Quick Answer: Apple sent its largest-ever wave of mercenary spyware threat notifications on August 13, 2026, warning iPhone users in 110 countries that they may have been individually targeted by sophisticated, government-grade spyware. For the first time, the alert now appears directly on the iPhone’s Lock Screen instead of only in an email or account page that’s easy to miss. Digital rights group Access Now reported a 30–40% surge in people seeking help compared to previous notification waves, calling it “unprecedented.” If you receive this notification, it does not mean your phone is definitely infected — but Apple says it should be taken very seriously. The recommended steps are to enable Lockdown Mode, update your software immediately, and contact a free service like Access Now’s Digital Security Helpline for expert help.

What Happened on August 13
On Thursday, August 13, 2026, Apple sent a fresh batch of “threat notifications” to iPhone users it believes were individually targeted by mercenary spyware, reaching people in 110 countries. Apple confirmed the scale directly to TechCrunch and republished an updated support page the same day describing a significant change to how the alerts are delivered.
For the first time, the warning now appears as a banner directly on the iPhone’s Lock Screen and as a permanent entry in the Settings app, rather than relying solely on email, iMessage, or a banner buried on the Apple Account website. Those older channels were easy for at-risk people to miss, filter as spam, or dismiss outright — a Lock Screen banner is much harder to overlook.
By the following weekend, digital rights groups reported an unusual surge in people reaching out for help. Mohammed Al-Maskati, who directs the investigator team at Access Now’s Digital Security Helpline, told TechCrunch the nonprofit received 30% to 40% more requests for assistance than it typically sees after an Apple notification wave — including from people who had received similar alerts in the past. Cybersecurity firm iVerify separately confirmed it was also seeing an influx in threat notifications.
Exactly What the Notification Says
If you receive one of these alerts, the message reads: “Apple detected a mercenary spyware attack targeted at your iPhone. There are actions you can take now to help protect your data and device.” Apple’s official support documentation describes these as “high-confidence alerts that a user has been individually targeted by a mercenary spyware attack, and should be taken very seriously.”
Apple sends the notification through multiple channels simultaneously: the new Lock Screen banner, a persistent entry in Settings, an email from the address threat-notifications@email.apple.com, and a banner on the user’s Apple Account page. Because so many channels are used at once, it’s worth noting that this is one of the most convincing templates a phishing scam could copy — always verify a suspicious “Apple security” email by checking your Apple Account page directly rather than clicking any link inside the email itself.
What Is Mercenary Spyware?
Apple defines mercenary spyware as attacks that are “vastly more sophisticated than regular cybercriminal activity.” Unlike mass-market malware or ordinary phishing, mercenary spyware attackers apply exceptional financial resources to target a very small number of specific individuals and their devices, often exploiting zero-day or even zero-click vulnerabilities that require no action from the victim at all.
These campaigns are extremely expensive to run — often costing millions of dollars — and typically have a short shelf life before the vulnerabilities they exploit get patched. That combination of cost and sophistication is exactly why they’re historically been associated with governments and the private surveillance companies that build tools for them, most notably NSO Group’s Pegasus software, along with other tools researchers have identified such as Predator, Graphite, and Triangulation.
Apple deliberately does not identify the specific spyware or attacker behind any individual notification. The company has said that disclosing more detail about how it detects these attacks could give attackers useful information for evading detection in the future.
Who Actually Gets Targeted?
The vast majority of iPhone users will never receive one of these notifications. Mercenary spyware is precision tooling, not a mass-market threat — targets are typically selected because of who they are or what they do, not at random. Historically, that has meant journalists, human rights activists, politicians, diplomats, and lawyers.
Security researchers say that target list has broadened in recent years. Adam Boynton, a senior enterprise strategy manager at device-management firm Jamf, told outlets covering the story that “the economics of mercenary spyware mean the target list increasingly includes executives, negotiators, and anyone holding privileged access.” His advice for anyone in a corporate environment: if one of these notifications lands on a work device, it should be treated as a security incident from the first minute, not a routine alert to dismiss.
Does This Mean My Phone Is Infected?
Not necessarily. Apple is explicit that its investigations “can never achieve absolute certainty,” even though it describes the notifications as high-confidence alerts. Receiving one means Apple detected activity consistent with a targeted attack — it does not automatically confirm that an attacker successfully compromised your device or accessed your data.
That distinction matters for how you should respond. A threat notification is a strong signal that you were targeted, not necessarily proof that the attack succeeded. Either way, Apple and independent security researchers agree the right response is the same: treat it seriously and act quickly, rather than waiting to find out for certain.
What to Do If You Receive a Threat Notification
Security researchers and Apple’s own guidance converge on the same set of immediate steps if you get one of these alerts:

- Enable Lockdown Mode. Go to Settings > Privacy & Security > Lockdown Mode and turn it on. This is the single most effective step available to regular users, discussed in more detail below.
- Update your software immediately. Install the latest iOS, iPadOS, or macOS update, since these often contain patches for the exact vulnerabilities mercenary spyware relies on.
- Contact a digital security helpline. Access Now’s Digital Security Helpline offers free, expert assistance to people who receive these notifications and is the organization Apple itself points affected users toward.
- Turn on two-factor authentication and use a strong, unique password for your Apple Account if you haven’t already.
- Enable Stolen Device Protection in Settings, which adds extra security barriers if your device is ever physically stolen.
- Don’t try to do your own forensic investigation. Apple does not perform device forensics itself, and security experts generally agree this task is best left to nonprofits and specialists rather than attempted independently, since mishandling a potentially compromised device can destroy the evidence investigators would need.
Why Lockdown Mode Is the Recommended First Step
Lockdown Mode is an extreme, opt-in protection feature Apple introduced in iOS 16 back in 2022, specifically designed for the small number of people who face this kind of targeted threat. It works by aggressively restricting features that are common attack vectors: it blocks most message attachment types, limits incoming FaceTime calls from people not already in your contacts, and restricts certain web browsing technologies that attackers commonly exploit.
Enabling it changes how your phone behaves day to day — some links, previews, and features you’re used to will stop working or require extra steps. That trade-off is deliberate: Lockdown Mode is meant to shrink the attack surface as much as possible for someone who has reason to believe they’re an active target, not to be a feature everyone leaves on permanently.
The track record so far is notable. As of March 2026, an Apple spokesperson told TechCrunch the company is not aware of any successful mercenary spyware attack against a device that had Lockdown Mode switched on — nearly four years after the feature first shipped. Donncha Ó Cearbhaill, who leads Amnesty International’s Security Lab and has investigated dozens of these cases, has said the same thing independently: no evidence of a successful compromise while Lockdown Mode was active at the time of an attack. Citizen Lab has separately documented specific instances where Lockdown Mode blocked live attack attempts, including at least one using NSO Group’s Pegasus software.
You can turn it on by going to Settings > Privacy & Security > Lockdown Mode, and it doesn’t require a device wipe or any special configuration to enable.
How This Program Has Grown Since 2021
Apple has been sending threat notifications since 2021, but the scale has increased noticeably in recent years:
- July 2024: A wave reached users across 98 countries.
- April 2025: A separate wave reached users in 92 countries.
- Early-to-mid 2025: France’s national cybersecurity agency, CERT-FR, documented four separate waves of Apple alerts between March and September, citing tools including Pegasus, Predator, Graphite, and Triangulation.
- August 13, 2026: The current wave reaches 110 countries — described by researchers as the largest and most geographically diverse batch yet, and the first delivered via a Lock Screen banner.
Apple has confirmed it has now notified customers in more than 150 countries in total since the program began, though the company has never disclosed how many individual people that represents — only the country count, which has climbed nearly every year the program has run.
John Scott-Railton, a senior researcher at the University of Toronto’s Citizen Lab who first flagged the latest wave publicly on social media, described the pattern this way: “The scale and geographic diversity of public posts about receiving notifications are pretty unprecedented. For every public notification like this, you can imagine there’s a huge notification iceberg that the public will never learn about.”
The Legal Backdrop: NSO Group’s Ongoing Court Battle
This notification wave lands against the backdrop of an active legal fight between Meta and NSO Group, the Israeli company behind Pegasus. A federal court found NSO liable for violating US anti-hacking laws in a case brought by WhatsApp, and a jury awarded roughly $167 million in damages in May 2025. A permanent injunction against NSO took effect on January 28, 2026.
That injunction hasn’t ended the story. Meta filed a contempt motion in June 2026, alleging that NSO ran new spyware campaigns targeting WhatsApp users within days of the injunction taking legal effect — suggesting that even a major US court judgment hasn’t fully stopped mercenary spyware operations tied to the company.
Why the Lock Screen Change Matters
The shift from email-only delivery to a Lock Screen banner might sound like a minor UX tweak, but security researchers see it as a meaningful change in how seriously Apple wants these warnings treated. Email notifications can sit unread for days or get caught in a spam filter; a banner that appears every time you unlock your phone is nearly impossible to miss.
It also removes a common excuse people have used to explain away not acting on a warning. A Lock Screen banner backed by a permanent row in Settings makes it much harder for an at-risk person — or the people around them, like a security team or family member — to argue they simply never saw it.
Is This a Risk to the Average iPhone User?
For the overwhelming majority of iPhone owners, the honest answer is no. Mercenary spyware campaigns cost millions of dollars to run against a single target, which is precisely why they’re reserved for people whose access, position, or work makes them valuable enough to justify that cost. A random consumer simply isn’t a profitable target for this kind of attack.
That said, the definition of “valuable target” keeps expanding, as Jamf’s Adam Boynton pointed out — it’s no longer limited to the classic list of journalists and activists. Anyone with access to sensitive negotiations, financial systems, or confidential information at a company could plausibly become a target, which is part of why security teams at larger organizations are treating this notification wave as a reminder to review their own incident-response plans, even for staff well outside the traditional risk categories.
How to Tell a Real Notification From a Phishing Attempt
Because the genuine Apple threat notification is delivered by email as well as on-device, it has inadvertently become a template that phishing scammers could try to imitate. A few ways to verify a notification is legitimate:
- Check your Apple Account page directly by typing the address into your browser yourself, rather than clicking any link in an email — genuine alerts also appear there.
- Look for the notification on your Lock Screen and in Settings under the dedicated threat notification entry — a phishing email won’t be able to fake this on-device placement.
- Verify the sender address is exactly threat-notifications@email.apple.com, and be skeptical of any lookalike domain.
- Apple will never ask for your password, verification code, or payment details as part of a threat notification. Any message asking for those is not legitimate, regardless of how convincing it looks.
What Happens After You Report a Notification
If you contact Access Now’s Digital Security Helpline or a similar organization after receiving a notification, the process typically starts with an intake conversation about your specific situation — your role, what data or accounts might be sensitive, and what device you received the alert on. From there, investigators may ask you to preserve the device in its current state rather than restarting or resetting it, since some forensic evidence can be lost the moment a device reboots or gets wiped.
Depending on the case, a full forensic analysis can take anywhere from a few days to several weeks, particularly if investigators need to coordinate with other research groups like Citizen Lab or Amnesty International’s Security Lab to confirm findings. Not every case results in a confirmed identification of the specific spyware involved — sometimes the evidence is inconclusive, which is part of why Apple frames its own notifications as high-confidence rather than certain.
Throughout this process, it’s worth continuing to use the device normally rather than avoiding it entirely, unless a security professional specifically advises otherwise. Mercenary spyware operators are aware that abrupt behavior changes — like suddenly going silent on a device — can itself be a signal, and normal usage patterns while an investigation proceeds are generally considered fine.
What This Means If You Manage a Company’s Security
For IT and security teams, this notification wave is a useful prompt to revisit how prepared an organization actually is to treat a threat notification as a genuine incident rather than routine noise. A few practical steps worth considering:
- Build a specific response plan for what happens when an employee reports receiving an Apple threat notification, separate from your general phishing or malware incident playbook, since the appropriate response differs meaningfully.
- Identify which roles carry elevated risk beyond the traditional list of executives — anyone handling sensitive negotiations, financial approvals, or privileged system access should be considered, per the expanding target profile researchers have described.
- Pre-approve Lockdown Mode for high-risk roles on company-managed devices, so enabling it doesn’t require a lengthy approval process in the middle of a live incident.
- Maintain a relationship with a forensics partner like Jamf or a similar mobile device management firm before an incident happens, rather than searching for one for the first time during an active investigation.
The Broader Trend: Why These Waves Keep Growing
Part of what makes this year’s notification wave notable isn’t just its size, but what it suggests about the trajectory of the mercenary spyware market as a whole. The country count in Apple’s cumulative notifications has climbed almost every year since the program’s 2021 launch, moving from isolated regional campaigns toward what researchers now describe as a genuinely global market for surveillance tools.
That growth tracks with a broader pattern documented by organizations like Citizen Lab: commercial spyware vendors have proliferated well beyond the handful of companies that dominated headlines in the early 2020s, and the tools themselves have become more sophisticated even as legal and regulatory pressure has mounted against specific vendors like NSO Group. The Meta-NSO litigation shows that even a decisive US court victory hasn’t been enough to fully halt spyware campaigns tied to a single company, which gives some indication of how difficult this problem is to solve through legal action alone.
Frequently Asked Questions
What does Apple’s spyware threat notification actually mean?
It means Apple’s threat intelligence systems detected activity consistent with a mercenary spyware attack specifically targeting your device. It is a high-confidence warning, not automatic proof that your device was successfully compromised.
How many people received the August 2026 notification?
Apple has not disclosed an exact number of individuals, only that the notifications reached users across 110 countries on August 13, 2026 — the largest and most geographically widespread wave since the program began in 2021.
Should I panic if I get this notification?
No, but you should act quickly. Enable Lockdown Mode, update your device’s software, and contact a free resource like Access Now’s Digital Security Helpline for expert guidance rather than trying to investigate the device yourself.
Does Lockdown Mode actually work?
According to Apple, Amnesty International’s Security Lab, and Citizen Lab, there are no confirmed cases of a successful mercenary spyware compromise on a device that had Lockdown Mode enabled at the time of the attack, including at least one documented case where it blocked a live Pegasus attempt.
Is the average iPhone user at risk of mercenary spyware?
No. These attacks cost millions of dollars to run against a single target and are reserved for people with specific access, influence, or professional exposure, not random consumers.
How is this notification different from previous years?
This is the first wave delivered as a direct Lock Screen banner rather than relying only on email or the Apple Account website, making it significantly harder for a targeted person to miss or overlook.
What spyware is Apple warning about specifically?
Apple does not name the specific spyware or attacker behind any individual notification, to avoid giving attackers information that could help them evade detection. Historically, tools associated with these attacks include NSO Group’s Pegasus, along with Predator, Graphite, and Triangulation.
Can a threat notification be a phishing scam?
Yes, scammers can attempt to imitate the email format. Verify any notification by checking your Apple Account page directly and confirming it also appears on your Lock Screen and in Settings, since a fake email cannot replicate that on-device placement.



