Published Product3 min read
Apple's spyware alerts reached 110 countries in one batch. Your playbook should name a person.
Apple says it has now warned targets in more than 150 countries. The alert lands on an employee's lock screen, not in your monitoring stack, which makes the response path a design decision.
Not a builder's beat, but builders have a standing stake in it.See today for builders

What happened
- Apple told TechCrunch it sent a new batch of spyware threat notifications on Thursday to users targeted in 110 countries.
- Apple says that to date it has notified customers in over 150 countries about suspected spyware targeting.
- In a new support article, Apple says it will notify users directly on their iPhone lock screen with a push notification that urges the person to take action.
- The threat notification reads: "Apple detected a mercenary spyware attack targeted at your iPhone. There are actions you can take now to protect your data and device."
- Apple also sends the notifications by email and to users when they log in to their account.
Compiled by The Product DeskSomething wrong?How this is made
Why it matters
Apple sent a new batch of mercenary spyware threat notifications on Thursday to users in 110 countries, and told TechCrunch it has now notified customers in more than 150 countries since the program started in 2021 [1][2][14]. That volume moves these alerts out of the exotic category and into the category of operational signals a security team with a fleet of Apple devices should expect to encounter, and the signal arrives in a channel almost no employer monitors.
Start with the mechanics, because they determine the response path. Apple says it delivers the alert as a push notification on the iPhone lock screen urging the person to act, and also sends it by email and to users when they log in to their account [3][5]. The text reads: "Apple detected a mercenary spyware attack targeted at your iPhone. There are actions you can take now to protect your data and device." [4] Apple told TechCrunch it has updated the experience so recipients can more easily reach information on what to do next, and the notification opens advice on who to contact for help [6][7]. None of those three channels involves the employer. The first person to know, and possibly the only one, is the employee holding the phone.
The concentration is worth sitting with: at least 110 of the more than 150 countries Apple has ever notified were covered in this one round, roughly three quarters of the cumulative geography [8]. TechCrunch notes a notification does not necessarily mean the device was successfully compromised, but it still warrants immediate steps [9]. Such attacks remain generally rare, though the technology has spread and been used by governments against critics, including members of civil society [10][11].
Apple's stated mitigation is Lockdown Mode, which the notification advises switching on, and which Apple describes as making attacks far harder to succeed [7][12]. Apple also says it has yet to see a case where a device was hacked while Lockdown Mode was enabled [13]. That is the vendor's own claim about its own feature, and it is the only quantified defensive statement on offer here, so treat it accordingly: decide in advance which roles get Lockdown Mode turned on, who authorises it, and what breaks when it is.
The reason a shrug is the wrong reaction is that one alert is rarely about one phone. Citizen Lab senior researcher John Scott-Railton, who first flagged the latest batch in a thread on X, told TechCrunch that "notifications create a critical signal that a community is being targeted. People get an alert, and then some of them reach out and seek help. Often this kicks off an investigation that reveals many, many more cases." [15][16] He called the new push notifications a big improvement in getting people to seek help since Apple's alerts debuted in 2021 [17]. He also said that without Apple's notifications, the scandal over the former Polish government's use of spyware against its rivals in the election would not have been uncovered [18]. If one employee in a region or function gets an alert, the useful next question is who else in that cohort did.
Three things to watch. Whether Apple publishes anything about batch cadence, so teams can distinguish a broad sweep from a targeted one. Whether the updated notification design measurably increases the number of recipients who seek help, which is the mechanism Scott-Railton credits for uncovering wider cases [16]. And whether any organisation says publicly what it did after an employee received one, because right now the documented playbooks are individual, not institutional.
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Apple told TechCrunch it sent a new batch of spyware threat notifications on Thursday to users targeted in 110 countries.
- [2]
Apple says that to date it has notified customers in over 150 countries about suspected spyware targeting.
- [3]
In a new support article, Apple says it will notify users directly on their iPhone lock screen with a push notification that urges the person to take action.
- [4]
The threat notification reads: "Apple detected a mercenary spyware attack targeted at your iPhone. There are actions you can take now to protect your data and device."
ReportedView cited source - [5]
Apple also sends the notifications by email and to users when they log in to their account.
ReportedView cited source - [6]
Apple told TechCrunch it has updated the user experience, making it easier for recipients to access important information on what to do next.
Sources & coverage · 1 publisher
The reporting this story was synthesized from, earliest first. Every link goes to the original.
- techcrunch.comZack WhittakerAug 13If Apple sends you a push notification alerting you to a spyware attack, take it seriously
Additional citations
- Apple, via TechCrunch
- Apple support article, via TechCrunch
- TechCrunch
- Apple
- John Scott-Railton, Citizen Lab, via TechCrunch



