Product2 distinct publishers3 min readPublished Updated
Access Now says helpline requests ran 30% to 40% above the usual post-notification surge, a record. Among the recipients: a Ukrainian soldier who assumed the alert was a scam.
The Product Desk · Product desk

Compiled by The Product DeskSomething wrong?How this is made
Apple sent a fresh wave of mercenary-spyware threat notifications on Friday to customers in 110 countries [1], and over the weekend Access Now's helpline logged a record number of people asking for help, roughly 30% to 40% more than its investigators normally receive after a notification batch, according to team director Mohammed Al-Maskati [2][3]. The volume matters more than the individual cases: a notification stream this wide stops being a specialist concern for a few reporters and becomes an incident type that any organisation with travelling, exposed or politically salient staff will eventually have to triage.
The scale is worth sizing properly. Apple says that over the last few years it has alerted people in more than 150 countries in total [4]. A single Friday covering 110 of them means one batch spanned no more than about three-quarters of the country count Apple has ever reached, cumulatively [1]. Access Now, one of the digital rights groups Apple points victims toward, says this appears to be the largest batch yet [5]. John Scott-Railton of The Citizen Lab, which has investigated government spyware for more than 15 years, called the scale and geographic diversity of public posts unprecedented and said that for every public notification there is "a huge notification iceberg that the public will never learn about" [6][7].
Part of the jump is plumbing rather than pure targeting growth. Both Al-Maskati and Scott-Railton said the volume of people receiving alerts could also be attributed to Apple's new delivery methods [8]: since this year, Apple notifies users on the iPhone lock screen, in the Settings app, by email to the address on the Apple Account, and on web login to that account [9]. Al-Maskati said the new method has made the issue harder for users to ignore [10]. For operators, that is the awkward part. The alert lands on a personal lock screen and a personal mailbox, not in a security console, so whether it reaches your incident queue at all depends on an employee deciding to tell you.
They may not. A Ukraine Armed Forces soldier who received the notification told TechCrunch he initially thought it was a scam until he verified it with Apple [11], and said: "I wouldn't have thought I was important enough for them to target me like this" [12]. He said other people in Ukraine's military received the same notification and "were a bit worried" [13]. CERT-UA did not respond to TechCrunch's request for comment on whether it was aware of other Ukrainian recipients [14]. Apple also did not respond to a request for comment [15]. Self-assessed importance is clearly not a usable filter, which argues for pre-positioning rather than triage: Apple has said it is not aware of anyone with Lockdown Mode enabled being hacked [16], and TechCrunch notes that recipients who are not journalists, dissidents or human rights defenders have other organisations that can help investigate [17].
Watch whether Access Now's request volume stays elevated after this batch clears, because a helpline running 30% to 40% above normal is a capacity question as much as a threat signal [3]. Watch the country count on the next wave against the 110 in this one [1], and watch whether any national CERT publicly confirms clusters of recipients, which CERT-UA has not done here [14].
Ranked by verification strength, evidence, and original report placement.
The latest batch appears to have been the largest yet, according to one of the digital rights groups that Apple suggests victims of spyware reach out to for help.
John Scott-Railton is a senior researcher at The Citizen Lab, a digital rights group that has investigated government spyware attacks for more than 15 years, and said the reports show spyware attacks may be more prevalent than people realize.
Scott-Railton said: "The scale and geographic diversity of public posts about receiving notifications are pretty unprecedented" and "For every public notification like this, you can imagine there's a huge notification iceberg that the public will never learn about. This is a clear indication that something bigger is going on."
Apple sent out a new wave of threat notifications on Friday alerting customers in 110 countries that they had been targeted with powerful spyware.
Mohammed Al-Maskati, director of the Access Now team of investigators who review and investigate reports to its helpline, told TechCrunch that since Friday they have received a record high number of people reaching out for help, including people who had already received threat notifications in the past.
Al-Maskati said the number is around 30% to 40% more than the nonprofit's investigators usually receive after Apple sends out new notifications.
Follow any of these and your For You feed starts watching them — no settings page required.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Named responders on record, but one publisher and no hard counts
Two named, domain-credible sources (Access Now's helpline investigation lead and a Citizen Lab senior researcher) plus a first-person recipient account give the core facts real weight, and Apple's own country figures are cited. Against that: the cluster has a single publisher, every volume figure is relative rather than absolute, Apple declined comment on the wave, CERT-UA did not respond, and part of the observation base is public social media posts.
Real-world wave and responder load, scope only partly quantified
This is not a proposal or preview: notifications actually went out across 110 countries, a responder organization is absorbing measurable extra caseload, individual recipients including serving military personnel have surfaced, and Apple's new four-channel delivery is already live. What keeps the score mid-range is the absence of absolute recipient or request counts and of any organizational or fleet-level response data.
Superlatives outrun the measurements
The framing words carrying the story - 'unprecedented', 'largest yet', 'something bigger is going on' - rest on relative helpline load, public posts, and expert impression, while the same experts concede the volume could partly be an artifact of Apple's new multi-channel alerting. With Apple silent and no absolute numbers, the claim of an escalating spyware wave is somewhat overstated relative to what is actually measured, though the underlying event itself is real and materially large.
Mission-aligned responders speaking, vendor silent
The two characterizing voices are advocacy and research organizations whose funding and mandate depend on demonstrating that mercenary spyware is widespread - a real directional incentive, offset by long track records and on-record attribution. Apple's incentives cut the other way: it declined to comment while the article restates its Lockdown Mode safety claim, a marketing-relevant assertion left unverified. The reporting outlet also solicits tips on this beat.
Core event solid, magnitude and cause uncertain
Confidence is moderate: that a very broad notification wave occurred and produced record responder demand is well attributed, but the cluster is single-publisher, the magnitude claims are relative, the causal explanation is contested by the sources themselves, and neither Apple nor CERT-UA is on the record.
security
Apple's spyware alerts reached 110 countries, and they land on people, not fleets4 distinct publishers
security
Pegasus reached a Serbian student's iPhone through a hole Apple closed eight months earlier1 distinct publisher
security
Moscow's crews stopped stealing passwords. Now they ask victims to approve the login.2 distinct publishers
product
Eddy Cue's services division reclaims the App Store after 11 years under marketing1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
gizmodo.com
1 article · August 18, 2026
techcrunch.com
1 article · August 17, 2026