Key Takeaways
- Apple has issued its largest-ever wave of “mercenary spyware” threat notifications, alerting users in 110 countries to state-sponsored attacks.
- Digital rights groups like Access Now report a record influx of inquiries, confirming the unprecedented scale and broad reach of these sophisticated surveillance attempts.
- Users receiving these critical alerts are strongly advised to enable Lockdown Mode immediately, a robust security feature designed by Apple to counter advanced cyber threats.
An unprecedented surge in digital threat notifications from Apple has sent ripples through the cybersecurity community, as an extraordinary number of customers report being targeted by sophisticated, state-sponsored spyware. Over the past weekend, Apple dispatched a new wave of alerts, notifying users across 110 countries that their devices may have been compromised or targeted by powerful “mercenary spyware.”
This latest batch of alerts marks a significant escalation in the ongoing battle against advanced digital surveillance. Apple periodically issues such notifications in bulk to users it suspects have fallen victim to or are targets of malware typically employed by governments—a threat the company explicitly labels as “mercenary spyware.” In recent years, Apple has extended these warnings to individuals in more than 150 countries, but the current wave stands out for its sheer volume and global reach.
Digital rights organizations, often the first point of contact for victims of such attacks, confirm the record-breaking nature of these alerts. Mohammed Al-Maskati, director of the Access Now team, which investigates reports to its helpline, shared with TechCrunch that his organization has seen an unparalleled surge in requests for help since Friday. This includes individuals who had previously received threat notifications, indicating a persistent and escalating threat landscape. Al-Maskati noted that the number of inquiries is approximately 30% to 40% higher than what the nonprofit typically receives following Apple’s alert disbursements. Cybersecurity firm iVerify has also corroborated these observations, reporting a similar influx in threat notifications originating from Apple.
The widespread nature of these attacks is further evidenced by a deluge of public reports across various social media platforms over the weekend. Users from diverse backgrounds and geographies have come forward, sharing screenshots and accounts of receiving Apple’s stark warning.
Contact Us
Have you received a notification from Apple about being targeted with mercenary spyware? Or do you have information about spyware makers? We would love to hear from you. From a non-work device, you can contact Lorenzo Franceschi-Bicchierai securely on Signal at +1 917 257 1382, or via Telegram and Keybase @lorenzofb, or email.
Among those publicly reporting an alert is a Ukrainian Armed Forces soldier actively engaged in the conflict against Russia. The soldier, who requested anonymity to ensure his safety, initially dismissed the notification as a potential scam. However, after verifying its authenticity with Apple, the gravity of the situation became clear. “I was a bit surprised to be honest, I wouldn’t have thought I was important enough for them to target me like this. I am flattered though,” the soldier candidly told TechCrunch, highlighting the personal impact of such a sophisticated targeting effort. He also confirmed awareness of other Ukrainian military personnel who have received similar notifications, remarking that “They were a bit worried.” Requests for comment from the Computer Emergency Response Team of Ukraine (CERT-UA) regarding the targeting of soldiers or other Ukrainian citizens went unanswered.
The scale of these notifications underscores a troubling reality about the pervasiveness of government-backed spyware, often referred to as “mercenary spyware.” These tools are typically developed by private companies and sold to government clients globally, enabling them to covertly access and monitor targets’ devices, exfiltrate data, and even remotely activate microphones and cameras. Targets often include journalists, human rights defenders, political dissidents, and in this latest wave, military personnel in active conflict zones.
John Scott-Railton, a senior researcher at The Citizen Lab—a digital rights group that has extensively investigated government spyware attacks for over 15 years—emphasized the profound implications of these reports. “The scale and geographic diversity of public posts about receiving notifications are pretty unprecedented,” Scott-Railton stated. He likened the visible alerts to the tip of an iceberg, noting, “For every public notification like this, you can imagine there’s a huge notification iceberg that the public will never learn about. This is a clear indication that something bigger is going on.” This analogy points to the likelihood that many more individuals have been targeted without publicly disclosing their alerts, or that Apple’s detection capabilities are continuously improving.
Both Al-Maskati and Scott-Railton suggested that the dramatic increase in alerted users could also be partially attributed to Apple’s enhanced and more prominent notification methods. Starting this year, Apple has refined its alert system to ensure maximum visibility. Users are now notified directly on their iPhone lock screen, within their Settings app, via the email address linked to their Apple account, and upon logging into their Apple Account on the web. This multi-channel approach makes it significantly harder for users to overlook or dismiss these critical security warnings. “Apple’s new notification method has helped raise awareness of the issue’s importance, making it harder for users to ignore,” Al-Maskati confirmed, highlighting the positive impact of improved user communication on digital security awareness.
Apple, maintaining its standard policy on security incidents, did not respond to TechCrunch’s request for comment regarding the specific details or scope of this latest wave of alerts. However, their consistent messaging and the deployment of robust security features speak to their proactive stance on protecting user privacy and security from such advanced threats.
If you have received one of these notifications, cybersecurity experts and Apple themselves urge you to take it with utmost seriousness. While TechCrunch’s callout focuses on journalists and those with information on spyware makers, individuals who are not journalists, dissidents, or human rights defenders but have received an alert should still seek assistance. Organizations like Access Now and The Citizen Lab offer invaluable resources and investigative support to help targeted individuals understand and mitigate the risks.
Crucially, Apple and security experts universally recommend activating Lockdown Mode immediately if you receive a threat notification. This specialized security feature, available on iPhones, iPads, and Mac computers, is engineered to drastically reduce the attack surface for highly sophisticated cyberattacks, making it significantly more difficult for mercenary spyware to compromise a device. Apple has publicly stated that it has no knowledge of any user with Lockdown Mode enabled ever being successfully hacked. Activating it limits certain functions, restricts specific app behaviors, and disables various web features, effectively creating a fortified digital environment against zero-day exploits and other advanced persistent threats.
Bottom Line
The latest, unprecedented wave of “mercenary spyware” threat notifications from Apple serves as a stark reminder of the escalating and globally distributed nature of state-sponsored digital surveillance. With digital rights groups reporting record inquiries and public confirmations from individuals in high-risk professions, it’s clear that sophisticated cyber threats are more prevalent than ever. These alerts are not to be ignored; they are critical warnings demanding immediate action. Users are strongly advised to leverage Apple’s built-in security features like Lockdown Mode and seek expert assistance to protect themselves against these advanced and often invisible threats, reinforcing the critical importance of proactive digital hygiene in an increasingly hostile online world.
When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.
Source:{feed_title}

