Apple has issued a fresh wave of mercenary spyware notifications to targeted iPhone users across 110 countries, according to security researcher Ravie Lakshmanan writing for The Hacker News.
Understanding Mercenary Spyware Attacks
Mercenary spyware attacks represent some of the most advanced digital threats in existence today, according to statements shared by Apple with TechCrunch. These operations involve extreme costs, high technical sophistication, and a worldwide scope. Because of the vast resources required to develop exploits that deliver a surveillance payload, attackers typically focus on a very small number of individuals.

Apple describes these alerts as high-confidence notifications that a user has been individually singled out. However, the company does not attribute attacks to specific regions or threat actors. Past disclosures point to commercial surveillance tools like the Pegasus spyware developed by the NSO Group, though the current notifications do not name a specific company or tool.
How Apple Delivers Threat Notifications
Users who are targeted receive alerts through multiple official channels to prevent confusion and phishing attempts. According to The Hacker News, Apple dispatches these warnings in three specific ways:

- An Apple Threat Notification appears directly on the user’s iPhone screen, both on the Lock Screen and within device Settings.
- An email alert is sent to the addresses associated with the user’s Apple Account, originating specifically from the address
threat-notifications@email.apple.com. - A prominent threat notification banner appears at the top of the user’s account page upon signing in at account.apple.com.
Apple stresses that legitimate notifications will never ask a recipient to click a link, open a file, install an application or configuration profile, or provide their Apple Account password, according to Notebookcheck reporting.
Recommended Security Steps for Targeted Users
Because Apple keeps its detection methodologies secret to prevent attackers from adapting their tactics, users cannot verify infection status through traditional diagnostic tools. Instead, the company and digital safety organizations recommend immediate defensive measures.
Users who receive an alert are strongly encouraged to enable Lockdown Mode, a specialized setting that restricts specific device features and communication vectors to drastically limit potential attack surfaces. Additionally, affected individuals can access free, round-the-clock digital security assistance through the Digital Security Helpline run by the nonprofit organization Access Now, as noted by Notebookcheck.
Broader account and device hygiene measures recommended by security researchers include updating iOS to the latest software version, enforcing device passcodes with biometric authentication like Face ID or Touch ID, enabling two-factor authentication for Apple Accounts, turning on Stolen Device Protection, and installing apps strictly from trusted sources.