Apple sends urgent spyware alert to iPhones in 110 countries

Why targeted users should take the warning seriously

Apple has warned targeted iPhone users in 110 countries about potential mercenary spyware attacks | ©Image Credit: Unsplash / Filip Baotić
Apple has warned targeted iPhone users in 110 countries about potential mercenary spyware attacks | ©Image Credit: Unsplash / Filip Baotić

If your iPhone suddenly tells you that Apple detected a mercenary spyware attack targeting your device, don’t swipe it away like another annoying notification. Apple sent a fresh wave of its Threat Notifications on August 13 to targeted users across 110 countries, warning that they may have been individually targeted by sophisticated spyware.

The company confirmed the alerts are legitimate after users began posting screenshots online and wondering whether the frightening message was itself a scam.

This is not a warning for every iPhone user

Before you start eyeing your iPhone, know that most people will never receive this alert. Apple describes these notifications as high-confidence warnings for people it believes may have been individually targeted by mercenary spyware, typically because of who they are or what they do. The company says these attacks are expensive, highly sophisticated, and generally aimed at a small number of specific people.

That can include journalists, activists, politicians, executives, diplomats and other people who may have access to sensitive information.

So the notification appearing in 110 countries does not mean 110 countries are suddenly crawling with compromised iPhones.

The notification is real

Some users were understandably suspicious because the latest alerts look different from previous Apple spyware warnings. Apple has now confirmed that the messages are genuine.

As of 2026, the company says targeted users can receive the warning directly on their iPhone as well as by email from Apple Threat Notifications. The exact appearance can vary depending on the device and software version. If you receive one, you should verify it by signing in to your Apple account rather than blindly trusting links or instructions inside an email.

What makes mercenary spyware so scary?

This is not your average malware downloaded after clicking a suspicious “You won an iPhone!” link. Mercenary spyware is designed to quietly infiltrate high-value targets and collect information from their devices. Some attacks can exploit software vulnerabilities without requiring the victim to click anything.

A zero-click attack can potentially compromise a device without the victim opening a link, downloading an app or doing anything obviously suspicious.

Once spyware gets inside a device, an attacker could potentially access sensitive communications and other information—even data handled through encrypted messaging apps.

Apple has been sending these warnings for years

This is not Apple’s first spyware alert. The company began sending threat notifications in 2021 and says it has notified users in more than 150 countries since then. The latest wave covers 110 countries.

Apple also makes an important distinction that receiving a notification doesn’t necessarily mean the device was successfully compromised. The company describes its warnings as high-confidence alerts that someone was individually targeted.

While that’s still incredibly serious, it isn’t the same thing as saying your phone was successfully hacked. So, if you get such a warning, do not panic. At the same time, you want to take the warning seriously.

Apple recommends keeping your devices updated and enabling Lockdown Mode, a security feature designed specifically to reduce the attack surface available to extremely sophisticated spyware. Security experts also advise that you seek professional assistance if you receive an alert, particularly if the device is used for sensitive work.

And don’t immediately wipe or throw away the phone if it’s a work device or potentially compromised. Preserving the device can be important for security professionals investigating what happened.

Sources: Forbes, Malwarebytes