Published Product3 min read
Apple's spyware notices reach 110 countries, and Lockdown Mode becomes a baseline control
Apple told TechCrunch it warned selected users across 110 countries on Thursday. For any org with journalists, diplomats or executives on iOS, the hardened profile is no longer an edge case.
Not a builder's beat, but builders have a standing stake in it.See today for builders

What happened
- Apple said it sent mercenary spyware notifications to select customers on Thursday across 110 countries, sharing the latest details with TechCrunch.
- The attacks are not aimed at average users but at people with prominent roles in society, including journalists, activists, politicians and diplomats.
- If successful, the spyware can bypass built-in encryption to access private files, snoop on conversations, capture audio and video, track locations and control the device.
- Apple said in an updated support page: "Such attacks are vastly more sophisticated than regular cybercriminal activity, as mercenary spyware attackers apply exceptional resources to target a very small number of specific individuals and their devices" and "Mercenary spyware attacks cost millions of dollars and often have a short shelf life, making them much harder to detect and prevent."
- John Scott-Railton is a senior researcher at the security research center Citizen Lab, and described and displayed the notification.
Compiled by The Product DeskSomething wrong?How this is made
Why it matters
Apple sent a new round of what it calls mercenary spyware notifications on Thursday to selected customers across 110 countries, according to details the company shared with TechCrunch [1]. The notified population is journalists, activists, politicians and diplomats [2], which moves Lockdown Mode out of the curiosity bin and into the set of controls any organization employing those people needs a written answer for.
The capability being defended against is total. Apple says successful mercenary spyware bypasses built-in encryption to reach private files, listen in on conversations, capture audio and video, track location and control the device [3]. On its updated support page the company says these attacks "are vastly more sophisticated than regular cybercriminal activity, as mercenary spyware attackers apply exceptional resources to target a very small number of specific individuals and their devices," and that they "cost millions of dollars and often have a short shelf life, making them much harder to detect and prevent" [4]. The short shelf life is the line operators should read twice: if the exploit chain is disposable, detection is not a durable safeguard and configuration has to carry the load.
The alert itself is unambiguous. John Scott-Railton, a senior researcher at Citizen Lab, described and displayed the notice, which lands as an Apple Threat Notification reading: "Apple detected a mercenary spyware attack targeted at your iPhone. There are actions you can take now to help protect your data and device." [5][6]
This is a program, not an incident. Apple sent such notifications twice during 2024 [7], and says on its notifications page that it has issued them multiple times a year and has alerted people across more than 150 countries to date [8]. That makes this single wave's 110 countries no more than about 73 percent of the cumulative footprint [9], which is a useful way of saying the geography is not narrowing. NSO Group, the maker of Pegasus, has often been accused of fomenting such attacks and typically denies culpability, saying it sells only to intelligence and law enforcement agencies fighting terrorists and criminals [10]. Apple and other firms have sued NSO Group, and vendors have been forced to patch software vulnerabilities that Pegasus exploited [11].
The reason Lockdown Mode is treated as optional is that it costs something. It blocks most message attachments and link previews, restricts advanced web technologies, limits incoming FaceTime calls, disables SharePlay and Game Center, and stops certain Apple service invitations [12]. It also removes shared photo albums, excludes location data from shared images, requires devices to be unlocked before they connect to accessories or computers, blocks unsecure Wi-Fi networks, and prevents device management profiles from being installed [13]. That last item is the one IT should sequence around: a device already in Lockdown Mode cannot take a new management profile unless the mode is turned off first [14]. Enrolment before hardening, not after.
Turning it on is trivial by comparison. On iPhone or iPad the path is Settings, Privacy and Security, Lockdown Mode, then Turn On Lockdown Mode; on a Mac it is System Settings, Privacy and Security, Lockdown Mode [15].
What to watch: whether the cumulative country count moves past 150 at the next wave [8], whether your MDM enrolment runbook survives contact with the profile block [14][13], and whether the staff most likely to be targeted [2] know what the notification looks like [6] before one arrives. Rehearse the workflow now, because the window between notification and compromise is not where you want to be reading a settings menu for the first time.
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Apple said it sent mercenary spyware notifications to select customers on Thursday across 110 countries, sharing the latest details with TechCrunch.
- [2]
The attacks are not aimed at average users but at people with prominent roles in society, including journalists, activists, politicians and diplomats.
ReportedView cited source - [3]
If successful, the spyware can bypass built-in encryption to access private files, snoop on conversations, capture audio and video, track locations and control the device.
ReportedView cited source - [4]
Apple said in an updated support page: "Such attacks are vastly more sophisticated than regular cybercriminal activity, as mercenary spyware attackers apply exceptional resources to target a very small number of specific individuals and their devices" and "Mercenary spyware attacks cost millions of dollars and often have a short shelf life, making them much harder to detect and prevent."
- [5]
John Scott-Railton is a senior researcher at the security research center Citizen Lab, and described and displayed the notification.
- [6]
The notice appears on the device as an Apple Threat Notification reading: "Apple detected a mercenary spyware attack targeted at your iPhone. There are actions you can take now to help protect your data and device."
ReportedView cited source
Sources & coverage · 1 publisher
The reporting this story was synthesized from, earliest first. Every link goes to the original.
Additional citations
- Apple, via TechCrunch, reported by ZDNET
- Apple support page
- John Scott-Railton, Citizen Lab
- Apple notifications page



