threats often aimed at high-profile individuals.
If you've recently received an "Apple Threat Notification" indicating a "mercenary spyware attack targeted at your iPhone," you are not alone. Reports on platforms like **Reddit** confirm that **Apple** issued a new batch of these alerts on August 13.

**Apple** has been proactively sending these threat notifications multiple times a year since 2021, specifically when it detects highly targeted mercenary spyware attacks.
While **Apple** does not explicitly identify the specific spyware behind each individual alert, the company has historically cited **NSO Group's Pegasus** as an example of mercenary spyware associated with such sophisticated attacks. Forensic investigations following previous **Apple** threat notifications have, in some instances, corroborated **Pegasus** infections.
In a dedicated [support document](https://support.apple.com/en-us/102174), **Apple** previously confirmed its practice of sending these notifications to users in over 150 countries. These alerts are triggered by the detection of highly targeted mercenary spyware attacks against specific **iPhone** users.
Typical targets of these advanced and expensive attacks often include journalists, activists, politicians, and diplomats. These individuals have historically been prime targets for this type of surveillance technology.
**Apple** emphasizes the nature of these threats, stating, "Mercenary spyware attacks cost millions of dollars and often have a short shelf life, making them much harder to detect and prevent." The company reassures the broader user base that "The vast majority of users will never be targeted by such attacks." **Apple** also refrains from attributing individual alerts to specific governments, companies, or geographical regions.
## Apple Says Threat Notifications Should Be Taken Seriously
**Apple** relies on its proprietary threat intelligence and extensive investigations to identify suspected mercenary spyware activity. Consequently, these notifications are considered "high-confidence alerts" and should not be dismissed as routine warnings.
"Although our investigations can never achieve absolute certainty, **Apple** threat notifications are high-confidence alerts that a user has been individually targeted by a mercenary spyware attack, and should be taken very seriously," **Apple** noted. The company intentionally withholds specific details about the detection mechanisms to prevent mercenary spyware attackers from adapting their tactics to evade future detection.
Upon detecting such activity, **Apple** dispatches email and **iMessage** notifications to the email addresses and phone numbers linked to the user's **Apple Account**. Genuine emails originate from `[email protected]`. Users are cautioned about fraudulent versions of these alerts.
To verify the authenticity of a threat notification, remember that **Apple** will never ask you to click a link, open a file, install an app or profile, or provide an **Apple Account** password or verification code in these alerts. You can also independently confirm the alert by signing in directly to [account.apple.com](https://account.apple.com/). If a legitimate threat notification has been issued, it will prominently appear at the top of the page after you log in.
If you believe you have been affected, it is strongly recommended to enable **Lockdown Mode** on your device and consult with a cybersecurity expert. **Apple**'s recommendation to take these alerts seriously stems from the high confidence it places in the individual targeting indicated by such a notification.