Apple sends new “threat alerts” about mercenary spyware attacks

Apple sends new “threat alerts” about mercenary spyware attacks

Apple

You’re not alone if you just received an “Apple Threat Notification” saying that a “mercenary spyware attack on your iPhone” has been detected.

Some users on Reddit report that they received these warnings today after Apple sent out a new batch of threat notifications on August 13, but the feature itself is not new.

Apple threat
Apple sent a new set of warnings to users on August 13th
Source: Reddit

Apple has been sending these threat notifications several times a year since 2021 when it detects highly targeted mercenary spyware attacks.

Picture

It’s also worth noting that Apple doesn’t identify the spyware behind individual alerts, so there’s no evidence that today’s alerts are specifically related to Pegasus.

However, Apple itself cites NSO Group’s Pegasus as an example of mercenary spyware that has been linked to this type of attack in the past, and forensic investigations of previous Apple threat alerts have confirmed Pegasus infections in some cases.

In one Support documentApple previously confirmed that it was sending threat notifications to users in more than 150 countries after detecting highly targeted mercenary spyware attacks against specific iPhone users.

The list of potential targets includes journalists, activists, politicians and diplomats, who have been among the targets of this type of spyware in the past.

These attacks are expensive, sophisticated, and typically target a very small number of people.

“Mercenary spyware attacks cost millions of dollars and often have a short shelf life, making them much more difficult to detect and prevent,” Apple explained.

“The vast majority of users will never be the target of such attacks.”

The Company does not attribute individual alerts to a specific government, company or geographic region.

Apple says threat notifications should be taken seriously

Apple relies on its own threat intelligence and research to identify suspected mercenary spyware activity, meaning these alerts are “high confidence alerts” and not just a regular alert.

“Although our investigations can never achieve absolute certainty, Apple’s threat notifications are highly suspicious alerts that a user has individually been targeted by a mercenary spyware attack and should be taken very seriously,” Apple noted.

“We are unable to provide information about why we issue threat notifications, as this could help mercenary spyware attackers adapt their behavior to avoid detection in the future.”

When Apple detects this activity, it sends an email and iMessage notification to the email addresses and phone numbers associated with the user’s Apple account.

The emails usually come from threat-notifications@email.apple.comand Apple also warns users about fake versions of these warnings.

You can check whether a threat notification is real because Apple doesn’t ask you to click a link, open a file, install an app or profile, or provide an Apple account password or verification code.

You can also check the notification by logging in directly to account.apple.com. If Apple has sent you a threat notification, it will appear at the top of the page after you’re signed in.

If you think you have been affected, you should activate lockdown mode and contact a cybersecurity expert.

Apple recommends that you take these warnings seriously because receiving one means a high level of confidence that the user has been individually addressed.

BleepingComputer reached out to Apple for comment on the threat notifications, but we have not received a response at the time of publication.


Item image

Overall prevention scores can hide what happens after the first access. Once attackers use valid credentials, prevention drops sharply.

The 2026 Blue Report measures defense technology for technology in 338 million simulations conducted in customer production environments.

Get the report

Leave a Reply

Your email address will not be published. Required fields are marked *