Apple's spyware warnings reached users in 110 countries, informing them that they may have been targeted by commercial surveillance software. The company did not name the perpetrators or a specific program, but it described the alerts as high-certainty.
The new notification campaign was confirmed by Apple to TechCrunch and is aimed at people who may have been targeted because of their identity or activity. Apple's spyware warnings are not a general update to all iPhone owners, but a personalized warning to a limited number of users.
See also: iOS 26.6: The critical update that fixes 87 vulnerabilities

What Apple's spyware warnings mean
According to Apple's official support page, mercenary spyware is used in highly targeted attacks with significant financial and technical resources. Journalists, activists, politicians, and diplomats have been repeatedly targeted, while the majority of users are not at risk from such operations.
Apple says it has notified users in more than 150 countries since 2021, without attributing the attacks to any specific country or group. The current deployment to 110 countries is part of that ongoing process. Apple's spyware warnings are based on internal threat intelligence and research, but the company clarifies that no technical investigation can provide absolute certainty.

The alert can appear on the lock screen, in the user's account, and via email or iMessage. Apple emphasizes that it never asks the recipient to open a link, install an app or profile, or reveal an Apple Account password. Authenticity can only be verified by logging in to account.apple.com, where the genuine alert appears at the top of the page.
The format of the alert matters because attackers can mimic the appearance of a corporate update. Apple emphasizes that it does not disclose the technical criteria that trigger an alert, so as not to help spyware operators adapt their methods. For the same reason, the message does not include the identity of the perpetrator, the country of origin, or details of the possible intrusion.
See also: How to do a privacy check on a smartphone
What should recipients do?
The first step is to enable Lockdown Mode, which restricts certain features on your iPhone, iPad, and Mac to reduce the attack surface. The setting can affect features like message attachments, certain invitations, and browsing, so it's intended for users at increased risk.
Apple also recommends contacting experts immediately. Access Now's Digital Security Helpline provides emergency support 24 hours a day, seven days a week. Recipients should not delete data or reset the device before receiving instructions, as this could result in the loss of valuable evidence for technical review.

Additionally, you need to install the latest updates, have a strong device passcode, and enable two-factor authentication on your Apple Account. Apple also recommends using unique passwords, passcodes where supported, enabling Stolen Device Protection, and installing apps only from the App Store.
How to avoid fake alerts
The publicity surrounding Apple's spyware warnings can also be exploited by scammers. A message asking for passwords, payment, phone calls, or tool installation should not be considered genuine, even if it uses the Apple logo and language. Checking through the official account is the safest criterion.
See also: Phineas Fisher: The hacktivist behind leaks and spyware

For those who did not receive a notification, the basic measures remain useful: updated devices, strong passwords, two-factor authentication, and caution against links or files from unknown senders. Enabling Lockdown Mode may be considered when there are specific indications of targeting, even without a message from Apple.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
The development mainly concerns individuals with a high public or professional profile and should not be confused with the usual scams that are circulated en masse. Nevertheless, the verification process is useful for everyone, because scammers often take advantage of current events to send fake messages. The cool-headed cross-check through the official page protects both credentials and personal data. Users should avoid hasty actions and seek help from trusted experts before changing their device.
The new warning in 110 countries shows that commercial spyware is still being used selectively and internationally. The main conclusion for each recipient is clear: confirmation only from the Apple Account, immediate technical assistance and no sharing of passwords with third parties.
