Apple has sent a new wave of security alerts to people it believes may have been individually targeted by sophisticated mercenary spyware, introducing more visible push notifications as surveillance tools continue to threaten selected iPhone users worldwide.
New Push Notifications Make Spyware Warnings Harder to Miss
Apple has issued threat notifications since 2021, but the newest approach makes warnings more prominent.
TechCrunch reported that Apple updated the experience so targeted users can receive a warning directly on the iPhone lock screen, with the notification stating that Apple detected a “mercenary spyware attack” targeting the device.
Sportskeeda said the push-notification format makes the latest warnings harder to overlook and noted that Apple has now notified people in more than 150 countries since beginning its threat-notification program.
Apple Calls Them ‘High-Confidence Alerts’
Receiving a notification does not necessarily prove that spyware successfully compromised the device, but Apple says users should not dismiss it.
BleepingComputer reported that Apple describes the warnings as “high-confidence alerts” indicating that an individual user has been specifically targeted, although the company says its investigations can never provide absolute certainty.
An alert may not mean the recipient was successfully hacked, but users should still take immediate action to protect their device and data.
Apple does not reveal the evidence behind individual warnings because explaining its detection methods could help spyware operators modify their behavior and avoid future detection.
Pegasus Is an Example, but Apple Does Not Name the Spyware
The warnings should not automatically be interpreted as evidence that one particular surveillance product was used.
Apple does not identify the spyware responsible for individual alerts, meaning there is no evidence that the August 13 notifications specifically involve NSO Group’s Pegasus.
Apple has nevertheless previously cited Pegasus as an example of mercenary spyware developed by private companies for government customers.
BleepingComputer said journalists, activists, politicians, and diplomats have historically been among the people targeted by this category of surveillance technology, while Apple says such operations can cost millions of dollars and affect only a small number of users.
Users Can Verify Whether an Apple Warning Is Genuine
The attention surrounding the alerts also creates an opportunity for scammers to imitate them.
BleepingComputer reported that genuine Apple threat-notification emails generally come from threat-notifications@email.apple.com, while Apple will not ask recipients to click a link, install an application or profile, or provide an Apple Account password or verification code.
Users can independently verify an alert by signing directly into their Apple Account, where a genuine threat notification will appear prominently.
Lockdown Mode Can Reduce the Attack Surface
Apple recommends stronger security measures for anyone who receives a warning.
Users should update their devices and enable Lockdown Mode, which limits certain features and services to reduce opportunities for sophisticated spyware to attack the device.
Apple says it has yet to observe a case in which a device was successfully compromised by mercenary spyware while Lockdown Mode was enabled.
Citizen Lab senior researcher John Scott-Railton shared that the new push notifications are a “big improvement” because alerts can prompt targeted people to seek expert assistance and can ultimately help investigators uncover broader surveillance campaigns.
For most iPhone owners, mercenary spyware remains an unlikely threat. But for someone who receives Apple’s highly targeted warning, the rarity of the attack is precisely what makes the notification significant: Apple believes that person—not simply iPhone users in general—may have been deliberately selected for surveillance.