Aug 14, 2026 · 6 min read
Apple Warns Spyware Targets in 110 Countries
Apple's August 13 wave of mercenary spyware threat notifications reached 110 countries, and for the first time it lands as a push alert on the iPhone Lock Screen rather than only in an inbox.
This one did not wait in an inbox. On Thursday, August 13, 2026, people in 110 countries picked up an iPhone and found a banner already on the Lock Screen: Apple had detected a mercenary spyware attack aimed at that device. Apple republished its support document the same day. These are high confidence alerts that a user has been individually targeted, and they should be taken very seriously.
Key Takeaways
- Apple sent mercenary spyware threat notifications to users in 110 countries on August 13, 2026.
- Apple states it has notified users in over 150 countries in total since the program began in 2021.
- The alert now appears on the iPhone Lock Screen and in Settings, alongside an email from threat-notifications@email.apple.com.
- Apple names no spyware vendor, government, or region, and says a genuine notification never asks you to click a link, install anything, or hand over a password.
- The only verification Apple endorses is signing in to account.apple.com, where a real notification appears as a banner at the top of the page.
What Did Apple Send on August 13, 2026?
Apple told individually targeted users that mercenary spyware had been aimed at their devices, and TechCrunch reported the wave reached 110 countries. The message is short: Apple detected a mercenary spyware attack targeted at your iPhone, and there are actions you can take now to protect your data and device.
What Apple will not say is who did it. Its support document states that Apple does not attribute the attacks to any specific attackers or regions, and will not describe what triggered an alert, since that would help attackers evade detection. BleepingComputer noted there is therefore no evidence tying this batch to Pegasus or any other named product. The victim profile has not changed since 2021: journalists, activists, politicians, and diplomats. We have covered confirmed cases, including the Pegasus infection of the EU lawmaker investigating Pegasus.
Why Does the Lock Screen Alert Change Anything?
Because an email can sit unopened for a week and a Lock Screen banner cannot. Apple now documents three channels for one notification: an alert on the Lock Screen and in Settings, an email to the addresses on the Apple Account, and a banner atop the account page after sign in. As of 2026, the page says, Apple notifies targeted users directly on iPhone as well as by email from Apple Threat Notifications (threat-notifications@email.apple.com).
Speed matters more here than for a routine warning. Citizen Lab senior researcher John Scott-Railton told TechCrunch that the notifications "create a critical signal that a community is being targeted," and that recipients then reach out for help. That chain only starts when the alert is seen.
There is a tradeoff nobody has said out loud. A Lock Screen banner is visible to anyone standing near the phone: a border officer, a colleague, a relative in a household where being flagged as a target is itself dangerous. The channel that guarantees you see the warning guarantees others might.
Is 110 Countries a Lot?
It is the widest single wave publicly reported. On April 10, 2024, Amnesty International recorded a wave covering 92 countries. This one covers 110, roughly a fifth more ground a little over two years later, and the cumulative total now stands above 150 countries.
Here is the part most coverage skips. The count is the least informative number in the story, because Apple never says how many people were notified. One targeted diplomat puts a whole country on the list. So 110 countries, more than half the 193 UN member states, describes the geography of the spyware market rather than the size of this attack.
What This Means for Your Inbox
Every threat notification is also an email, which makes it one of the most valuable phishing templates in circulation. Apple sends the warning to the addresses on the Apple Account from a fixed sender. A scammer copying that format has a lure beating almost anything else in the inbox.
Attackers do not even need a forgery. In April 2026, researchers documented a campaign that stuffed scam text into the name fields of an Apple Account, so Apple's own servers delivered it inside a real account change email that passed SPF, DKIM, and DMARC. We covered it in phishing sent from Apple's own email servers. Aimed at threat notifications, that playbook produces a spyware warning which authenticates perfectly and still ends in a credential theft link.
The email carries a quieter signal. If a real notification arrives, an operator with state client resources already knew which address belongs to you. For anyone keeping a public address separate from a private one, that is the moment to audit which inbox is tied to the Apple Account.
How Do You Verify a Real Apple Threat Notification?
Type account.apple.com yourself and sign in, then check for a threat notification banner at the top of the page. Apple names that as the verification method, and it is the only one that works: it depends on nothing inside the message you received.
The negative rules matter just as much. Apple states its notifications never ask a user to click links, open files, install apps or profiles, or hand over an Apple Account password or verification code. A supposed spyware alert that does any of those is a fraud, no matter how correct the sender looks. Our guide on what to do after a government spyware alert applies the same discipline to Google's equivalent warnings.
One nuance, flagged by Amnesty International: a notification means a targeting attempt was detected, not a confirmed infection. Only forensics settle that, and Access Now's Digital Security Helpline, which Apple points recipients toward, does that work free for civil society targets.
Should You Turn On Lockdown Mode?
If you received a notification, yes, and Apple recommends it in the alert. Lockdown Mode strips out the surfaces zero click exploits keep landing on. Apple's documentation lists blocked message attachment types, unavailable links and link previews, complex web technologies disabled in Safari, incoming FaceTime calls blocked unless you called that person in the past 30 days, and accessory connections refused unless the device is unlocked.
The cost is real: some sites break, some attachments will not open, shared albums disappear. The benefit is the strongest claim Apple makes about any security feature it ships, examined in Apple's record on Lockdown Mode and spyware.
What to Do in the Next Hour
The sequence below is what responders will ask about anyway. It follows Apple's own guidance and Amnesty's advice to recipients.
- Verify at account.apple.com, typed by hand, never through a link in the message.
- Do not factory reset the phone. A wipe destroys the evidence an analyst needs.
- Contact a responder before changing anything else. Access Now's helpline runs 24 hours a day.
- Turn on Lockdown Mode, update to the latest iOS release, and confirm two factor authentication on the Apple Account.
- Assume the device contents are compromised and warn the people in them, especially sources who never agreed to be there.
And treat the email version as untrusted until the account page confirms it. The genuine warning and a perfect forgery now look almost identical, which is exactly what an attacker was hoping for.