Apple’s mercenary spyware warnings are getting harder to miss. The alerts now appear directly on the iPhone Lock Screen and in Settings, putting them in front of targeted users before they even reach their inbox.
On Aug. 13, 2026, Apple confirmed that it sent a new round of threat notifications to targeted users in 110 countries. The alerts do not indicate a mass compromise: Apple describes them as high-confidence warnings that specific individuals were targeted, not proof that spyware was successfully installed.
BleepingComputer confirmed the 110-country figure with Apple. Apple’s threat notification guidance says the company has issued warnings multiple times a year since 2021 and has notified users in more than 150 countries overall.
A warning signals targeting, not a confirmed breach
Apple bases the notifications on its own threat intelligence and investigations. Mercenary spyware campaigns have historically targeted small numbers of journalists, activists, politicians and diplomats, while Apple says the vast majority of users will never face such attacks.
The company does not disclose what evidence triggered a notification or attribute individual alerts to a particular attacker or region. Apple has not identified the spyware behind the Aug. 13 warnings, so there is no basis to link this batch specifically to NSO Group’s Pegasus or another named product.
Past warnings have preceded confirmed infections. Citizen Lab researchers forensically confirmed in 2025 that journalists who received Apple notifications were targeted with Paragon’s Graphite spyware, including one device compromised through a zero-click iMessage attack.
Apple has also experimented with more visible protections in Messages. In July, an iOS 26.6 beta revealed a malicious iMessage warning designed to flag potentially dangerous messages and let recipients report them.
Verify the alert before responding
Recipients can verify a warning by signing in directly at account.apple.com, where Apple says a legitimate threat notification appears at the top of the page. Genuine threat-notification emails will not ask users to open attachments, install apps or configuration profiles, or provide an Apple Account password or verification code.
Apple urges notified users to seek expert assistance. Access Now advises at-risk civil society users not to erase a potentially affected device because doing so can destroy evidence that may be useful for forensic analysis.
Lockdown Mode is another recommendation. In March 2026, Apple told TechCrunch it was not aware of any successful mercenary spyware attack against an Apple device while Lockdown Mode was enabled.
Keeping devices patched remains important. Apple has been releasing some iPhone security fixes sooner rather than waiting for broader iOS releases, and its July updates patched 194 unique vulnerabilities across iPhones, Macs and other devices.
Organizations supporting high-risk personnel should establish who verifies a warning, who handles escalation and when Lockdown Mode or outside forensic help should be used. Treating mercenary spyware alerts as an incident-response scenario rather than an ordinary user-support ticket can reduce delays when a targeted employee receives one.
Read more: The spyware alerts add to a broader 2026 pattern of Apple security fixes, with zero-days and exploit chains continuing to shape iPhone risk management for organizations maintaining large mobile fleets.
No Comment! Be the first one.