Apple Threat Notification Warns iPhone Users of Mercenary Spyware Attacks
If you recently received an Apple Threat Notification warning that a “mercenary spyware attack targeting iPhones” has been detected, you are not alone.
Several users reported on Reddit that they received Apple threat alerts after the company sent a new round of notifications on August 13. However, Apple’s threat notification system is not new.

Source: Reddit
Since 2021, Apple has sent these notifications several times a year when its security systems detect highly targeted attacks involving mercenary spyware.
Apple does not identify the specific spyware associated with individual alerts. Therefore, there is no evidence that the latest notification is directly linked to Pegasus.
However, Apple has cited NSO Group’s Pegasus spyware as an example of mercenary spyware used in highly targeted attacks. Forensic investigations of previous Apple threat notifications have also confirmed Pegasus infections in some cases.
According to Apple’s support documentation, the company has sent threat notifications to users in more than 150 countries after identifying highly targeted mercenary spyware attacks against specific iPhone users.
Potential targets have included journalists, activists, politicians, diplomats, and other individuals whose work or public roles make them valuable targets for sophisticated surveillance campaigns.
Mercenary spyware attacks are expensive, highly advanced, and typically directed at a very small number of people.
“Mercenary spyware attacks cost millions of dollars and often have a short shelf life, making them extremely difficult to detect and prevent,” Apple explained.
“The vast majority of users would never be the target of such an attack.”
Apple also says it does not attribute individual threat notifications to a specific government, company, or geographic region.
Apple says threat notifications should be taken seriously
Apple uses its own threat intelligence and security research to identify suspicious spyware activity. The company describes these messages as high-confidence warnings rather than ordinary security alerts.
“While our research does not allow us to achieve absolute certainty, Apple’s threat notifications are high-confidence warnings that you are personally the target of a mercenary spyware attack and should be taken very seriously,” Apple said.
“We cannot provide information about what causes us to issue a threat notification, as it may help mercenary spyware attackers adapt their behavior to evade detection in the future.”
When Apple detects this type of activity, it sends an email and iMessage notification to the email address and phone number associated with the user’s Apple Account.
Official Apple threat notification emails are typically sent from [email protected]. Apple also warns users about phishing messages designed to imitate legitimate threat alerts.
Apple will not ask you to click a link, open an attachment, install an app or configuration profile, or provide your Apple Account password or verification code. These are important signs that can help you determine whether a notification is genuine.
You can also verify threat notifications by signing in directly at account.apple.com. If Apple has issued an alert for your account, a notification will appear at the top of the page after you sign in.
If you believe your iPhone may be affected, Apple recommends enabling Lockdown Mode and contacting a qualified cybersecurity professional for assistance.
Receiving an Apple threat notification means the company believes you were individually targeted. Apple advises affected users to take the warning seriously and follow its security recommendations.
BleepingComputer contacted Apple for additional information about the latest threat notifications but had not received a response at the time of publication.
The overall prevention score can hide what happens after the initial access. If an attacker uses valid credentials, your defenses drop sharply.
Blue Report 2026 measures defense techniques by technology across 338 million simulations run in customer production environments.
Source: www.bleepingcomputer.com




