Apple dispatched a new wave of Threat Notification alerts on August 13, 2026, warning iPhone users in 110 countries that they may have been targeted by mercenary spyware attacks. The notifications — which appear on the Lock Screen, in device Settings, and via email from threat-notifications@email.apple.com — mark the latest escalation in a notification program Apple launched in 2021 that has now reached users in more than 150 countries cumulatively.
What the Notifications Say
If your iPhone received one of these alerts, the message reads:
"Apple detected a mercenary spyware attack targeted at your iPhone. There are actions you can take now to protect your data and device."
Apple has clarified that legitimate notifications will never ask you to click a link, open a file, install an app, or provide your Apple Account credentials. If you're unsure whether a notification is real, sign in directly to account.apple.com — legitimate warnings will also appear there as a banner.
Who Is Being Targeted
Mercenary spyware campaigns are highly targeted operations. Apple's notifications are typically sent to journalists, activists, politicians, and diplomats — people targeted because of their identity or work, not because of something they downloaded. The attacks are typically commissioned by or associated with nation-state actors, or private companies developing spyware on their behalf.
Apple does not disclose the number of individuals notified or the specific countries targeted in each wave.
Active Spyware Threats Tracked in 2026
While Apple does not name specific spyware in individual alerts, several mercenary spyware families are actively tracked as of August 2026:
| Spyware | Operator | Notable Technique |
|---|---|---|
| Pegasus | NSO Group | Zero-click iMessage exploits |
| Graphite | Paragon Solutions | Reads messages before encryption / after decryption on-device |
| Predator | Intellexa Consortium | Multi-stage delivery via redirect chains |
| DarkSword | Unknown | PoC published to GitHub; broadening threat actor pool |
Google's Threat Analysis Group (TAG) is currently tracking more than 40 companies in the commercial surveillance market.
Recent CVEs Linked to Mercenary Spyware
| CVE | Impact | Status |
|---|---|---|
| CVE-2025-43200 | Graphite/Paragon — linked to iPhone compromises | Patched in iOS 18.3.1 |
| CVE-2025-31277 | JavaScriptCore memory corruption | Patched |
| CVE-2025-43529 | JavaScriptCore memory corruption | Patched |
| CVE-2026-20700 | PAC bypass in dyld — zero-day at time of exploitation | Patched |
Devices running iOS 18.7.1 or earlier, or iOS 26.0–26.2, may remain vulnerable to DarkSword variants.
Zero-Click Exploits: No Interaction Required
The most dangerous aspect of these attacks is that many mercenary spyware tools use zero-click exploits — no tap, no link, no user action required. An attacker simply sends a malicious message; the device processes it in the background and is silently compromised. Standard antivirus software cannot detect these attacks. Forensic analysis requires specialized tools.
What to Do If You Receive a Threat Notification
Apple recommends the following immediate steps:
- Update iOS immediately — Install the latest version to close known exploit chains
- Enable Lockdown Mode — Dramatically reduces the attack surface for sophisticated spyware (Settings → Privacy & Security → Lockdown Mode)
- Contact a forensics expert — Reach the Digital Security Helpline at Access Now for 24/7 emergency support for civil society targets
- Verify the notification — Sign in to account.apple.com directly; do not click links in the notification
- Factory reset if compromised — A clean restore from a backup predating the suspected compromise is the safest remediation
Enabling Lockdown Mode
Lockdown Mode aggressively restricts device functionality to minimize the attack surface:
- Blocks most message attachment types in iMessage
- Disables FaceTime calls from unknown contacts
- Restricts shared albums and web-browsing JavaScript JIT
- Blocks wired connections from computers when the device is locked
Settings → Privacy & Security → Lockdown Mode → Turn On Lockdown Mode
Apple's Notification Program
Since 2021, Apple has sent Threat Notifications to users in over 150 countries. The program uses internal threat intelligence to identify devices that may have been compromised. Apple explicitly states it cannot achieve certainty in its detections, but errs on the side of notifying potential victims rather than remaining silent.
"Apple threat notifications are designed to inform and assist users who may have been individually targeted by mercenary spyware attacks." — Apple
References
- BleepingComputer — Apple sends new Threat Notification alerts over mercenary spyware attacks
- Apple — About Apple Threat Notifications and protecting against mercenary spyware
- Access Now — Digital Security Helpline