IC Technology & Cyber — 2026-08-16

Apple Sends Mercenary Spyware Alerts to Users in 110 Countries via New Lock Screen Warning

BLUFApple's expanded Lock Screen warnings strengthen the civil-society accountability pipeline that has exposed state spyware abuses, yet the growing scale of each notification round confirms the commercial spyware market is outpacing regulatory constraint.

Apple sent a new round of threat notifications on Thursday to users in 110 countries, part of a program that has now reached individuals in over 150 countries since 2021 mercenary spyware" data-source="Apple Support" data-url="https://support.apple.com/en-us/102174" data-rt="primary" data-mbfc="mixed" data-otype="trade_press">123. Apple published a support article confirming the alerts now appear directly on the iPhone Lock Screen and in Settings, supplementing existing email and Apple Account page notifications 14. Apple describes the alerts as high-confidence indications that a user has been individually targeted by a mercenary spyware attack and says it does not attribute the notifications to any specific attacker or region 13. Citizen Lab researcher John Scott-Railton first identified the batch on X and told TechCrunch the notifications helped surface Poland's spyware scandal involving its former government 2. Apple is urging recipients to enable Lockdown Mode, saying no device with the feature turned on has been successfully compromised by spyware 2.

Analysis
Apple's shift of these alerts onto the Lock Screen closes the gap between detection and user awareness, feeding targeted individuals more directly into the Citizen Lab and Access Now referral pipeline that has previously turned isolated alerts into public accountability scandals, as Poland's spyware affair demonstrated. Apple's refusal to name attackers or regions leaves state sponsors and their vendors unidentified even as the recurring scale of these rounds points to a widening market for individually targeted spyware, though sourcing rests on Apple's own support article as the sole primary document, with Malwarebytes, TechCrunch, and The Hacker News offering secondary amplification rather than independent confirmation. The expanded alert surface may serve Apple's liability and compliance posture as much as spyware deterrence, shifting responsibility for post-notification protection onto users and NGOs rather than reflecting improved detection capability.
4 sources
  1. About Apple threat notifications and protecting against mercenary spyware - Apple Support
  2. If Apple sends you a push notification alerting you to a spyware attack, take it seriously - TechCrunch
  3. Apple Warns Users in 110 Countries They May Be Targets of Mercenary Spyware - The Hacker News
  4. Apple now uses iPhone alerts for targets of mercenary spyware - Malwarebytes

View in full brief →

UNCLASSIFIED // OPEN SOURCE