Back Firstpost Apple warns users in 110 countries over suspected spyware attacks: Report
Apple has issued another round of threat notifications to customers it believes may have been targeted by sophisticated spyware. The latest alerts cover users across 110 countries and come with updated guidance on securing affected devices, including Apple’s Lockdown Mode.
Apple has issued a fresh wave of security alerts to customers it believes may have been targeted by sophisticated spyware, warning that their iPhones, iPads or Macs could be at risk.
The latest notifications were sent on Thursday to users in 110 countries, Apple told TechCrunch. The company has now alerted customers in more than 150 countries since it began notifying people suspected mercenary spyware attacks.
Unlike conventional malware campaigns, mercenary spyware is typically associated with highly sophisticated surveillance operations and can be deployed against a small number of specific targets. Governments have been among the known users of such tools, although the technology has also drawn scrutiny over its use against journalists, activists and other members of civil society.
Apple has also changed how it delivers the warnings. The company says recipients can now receive a prominent alert directly on the lock screen of their iPhone. The notification points users towards information explaining what the warning means and the steps they can take to protect their devices and personal information.
The company said the updated experience is designed to make it easier for people who receive an alert to understand what they should do . Apple also sends the warning by email and displays it when affected users sign in to their Apple accounts.
Receiving an alert does not necessarily establish that an attacker successfully broke into a device. Instead, it means Apple has detected activity that has led it to believe the user may have been specifically targeted.
The warning tells recipients that Apple has detected a mercenary spyware attack aimed at their iPhone and directs them towards protective measures.
Apple recommends enabling Lockdown Mode, a security setting designed to reduce the number of ways highly targeted attacks can compromise an Apple device. The company says it has not seen a confirmed case of a device being successfully compromised while Lockdown Mode was active.
Users who receive an alert are also directed towards organisations and experts who can help assess the situation and secure their devices. That guidance is particularly important because spyware attacks can involve sophisticated techniques that are difficult for individuals to investigate themselves.
Citizen Lab researcher John Scott-Railton, who first drew attention to the latest notifications in a post on X, described the changes as a significant improvement over Apple's earlier warning system.
He said the alerts can also help uncover broader surveillance campaigns because people who receive them may seek assistance, potentially leading researchers to identify additional victims.
Apple introduced its threat notifications in 2021 as governments and private surveillance firms faced growing scrutiny over the use of powerful spyware.
Scott-Railton pointed to Poland as an example of how such alerts can help bring surveillance operations to light. The country has faced a major controversy over the alleged use of spyware by its former government against political opponents and others.
According to Scott-Railton, Apple's warnings can provide an important starting point for investigations by connecting affected individuals with researchers and organisations that can examine their devices.
The scale of Apple's latest notification campaign also illustrates the geographic reach of targeted spyware. While such attacks remain relatively uncommon compared with ordinary cyber threats, the spread of commercial surveillance tools has raised concerns their potential misuse.
For users who receive Apple's warning, the company recommends treating it as a serious security signal rather than proof that a device has already been compromised. Enabling stronger protections and seeking specialist assistance can help determine what happened and reduce the risk of further intrusion.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
