Apple has sent threat notifications to users in 110 countries, warning that they may have been individually targeted by highly sophisticated mercenary spyware attacks.

The alerts were sent on August 13, Apple confirmed to USA Today on August 14. The company did not disclose which countries were affected or provide details about the specific threats behind the latest notifications.
The warnings are designed for a small group of users who Apple believes may be at heightened risk of targeted spyware attacks. The company says these attacks are rare but can involve significant resources and are far more sophisticated than ordinary cybercrime.
Why is Apple sending threat notifications?
Apple introduced its threat notification system in 2021 to warn users when the company detects activity suggesting they may have been individually targeted by mercenary spyware.
Unlike typical cyberattacks, these operations are generally aimed at a small number of specific people and their devices. Apple says attackers can have access to exceptional resources, and such spyware campaigns can cost millions of dollars.
The company does not publicly identify every targeted user or disclose all the details behind an individual notification.
Receiving an alert does not mean Apple is claiming that a user's device has definitely been infected. Instead, the notification indicates that Apple has detected activity that suggests the user may be a potential target and should take additional security precautions.
Who gets Apple threat notifications?
Apple sends these warnings only to users it believes may have been individually targeted by mercenary spyware.
That means the notification is not a general warning being sent to all iPhone users. People who receive one may include individuals who are considered particularly attractive targets for sophisticated surveillance campaigns.
Apple has previously described these attacks as involving a small number of people rather than large-scale attacks affecting millions of ordinary users.
For the latest round, Apple confirmed that notifications went to users in 110 countries, but it has not publicly identified the countries or disclosed the identities or categories of those targeted.
What does an Apple threat notification look like?
Apple says genuine threat notifications can appear in several places, including as a push alert on a user's device, within the Settings app, by email to addresses associated with the Apple Account and as a banner at the top of the user's Apple Account page.
The company also provides a way to distinguish an authentic warning from a phishing attempt.
A genuine Apple threat notification will not ask users to click suspicious links, install an application or provide their Apple Account password or username.
Users who receive an alert can sign in directly to their Apple Account rather than following links in a message. If Apple has issued a genuine threat notification, it should appear at the top of the account page after signing in.
What should users do after receiving the alert?
Apple recommends taking the warning seriously and following the security measures included with the notification.
One of the most important steps is enabling Lockdown Mode, an optional security feature designed to provide an extreme level of protection against sophisticated digital attacks. It restricts or limits certain apps, websites and device features that could potentially be exploited.
Lockdown Mode is available on devices running iOS 16 or later.
Apple also recommends keeping devices updated with the latest software, using a strong device passcode and enabling two-factor authentication for an Apple Account.
Users should also consider enabling Stolen Device Protection, use strong and unique passwords and avoid opening unexpected links or files.
Apple advises users to install applications only through the App Store.
Why these alerts matter
Mercenary spyware attacks are considered different from conventional cybercrime because they are highly targeted and can involve substantial financial and technical resources.
Apple has repeatedly warned that such attacks may target a small number of people because of who they are or what information they may have access to. The company therefore uses threat notifications as an early warning mechanism for users who could face an elevated risk.
For people who receive one, the alert should not be dismissed as an ordinary security notification. At the same time, users should avoid panic and verify the warning directly through their Apple Account rather than clicking links contained in messages.
Apple also recommends that people who receive threat notifications seek expert assistance. The company points users to Access Now's Digital Security Helpline, which offers technical support and rapid-response assistance to people at risk.