Apple has sent a new round of Apple Threat Notifications to users it believes may have been individually targeted by mercenary spyware. The alerts are high-confidence warnings aimed at a small number of people, including journalists, activists, politicians and diplomats.
Apple issues new spyware alerts
Users reported receiving Apple Threat Notifications on 13 August. Apple has issued these warnings several times a year since 2021 when its investigations identify signs of highly targeted mercenary spyware activity.
The company does not name the spyware involved in individual cases. As a result, the latest alerts should not automatically be linked to Pegasus or another specific surveillance tool.
However, Apple has previously used NSO Group’s Pegasus as an example of mercenary spyware. Previous forensic investigations have also confirmed Pegasus infections in some cases involving Apple’s threat alerts.
Apple says it sends these notifications to users in more than 150 countries when it detects suspected attacks against a specific individual.
Mercenary spyware attacks target a small number of people
Mercenary spyware is expensive, sophisticated and usually deployed against carefully selected targets. These attacks often focus on people whose work or position may make them valuable targets for surveillance.
Potential targets can include journalists, activists, politicians and diplomats. The vast majority of Apple users will never receive one of these alerts.
Apple describes its alerts as high-confidence notifications. They do not represent a general security warning or an automated message triggered by everyday phishing attempts.
The company does not disclose the technical evidence behind a notification. Sharing those details could help spyware operators change their methods and avoid detection.
How to check if an Apple alert is real
If Apple identifies a possible mercenary spyware attack, it sends notifications through email and iMessage to the contact details associated with the user’s Apple Account.
Apple says genuine Apple Threat Notifications will never ask recipients to click a link, open a file, install an app or configuration profile, or provide an Apple Account password or verification code.
Users can also verify an alert by signing in directly to account.apple.com. A genuine threat notification should appear at the top of the account page after login.
Because scammers may copy the design and language of security warnings, users should avoid following links in unexpected emails or messages. Instead, they should open Apple’s account website manually in a browser.
What to do after receiving a threat notification
Apple advises recipients to take these notifications seriously. A warning means the company has high confidence that the user was individually targeted by mercenary spyware.
Users who receive an alert should enable Lockdown Mode, which provides additional protection against highly sophisticated attacks. They should also seek help from a trusted cybersecurity expert, especially if they handle sensitive information or believe their device may contain important evidence.
It is also sensible to update devices, review Apple Account security settings and ensure that strong authentication protections are enabled.


0 responses to “Apple sends new threat notifications over mercenary spyware attacks”