CUPERTINO, California, August 17, 2026, 14:06 PDT
- Apple sent mercenary-spyware alerts to targeted users in 110 countries.
- Access Now says help requests ran 30%–40% above a typical alert wave.
- A warning signals high-confidence targeting, not confirmed device compromise.
Apple (NASDAQ:AAPL) sent mercenary-spyware warnings to targeted users in 110 countries. Access Now said requests for help rose 30%–40% above its normal volume after an Apple alert wave. The nonprofit described the influx as a record.
The country count shows reach, not the number of people targeted. Apple has not disclosed a recipient total. It also has not named the attackers or spyware used.
The latest wave arrives with a stronger warning system. Alerts now appear on an iPhone’s Lock Screen and in Settings. Apple also sends email and displays a banner at account.apple.com.
| Alert wave | Countries reported | Delivery context | Disclosed recipient count |
|---|---|---|---|
| April 2024 | 92 | Email and account notifications | Not disclosed |
| December 2025 | 84 | Periodic global threat notification | Not disclosed |
| August 2026 | 110 | Lock Screen, Settings, email and Apple Account | Not disclosed |
Apple has notified people in more than 150 countries since 2021. Earlier waves reached 92 countries in April 2024 and 84 in December 2025. The new 110-country batch is broader than either comparison.
Apple calls each notice a high-confidence alert of individual targeting. It does not prove that the device was successfully compromised. That distinction requires forensic analysis.
| What the signal says | What it does not establish | Best next evidence |
|---|---|---|
| Apple detected activity consistent with targeted mercenary spyware | That an infection succeeded | Device forensic analysis |
| The user was individually selected | Who selected the target | Technical and contextual investigation |
| The warning is high confidence | Which spyware product was used | Expert examination and indicators |
| Urgent action is warranted | That every Apple user faces the same risk | Targeted risk assessment |
John Scott-Railton of Citizen Lab called the scale and geographic diversity “pretty unprecedented.” Mohammed Al-Maskati of Access Now said the new format made alerts harder to ignore. Both cautioned that visibility may partly explain the surge. Investigator comments
Recipients should verify the message directly at account.apple.com. A genuine Apple threat notice never asks users to open a file, install a profile or disclose a password. The company also tells users to avoid unknown links and attachments.
| Channel or request | Consistent with Apple’s current process? | Verification step |
|---|---|---|
| Lock Screen alert | Yes | Check Settings and account.apple.com |
| Settings alert | Yes | Check account.apple.com |
| Email from [email protected] | Yes | Type account.apple.com independently |
| Request for Apple Account password or code | No | Do not respond |
| Request to install an app or profile | No | Do not install it |
| Unexpected attachment or sign-in link | No | Do not open it |
Apple recommends Lockdown Mode for people who receive an alert. The optional setting narrows several attack surfaces. It also limits normal device functions, so the trade-off is deliberate.
| Area | Lockdown Mode protection | User trade-off |
|---|---|---|
| Messages | Blocks most attachment types except images | Some attachments and link previews are unavailable |
| Web browsing | Disables selected complex web technologies, including JIT compilation | Some sites may work differently |
| Apple services | Blocks invitations from people not previously contacted | Unexpected FaceTime calls and requests may not arrive |
| Wired access | Blocks computer and accessory connections while locked | The device must be unlocked for a connection |
| Configuration | Prevents new profiles and MDM enrollment | New management profiles cannot be installed |
Lockdown Mode is available on iPhone, iPad and Mac. It must be enabled separately on each device. Apple says most people will never need it.
Access Now advises recipients to update the operating system and seek expert help. It says users should not erase an affected device. A backup can preserve evidence needed for investigation.
Risks: The 30%–40% increase measures helpline contacts, not confirmed infections. Apple’s new delivery channels may have raised reporting. The company has disclosed neither the victim count nor an attacker.
The practical rule is simple. Verify the alert outside the message, harden the device and preserve evidence. Then get qualified help.