Apple sent threat notifications on Thursday to users in 110 countries it suspects may have been targeted by mercenary spyware. Since it began the programme in late 2021, it has notified people in more than 150 countries.

Apple's characterisation:

The extreme cost, sophistication, and worldwide nature of mercenary spyware attacks make them some of the most advanced digital threats in existence today.

And, importantly:

[Apple] does not attribute the attacks or resulting threat notifications to any specific attackers or geographical regions.

Who gets one

These are not broad warnings. Notifications typically reach people singled out by their identity or role — journalists, activists, politicians, diplomats — and Apple describes them as high-confidence alerts about individualised targeting.

That framing is the useful part. A mercenary spyware operator is spending a great deal of money per target. Receiving one of these means someone decided you specifically were worth that spend.

How the notification arrives

Three channels, deliberately:

The redundancy exists because the notification itself is an obvious phishing lure. Anyone can send an email claiming to be an Apple spyware warning; only Apple can put a banner on your Apple Account page.

If you receive one: do not click links in the email. Sign in to your Apple Account page directly and check for the banner. That single step distinguishes a real notification from the copycat campaigns that follow every round.

What Apple recommends

Update devices; use a passcode or biometrics; enable two-factor authentication; turn on Stolen Device Protection and Lockdown Mode; install apps only from trusted sources; do not open links or attachments from unknown senders.

Lockdown Mode is the one that matters here and the one almost nobody enables. It disables the attack surface these operators actually use — most message attachment types, some web technologies, incoming FaceTime from unknown callers, wired accessory connections while locked. It makes the phone meaningfully less pleasant to use, which is why it is off by default, and it is the only item on that list designed specifically against this threat.

The attribution gap

Apple's refusal to name vendors or regions is defensible: naming would expose detection methodology, and a wrong attribution against a state or a company is a legal and diplomatic problem Apple does not need.

It also leaves the recipient with a warning and no context. "You may have been targeted" does not tell you by whom, through what, whether it succeeded, or whether it is still happening.

In practice that gap gets filled by others. Citizen Lab and Amnesty International's Security Lab have historically done the forensic work on notified devices and produced the attribution Apple will not — which is how NSO Group's Pegasus, Intellexa's Predator and others have been documented. Anyone receiving a notification should be talking to one of those organisations, not just following the checklist.

What is not established

  • How many people were notified. Apple gives country counts, never user counts, and 110 countries could be hundreds of people or thousands.
  • Which spyware or vendors. Apple does not say and we found no reporting that established it for this round.
  • Whether any attempt succeeded. A notification means suspected targeting, not confirmed compromise.
  • What triggered this round. No campaign, vulnerability or vendor has been publicly tied to it in what we read.
  • Reaction from Citizen Lab or Amnesty on this specific round — we did not find a statement.

Why a mainstream tech audience should care

The instinct is that this is a story about journalists in other countries. Two reasons it is not only that.

The techniques descend. Mercenary spyware chains — zero-click message exploits, malicious attachment parsing, exploit chains against browser engines — are the highest-end work being done against phones, and the vulnerability classes reach commodity criminal tooling eventually.

The defences are already in your settings. Lockdown Mode, Stolen Device Protection and Advanced Data Protection exist because of this threat, and are available to everyone. Most people have never opened that screen.

The one action worth taking from this story, if you are not a likely target: open Settings and look at what Lockdown Mode actually turns off. You probably will not enable it. You will learn what your phone's attack surface consists of.