Published Product3 min read
Apple's spyware warnings now span 150-plus countries. That is a fleet problem, not a dissident problem
A new wave of threat notifications went to users in 110 countries, and Apple's own guidance makes clear that nobody outside Apple will ever be told why.
Not a builder's beat, but builders have a standing stake in it.See today for builders

What happened
- Apple confirmed to TechCrunch that it sent a new wave of notifications alerting an unspecified number of users in 110 countries that they may have been targeted by a mercenary spyware attack.
- According to TechCrunch, the latest round brings the total number of countries where Apple has alerted users to mercenary spyware attacks over the past few years to more than 150.
- The number of users notified in the latest wave was unspecified.
- A little more than one year earlier, Apple sent warnings to users in 100 countries that their iPhones had been targeted.
- The latest wave covers 10 more countries than the wave sent a little more than a year earlier.
Compiled by The Product DeskSomething wrong?How this is made
Why it matters
Apple has confirmed to TechCrunch that it sent a new round of notifications telling users in 110 countries they may have been targeted by a mercenary spyware attack [1], and TechCrunch puts the cumulative figure at more than 150 countries where Apple has issued such warnings over the past few years [2]. At that spread, targeted spyware stops being an exotic risk carried by a few named dissidents and becomes a device-fleet contingency for any organisation whose staff hold something worth stealing.
The trend line is modest but one-directional. A little more than a year ago Apple warned users in 100 countries that their iPhones had been targeted [4], so the latest wave covers ten more countries than that one [5]. Put differently, a single wave reached roughly 73 percent as many countries as Apple's entire multi-year total [6], which is an upper bound given the total is stated as "more than" 150 [2]. Apple did not say how many people were notified [3]. The company has previously confirmed one concrete cluster: more than a dozen Iranian cyberattack victims alerted in the lead-up to the war with Israel [7].
The operationally important detail is not the country count. It is in Apple's own support page, published the same day and titled "About Apple threat notifications and protecting against mercenary spyware" [8]. Apple recommends that notified users turn on Lockdown Mode and enlist expert help, pointing specifically to the rapid-response emergency assistance run by the nonprofit Access Now through its Digital Security Helpline, reachable 24 hours a day, seven days a week [9]. Then the line that should reshape any internal playbook: Apple states that outside organisations have no information about what caused it to send a threat notification, and can only offer tailored security advice [10].
Read that as a constraint on incident response. The alert arrives on an individual's device, not in your SIEM. Your security vendor, your MDM console, and your outside counsel will not be able to establish the vector, the operator, or the dwell time from the notification itself. Any runbook has to work with a single input, which is a user saying they got a warning, and it has to specify in advance who they tell, who authorises a device swap, which credentials get rotated, and whether Lockdown Mode is a supported configuration on managed hardware rather than something an employee toggles alone at midnight.
Apple's general advice, by contrast, is baseline hygiene aimed at everyone: keep devices updated, use a passcode or Touch ID or Face ID, enable two-factor authentication with a strong Apple Account password, turn on Stolen Device Protection, install apps from the App Store, use strong unique passwords and passkeys where available, and avoid links and attachments from unknown senders [11]. Apple pairs that with the caveat that most users will never be targeted by mercenary spyware [12]. Both things are true at once, and that is exactly the awkward part for operators: the population at risk is small, unevenly distributed, and now scattered across more than 150 countries [2], so the cost of having no plan is concentrated on whichever executive, researcher, or journalist on your payroll draws the notification.
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Apple confirmed to TechCrunch that it sent a new wave of notifications alerting an unspecified number of users in 110 countries that they may have been targeted by a mercenary spyware attack.
- [2]
According to TechCrunch, the latest round brings the total number of countries where Apple has alerted users to mercenary spyware attacks over the past few years to more than 150.
- [4]
A little more than one year earlier, Apple sent warnings to users in 100 countries that their iPhones had been targeted.
ReportedView cited source - [7]
Apple later confirmed that it had also alerted more than a dozen Iranian cyberattack victims in the lead-up to the war with Israel.
ReportedView cited source - [8]
Apple published a new support article the same day titled "About Apple threat notifications and protecting against mercenary spyware," explaining what threat notifications are, how they are delivered, and what to do if a user receives one.
Sources & coverage · 1 publisher
The reporting this story was synthesized from, earliest first. Every link goes to the original.
- 9to5mac.comMarcus MendesAug 13Apple sends fresh wave of mercenary spyware warnings worldwide
Additional citations
- Apple, confirmed to TechCrunch, as reported by 9to5Mac
- TechCrunch, via 9to5Mac
- Apple



