Apple has issued threat notifications to iPhone users in over 150 countries [3] [9], warning them of potential mercenary spyware attacks targeting individuals based on their identity or activities [2].


These alerts, delivered via email, iMessage, and the Apple ID sign-in page, are sent within two days of detection and do not disclose the attackers' identities or specific countries affected. Since 2021, Apple has been actively detecting and notifying users of such attacks, with victims in India and 91 other countries being notified. Last October, warnings were issued to journalists and politicians in India, where the NSO Group's Pegasus spyware was found on iPhones. Amnesty International confirmed the use of the NSO Group's Pegasus spyware in these attacks. Indian authorities denied involvement but reportedly pressured Apple to provide alternative explanations to mitigate political backlash. These attacks are described as "mercenary spyware attacks" and are considered highly sophisticated and rare, often state-sponsored and aiming to remotely compromise the device. Apple urges affected users to take the threat notifications seriously and seek expert help from organizations like the Digital Security Helpline for emergency security assistance. The attacks, known as mercenary spyware attacks, aim to remotely compromise iPhones and are typically carried out by nation states against specific individuals such as journalists, activists, politicians, and diplomats. The attacks are advanced and complex, using zero-day exploits and self-destruct mechanisms to evade detection. The NSO Group's Pegasus spyware is a well-known tool used in such attacks, though the company claims it is only sold to intelligence and law enforcement agencies. Apple has sued the NSO Group for its role in state-sponsored attacks and has released bug fixes to address vulnerabilities exploited by Pegasus. If Apple determines that you are a potential victim of a mercenary spyware attack, you will receive an email, text message, and a threat notification on your Apple ID page. To protect against such attacks, Apple recommends using a passcode, enabling two-factor authentication, updating to the latest OS version, installing apps only from the App Store, using strong passwords, and avoiding clicking on links or attachments from unknown senders. Additionally, turning on Lockdown Mode can help prevent spyware from stealing sensitive data, and seeking assistance from security experts such as the Digital Security Helpline at Access Now is advised in the event of an attack. Users are advised to seek tailored security advice from third-party experts. Apple has previously warned of state-sponsored spyware attacks, but the latest notifications do not mention state sponsorship. Individually targeted attacks of high cost and complexity are typically associated with state actors or private companies developing spyware on their behalf.


