CyberIntel ⬡ News
★ Saved ◆ Cyber Reads
← Back ◇ Industry News & Leadership Aug 14, 2026

Apple sends new ‘Threat Notification’ alerts over mercenary spyware attacks

Bleeping Computer Archived Aug 14, 2026 ✓ Full text saved

You're not alone if you just received an "Apple Threat Notification" saying it detected a "mercenary spyware attack targeted at your iPhone." [...]

Full text archived locally
✦ AI Summary · Claude Sonnet


    Apple sends new ‘Threat Notification’ alerts over mercenary spyware attacks By Mayank Parmar August 13, 2026 09:19 PM 0 You're not alone if you just received an "Apple Threat Notification" saying it detected a "mercenary spyware attack targeted at your iPhone." Some users on Reddit are reporting that they received these alerts today after Apple sent out a new batch of threat notifications on August 13, but the feature itself is not new. Apple sent a new batch of alerts to users on August 13 Source: Reddit Apple has been sending these threat notifications multiple times a year since 2021, when it detects highly targeted mercenary spyware attacks. It's also worth pointing out that Apple does not identify the spyware behind individual alerts, so there's no evidence that today's notifications are specifically related to Pegasus. However, Apple itself cites NSO Group's Pegasus as an example of mercenary spyware historically associated with this type of attack, and forensic investigations into previous Apple threat notifications have confirmed Pegasus infections in some cases. In a support document, Apple previously confirmed it sends threat notifications to users in more than 150 countries after detecting highly targeted mercenary spyware attacks against specific iPhone users. The list of potential targets includes journalists, activists, politicians, and diplomats, who have historically been among those targeted by this type of spyware. These attacks are expensive, highly sophisticated, and typically aimed at a very small number of people. "Mercenary spyware attacks cost millions of dollars and often have a short shelf life, making them much harder to detect and prevent," Apple explained. "The vast majority of users will never be targeted by such attacks." The company does not attribute individual alerts to a specific government, company, or geographical region. Apple says threat notifications should be taken seriously Apple relies on its own threat intelligence and investigations to identify suspected mercenary spyware activity, which means these notifications are "high-confidence alerts" and not just a regular warning. "Although our investigations can never achieve absolute certainty, Apple threat notifications are high-confidence alerts that a user has been individually targeted by a mercenary spyware attack, and should be taken very seriously," Apple noted. "We are unable to provide information about what causes us to issue threat notifications, as that may help mercenary spyware attackers adapt their behavior to evade detection in the future." If Apple detects this activity, it sends an email and iMessage notification to the email addresses and phone numbers associated with the user's Apple Account.  The emails are usually from threat-notifications@email.apple.com, and Apple also warns users about fake versions of these alerts. You can verify whether a threat notification is genuine because Apple will not ask you to click a link, open a file, install an app or profile, or provide an Apple Account password or verification code. You can also check the alert by signing in directly to account.apple.com. If Apple sent you a threat notification, it will appear at the top of the page after you're logged in. If you believe you've been affected, you should enable Lockdown Mode and reach out to a cybersecurity expert. Apple recommends taking these alerts seriously because receiving one means it has high confidence that the user was individually targeted. BleepingComputer has contacted Apple for a statement on the Threat Notifications, but we have not received a response at the time of publication. Once attackers have valid credentials, only 37% of their actions are blocked Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report Related Articles: Tata Electronics confirms cyberattack as hackers leak data White House taps security firms for offensive hack-back operations Who Vets AI’s Code? The Scale Challenge Facing Open Source Ingestion The Threat Hiding in Your Hiring Process: How Fake Remote Workers Get In Vague Task, Total Access: When AI Delegation Becomes a Security Risk
    💬 Team Notes
    Article Info
    Source
    Bleeping Computer
    Category
    ◇ Industry News & Leadership
    Published
    Aug 14, 2026
    Archived
    Aug 14, 2026
    Full Text
    ✓ Saved locally
    Open Original ↗