Apple sends new ‘Threat Notification’ alerts over mercenary spyware attacks

Apple’s Threat Notification System Sounds Alarm on Mercenary Spyware Attacks

In a bid to safeguard its users from highly targeted and sophisticated cyber threats, Apple has sent out new “Threat Notification” alerts in multiple countries. The alerts, which have been popping up on iPhones worldwide, warn users that they may be the target of a mercenary spyware attack. While these notifications are not uncommon, they do serve as a stark reminder that certain individuals and organizations are being actively targeted by malicious actors.

The threat in question is mercenary spyware, a type of cyber espionage tool used by governments or private entities to compromise sensitive information from high-profile targets such as journalists, activists, politicians, and diplomats. These attacks are often expensive, highly sophisticated, and typically aimed at a very small number of people, making them difficult to detect and prevent.

According to Apple’s own statements, the company relies on its threat intelligence and investigations to identify suspected mercenary spyware activity. When it detects such activity, it sends an email and iMessage notification to the user’s associated email addresses and phone numbers. The notifications are considered high-confidence alerts, meaning that Apple has a strong reason to believe that the user is being targeted.

While Apple does not attribute individual alerts to a specific government, company, or geographical region, it does note that these attacks are often linked to NSO Group’s Pegasus spyware. However, it’s worth noting that Apple does not provide explicit evidence of which spyware is behind each alert, leaving users to wonder whether they might be the target of a specific attack.

It’s essential for users to take these alerts seriously, as receiving one means that Apple has high confidence that the user was individually targeted. To verify whether a threat notification is genuine, users can check if it comes from an email address ending in `threat-notifications@email.apple.com` and avoid clicking on any suspicious links or providing sensitive information.

If you believe you’ve been affected by such an attack, Apple recommends enabling Lockdown Mode and reaching out to a cybersecurity expert. While the vast majority of users will never be targeted by these attacks, it’s crucial for all iPhone owners to remain vigilant and take proactive measures to protect themselves from these sophisticated threats.

As we navigate an increasingly complex digital landscape, it’s essential to stay informed about emerging threats and take steps to safeguard our personal and professional lives. By staying ahead of the curve and being aware of potential risks, we can better protect ourselves against mercenary spyware attacks and other cyber threats that may arise in the future.


Source: Bleeping Computer — 2026-08-14