Apple’s Mercenary Spyware Warnings Are Real – Here’s What to Do If You Get One

Alerts sent to users in 110 countries in August 2026 signal targeted attacks by government-linked spyware operators

Annemarije de Boer Avatar
Annemarije de Boer Avatar

By

Image: Deposit Photos

Key Takeaways

Key Takeaways

  • Apple sent mercenary spyware alerts to users across 110 countries in August 2026.
  • Enable Lockdown Mode immediately and contact Access Now’s Digital Security Helpline if alerted.
  • Apple’s notification system raises costs for spyware firms, making targeting high-risk users harder.

Your iPhone lock screen lights up: “Apple detected a mercenary spyware attack targeted at your iPhone.” Not a phishing scam. Not iOS acting weird. A high-confidence alert that someone — almost certainly a government-linked operator — has singled you out personally. Apple sent exactly this notification to users across 110 countries on August 13–14, 2026. Most people reading this will never see it. The ones who do are in genuine danger and need to act immediately.

What Apple Is Actually Telling You

This isn’t a bug warning — it’s closer to a wiretap notice landing on your lock screen.

“Mercenary spyware” means commercial surveillance tools — think NSO Group’s Pegasus — sold to governments specifically to compromise high-value targets: journalists, activists, opposition politicians, diplomats. In many jurisdictions, these tools have existed in a regulatory gray zone, with some vendors facing sanctions and export controls while others operate with limited accountability.

Apple calls these “high-confidence” alerts based on internal technical signals, while acknowledging it can’t achieve absolute certainty. It deliberately withholds which vendor or government is behind the attack — revealing detection criteria would let attackers adapt and disappear.

John Scott-Railton, senior researcher at the University of Toronto’s Citizen Lab, confirmed on X: “Apple just sent out a fresh round of threat notifications about mercenary spyware. That means tech like Pegasus used by governments to spy on you.”

Receiving the alert doesn’t mean your device is fully compromised. It means Apple has detected activity consistent with a mercenary spyware attack targeting your device. That distinction matters — don’t let it become an excuse for inaction.

One critical detail: if an alert arrives only via email or text — without the lock screen banner and Settings row — treat it as phishing. Verify at account.apple.com.

If You Get One of These Alerts

Four moves, in order — each one closes a door attackers are actively trying to open.

Enable Lockdown Mode on every Apple device tied to your Apple ID. Go to Settings → Privacy & Security → Lockdown Mode. Once active, it blocks most message attachments, disables JIT JavaScript in Safari, blocks unsolicited FaceTime calls, and cuts wired connections when your phone is locked. Restrictive by design — that’s architecturally the point.

Updating your OS should happen in parallel. Mercenary spyware exploits unpatched vulnerabilities, and closing those gaps is among the fastest defensive moves available. Do not factory reset your device. Wiping destroys forensic evidence that investigators need to understand the scope of what happened. Back it up instead, then wait for expert guidance. Consider also securing your password vaults with strong two-factor authentication as part of your overall hardening.

Contact Access Now’s Digital Security Helpline — free, 24/7, and built for exactly this situation. Apple’s own support materials reference them directly.

Why Apple Built This – and What It Costs Attackers

Every notification round raises the price of targeting you — and that pressure is the whole idea.

Apple has sent these alerts since 2021, now reaching users across 150-plus countries in total. Each round, the system gets more visible — now front-and-center on your lock screen rather than buried in an email thread you might miss. Lockdown Mode, introduced with iOS 16, is the structural complement to that warning system.

Scott-Railton described it as a meaningful blow that will “reduce the attack surface, increase costs for spyware firms, and thus make it much harder for repressive governments to hack high-risk users,” according to Computerworld. Think of it as a digital panic room: you trade some convenience — no exotic file attachments, restricted browsing features — for walls that are significantly harder to breach.

Critics reasonably note that platform-level defenses don’t address the root problem. Spyware firms operating with minimal accountability, and governments purchasing their tools with little oversight, won’t be stopped by software alone. How iCloud left Apple‘s confidential files exposed illustrates how even platform-level protections can have blind spots. Regulation and sanctions remain part of the answer.

If your work puts you in the crosshairs of governments, this notification system is one of the few consumer-facing early-warning tools that actually exists. Treat it accordingly.

Share this

At Gadget Review, our guides, reviews, and news are driven by thorough human expertise and use our Trust Rating system and the True Score. AI assists in refining our editorial process, ensuring that every article is engaging, clear and succinct. See how we write our content here →