← BACK TO FEED
spywareApplesurveillancesecurityPegasus

Apple Pings Users in 110 Countries Over Mercenary Spyware Threats

Apple has sent threat notifications to users in 110 countries who may have been targeted by mercenary spyware attacks, bringing the total number of countries notified since 2021 to over 150. These sophisticated attacks typically target high-profile individuals such as journalists, activists, politicians, and diplomats, and represent some of the most advanced digital threats in existence. Apple delivers alerts via the iPhone lock screen, email, and the user's Apple Account page, and recommends protective measures such as enabling Lockdown Mode, using two-factor authentication, and keeping devices updated.

Apple has sent another round of threat notifications to users it believes may have been targeted by mercenary spyware, alerting an undisclosed number of people across 110 countries. The company has now issued warnings in over 150 countries since it began the notification programme in late 2021.

The targets aren't random. These alerts go to a narrow slice of high-value individuals: journalists, activists, politicians, diplomats. People who attract attention from well-funded, state-adjacent actors willing to spend serious money on surveillance tools.

Apple described the threat bluntly: "The extreme cost, sophistication, and worldwide nature of mercenary spyware attacks make them some of the most advanced digital threats in existence today." The company declined to name specific attackers or point fingers at particular governments, which is the sensible approach given how quickly threat actors adapt once their methods go public.

The notifications themselves arrive through three channels simultaneously: an alert on the iPhone lock screen and in Settings, an email from [email protected] to addresses linked to the user's Apple Account, and a banner on the Apple Account webpage at account.apple.com. If you get all three at once, Apple is reasonably confident you have a problem.

For most people reading this, the risk is close to zero. Mercenary spyware isn't spray-and-pray malware. It's expensive, targeted, and deployed against specific individuals. Building and maintaining these exploit chains costs enormous resources, which is why vendors like NSO Group charge state clients accordingly.

That said, if you happen to be someone whose work puts you in the crosshairs, Apple's recommended precautions are worth following: keep devices updated, use a strong passcode backed by biometrics, enable two-factor authentication, activate Stolen Device Protection, and turn on Lockdown Mode. The last one is the most aggressive option, stripping down a lot of functionality to significantly reduce the attack surface.

Avoid clicking links or opening attachments from senders you don't recognise. Which, frankly, should be standard practice for everyone regardless of whether they're being hunted by spyware vendors.

READ NEXT
The MEP Investigating Pegasus Got Hacked With Pegasus. Yes, Really.Predatorgate Victims Sue Intellexa for €8M Over Greek Spyware ScandalAI on the Battlefield: How Automated Kill Chains Leave Humans Mostly Out of the Loop