Apple's Latest Threat Notifications Reach 110 Countries
Apple has sent a fresh round of threat notifications to a carefully selected group of iPhone, iPad and Mac users, warning them that they may have been targeted by what the company calls mercenary spyware. The warnings went out on Thursday to customers in 110 countries, according to Apple, and are aimed at a narrow set of users: journalists, activists, politicians, diplomats and others with prominent public roles.
Apple says the spyware is not ordinary cybercrime. If it succeeds, it can bypass built-in encryption, read private files, listen to conversations, capture audio and video, track locations and take control of the device. The attacks are described as mercenary because they are typically deployed by or on behalf of nation states, cost millions of dollars and often have only a short window in which they remain effective. John Scott-Railton of Citizen Lab shared what the on-device notice looks like: an Apple Threat Notification saying that Apple detected a mercenary spyware attack targeted at the user's iPhone.
The company has issued these warnings multiple times a year and says it has alerted people in more than 150 countries to date; in 2024 alone there were two rounds. One company frequently named in connection with such attacks is NSO Group, maker of the Pegasus spyware. NSO denies wrongdoing and says it sells only to law enforcement and intelligence agencies to fight terrorism and crime, but Apple and other firms have sued the company, and software vendors have had to patch vulnerabilities exploited by Pegasus.
Why These Spyware Alerts Are Different From Everyday Malware
What makes the current alert different
Apple treats these notices as a higher-order warning than routine malware alerts. The company's support language says mercenary spyware attacks are vastly more sophisticated than regular cybercriminal activity because attackers apply exceptional resources to a very small number of specific individuals and their devices. Those economics explain why Apple warns in waves and why the notice directs recipients to Lockdown Mode rather than simply recommending a password update.
The NSO Group legal and reputational pressure
The new warnings land while NSO Group remains a focal point of litigation and public scrutiny. Apple and other companies have sued NSO Group, and the maker of Pegasus has repeatedly denied responsibility, saying its tools are sold to government agencies for lawful use. Even without naming the actor behind this specific wave, the announcement keeps the spotlight on commercial spyware vendors whose products have been used against journalists and activists.
What Lockdown Mode actually changes
Lockdown Mode is the central defensive response because it dramatically shrinks the attack surface. It blocks most message attachments and link previews, restricts advanced web technologies, limits FaceTime calls, disables features like SharePlay and Game Center, removes shared photo albums and location data from shared images, and stops configuration profiles and insecure Wi-Fi connections. That is designed to blunt exactly the methods a sophisticated spyware operator would use to deliver or maintain access.
What to Do If Apple Says You Were Targeted
If Apple sends you a threat notification, start with Lockdown Mode. On an iPhone or iPad, go to Settings > Privacy & Security, scroll to the bottom, tap Lockdown Mode, then Turn On Lockdown Mode. On a Mac, open System Settings > Privacy & Security > Lockdown Mode and turn it on.
- Update the device immediately: install the latest iOS, iPadOS or macOS so current security fixes are in place.
- Secure the Apple Account: use a strong unique password and two-factor authentication, and turn on Stolen Device Protection.
- Lock the device: require a passcode, Touch ID or Face ID rather than leaving the device unlocked.
- Reduce delivery routes: do not open links or attachments from unknown senders, and install apps only from the App Store.
- Use passkeys where supported and strong unique passwords elsewhere.
For users who did not receive a notification, Apple's guidance is the same for everyday hygiene, but the immediate Lockdown Mode step is most relevant to the small number of people explicitly warned.
Risk & Opportunity Assessment
| Commercial Risk | High | NSO Group faces ongoing litigation from Apple and other firms, and the new warnings reinforce commercial pressure on its Pegasus business, which denies wrongdoing but is repeatedly linked to attacks on journalists and activists. |
| Competitive Risk | Low | The alert does not name a direct smartphone or security competitor; Apple's Lockdown Mode response mainly strengthens its own security positioning among high-risk users. |
| Regulatory Risk | Medium | Legal actions by Apple and other companies against NSO Group signal continued judicial and policy scrutiny of commercial spyware vendors, even though no new government action is specified in this alert. |
| Reputation Risk | High | Apple's 110-country warning and Citizen Lab's public notice again associate NSO Group and mercenary spyware with attacks on journalists, activists, politicians and diplomats, deepening reputational damage. |
| Technology Disruption | High | Mercenary spyware can bypass built-in encryption, capture audio/video, track location and control devices; Lockdown Mode disables features commonly used for delivery and persistence. |
| Commercial Opportunity | Medium | The notification casts Apple's security features and Lockdown Mode as essential for high-risk users, which may strengthen trust and loyalty among journalists, diplomats and other targeted groups. |
Comments 0