Apple Notifies Users of Mercenary Spyware Attacks
Apple issued Threat Notifications to iPhone users warning of active mercenary spyware attacks. If you received one, here is what to do immediately.
Active wave confirmed. Apple issued “Threat Notifications” to an unspecified number of iPhone users stating it detected a “mercenary spyware attack targeted at your iPhone.” BleepingComputer, August 14, 2026.
What This Notification Means
Apple’s Threat Notification system does not send precautionary alerts. A notification means Apple’s internal telemetry identified indicators consistent with a targeted attack against that specific Apple ID or device. Apple states its threshold before sending is high confidence — not suspicion, not anomaly.
“Mercenary spyware” is Apple’s term for commercial surveillance software sold to governments and state-aligned clients. Highly targeted. Expensive. Typically deployed against journalists, lawyers, activists, opposition politicians, and human rights workers. If you received a notification: this is not a phishing test and it is not a mistake.
Confidence on actor and specific tooling: Not yet identified in public reporting as of this writing. Attribution to a named vendor or government client: pending.
What Notified Users Should Do
-
Enable Lockdown Mode immediately. Settings → Privacy & Security → Lockdown Mode. This hardens the attack surface that mercenary spyware tools typically exploit — restricting JavaScript compilation, message link previews, FaceTime from unknown callers, and other entry vectors. The performance trade-off is real and acceptable given the threat.
-
Update iOS to the latest release. Apple patches the zero-click and zero-day entry points these tools exploit. Running an outdated build past this point is a choice, not bad luck.
-
Get professional forensic support. Apple’s notification is not a forensic determination of active compromise. To confirm and remediate, contact Access Now’s Digital Security Helpline or reach Citizen Lab through the University of Toronto’s Munk School. Self-assessment with standard tools is not sufficient for mercenary-grade implants — some leave minimal traces and actively evade on-device detection.
-
Do not click the notification itself to access further details. Navigate to Apple’s support page for threat notifications directly from a trusted browser. Notification UI can be spoofed.
If you did not receive a notification: Not included in this wave. That is not a forensic clearance for prior campaigns.
Prior Waves
Apple has issued Threat Notifications in prior waves — following NSO Group Pegasus campaigns documented by Citizen Lab, following commercial spyware used against journalists and activists across multiple countries, and following broader European mercenary spyware disclosures. This is an established channel, not a new feature. Prior waves preceded researcher disclosures by days to weeks.
Analysis — labeled as assessment: Whether this wave reflects a newly identified campaign or previously undetected targeting from an existing operation is unconfirmed. The breadth of the current notification wave — enough recipients to generate public discussion — suggests systematic identification of a campaign rather than isolated incidents. Expect follow-up research disclosure from Citizen Lab, Amnesty International’s Security Lab, or a named vendor PSIRT within days.
Previously on 0dayNews: Citizen Lab Confirms Pegasus on MEP’s Phone · Apple topic hub · Mobile topic hub
Found this useful? Share it.


