Skip to content

Invest1 publisher3 min readPublished

Apple moved its spyware warnings to the Lock Screen. Your incident alerts are still in email.

Thursday's round of Apple threat notifications reached targets in 110 countries, and the delivery change is the lesson: an alert sent to an inbox is one you have to hope someone opens.

The Investor · Invest desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

Photograph accompanying Apple moved its spyware warnings to the Lock Screen. Your incident alerts are still in email.
Photo: cryptopolitan.com

What happened

  • Apple now places its mercenary spyware warnings, labelled "Apple Threat Notification", on the iPhone Lock Screen and inside Settings.
  • Thursday's round of Apple threat notifications reached targets in 110 countries.
  • Apple says it has notified people in more than 150 countries since the threat notification programme began in 2021.
  • Until this change, Apple used email and a banner shown after a user signed into an Apple Account to alert users to these threats.
  • The Lock Screen and Settings alert works in addition to the older email and Apple Account page alerts.

Compiled by The InvestorSomething wrong?How this is made

Why it matters

Apple now puts its mercenary spyware warnings on the iPhone Lock Screen and inside Settings [1], and Thursday's round of those notifications reached targets in 110 countries [2]. The technical detection did not change; the delivery path did, which is the part worth copying.

Until this change Apple relied on email plus a banner shown after a user signed into an Apple Account [4]. Both still run, with the on-device alert layered on top [5]. Apple says it reworked the experience so recipients can reach guidance on what to do next more quickly [7]. Pieter Arntz, the researcher quoted in coverage of the change, put the reasoning plainly: the on-device alert "is meant to make a high-risk warning harder to overlook and complements notifications by email and through the user's Apple Account page" [8]. That is a concession about channel reliability, not about detection quality.

The stakes justify the redundancy. Apple describes these as high-confidence alerts that a user has been individually targeted by a mercenary spyware attack, and says they should be taken very seriously [9]. The Lock Screen text tells the user Apple "detected a mercenary spyware attack targeted at your iPhone. There are actions you can take now to help protect your data and device" [6]. Apple's support documentation ties the attacks to state actors and the private firms that build surveillance tools for them, citing Pegasus from Israel's NSO Group as one example [11]. The usual recipients are journalists, activists, politicians and diplomats [12]. Apple characterises the campaigns as costing millions of dollars, burning fast once discovered, and aimed at a very small number of people [10]. The company will not say what triggers any specific alert, because that would help attackers evade it, and says it uses only its own threat intelligence [13].

Scale gives some sense of the routing problem. Apple says it has notified people in more than 150 countries since the programme began in 2021 [3], so a single Thursday touched no more than roughly three quarters of the countries the programme has ever reached [1].

For anyone running an incident-notification path, there are four design choices here worth stealing. First, the alert lands in a surface the recipient cannot avoid, not one they have to remember to check [1][4]. Second, it comes with one specific action rather than a menu: Apple's advice is to turn on Lockdown Mode, which strips out features attackers can exploit, and the company says it has not yet seen a Lockdown Mode device successfully hacked [14][15]. Third, there is a named human escalation, the Access Now Digital Security Helpline, available 24/7 [16]. Fourth, the notification is built to survive being impersonated: Apple tells recipients to confirm any alert by signing in at account.apple.com, where a genuine notification appears at the top of the page [17], and says its real notifications never ask anyone to click a link, install anything, or hand over a password or verification code [18].

That last point is the one most internal alerting systems fail. A credible urgent warning is useful bait, and any channel you add is also a channel an attacker can imitate.

Worth watching: whether Apple keeps publishing per-round country counts, since 110 in one Thursday against 150-plus since 2021 is the only public measure of tempo [2][3]; whether phishing kits start mimicking the new Lock Screen format; and whether the unbroken Lockdown Mode record [15] holds as the alert reaches more people who then enable it.

Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories