All incidents

Apple issues mercenary spyware warnings to users worldwide

incidentopenAug 14, 2026 — Aug 15, 2026
Apple issues mercenary spyware warnings to users worldwide

APPLE has begun sending threat notifications to users in more than 110 countries warning of possible mercenary spyware attacks. The alerts target individuals such as journalists activists and executives who are believed to be at heightened risk. Apple’s threat notification programme which started in 2021 is designed to detect signs of sophisticated surveillance tools. Recipients are told that their device may have been compromised and that immediate action is advisable. The company stresses that the warnings are separate from ordinary malware alerts and require urgent attention Apple’s support page.

The notifications do not cite a specific CVE but describe the behaviour of mercenary spyware like that produced by NSO Group. Such spyware often relies on zero‑click vulnerabilities to install itself without any interaction from the victim. Apple’s detection mechanisms look for indicators of compromise associated with known exploit chains used in Pegasus‑style campaigns. These indicators include unusual process creation abnormal network connections and access to privileged data stores.

The warnings cover iPhone iPad and Mac devices running recent versions of iOS iPadOS and macOS. Once installed the spyware can harvest messages emails call logs microphone and camera data. It may also gather location information passwords and keystrokes before exfiltrating the material to attacker‑controlled servers. Because the malware operates with high privileges it can bypass many built‑in protections unless extra defences are enabled.

Apple first launched its threat notification programme in 2021 and has since issued alerts to users in over 150 countries. The current wave coincides with increased public reporting of mercenary spyware campaigns aimed at media personnel and human rights defenders. Researchers frequently link the toolset used in these attacks to NSO Group although Apple does not name any state sponsor SecurityOnline reported. The alerts are part of a broader effort to inform victims of targeted surveillance that differs from indiscriminate cybercrime.

When a threat is detected Apple shows a full‑screen alert on the device sends an email to the address on the Apple ID and displays a banner when signing into appleid​.apple​.com. The company advises recipients to treat the message as genuine and to verify its legitimacy by visiting the official account page directly. Users should not click any links contained in the alert itself because they could be spoofed SecurityAffairs noted. Instead they should open a browser manually and log in to check for any security notifications.

Upon receiving a warning users should update their device to the latest version of iOS iPadOS or macOS as soon as possible. They should then enable Lockdown Mode which is found under Settings Privacy & Security and provides an extra hardening layer. Turning on two‑factor authentication for the Apple ID adds another barrier against unauthorised access. Reviewing the list of installed applications for anything unfamiliar and removing suspicious apps is also recommended. If there is reason to believe the device is already compromised restoring from a clean backup or performing a factory reset may be necessary.

For those who handle sensitive information Apple suggests using a separate dedicated device for communications and restricting personal use of the primary phone. Seeking assistance from a qualified security professional or a national Computer Emergency Response Team can help investigate the incident. Regularly backing up data to an encrypted store and monitoring account login activity can aid in detecting any further misuse. Staying current with security updates and maintaining strong unique passwords remain fundamental defences against mercenary spyware threats.

Intelligence briefing updated Aug 15, 2026

NSO Group
Root sourcesupport.apple.com
Timeline Coverage

Swipe to explore timeline