Apple has issued another round of security alerts to people it believes may have been targeted with mercenary spyware, highlighting how sophisticated surveillance attacks remain an ongoing problem for a small but particularly vulnerable group of iPhone users.
The company confirmed that notifications were sent to affected users across 110 countries. Apple has not disclosed how many people received the latest warnings, nor has it identified the spyware involved or the organizations suspected of deploying it.
This is not an isolated campaign. Apple has now sent mercenary spyware threat notifications to users in more than 150 countries over several years. A previous round in 2025 reached users across 100 countries, while reports later revealed that more than a dozen Iranian users had received alerts ahead of the war with Israel.
Mercenary spyware differs considerably from the everyday malware most consumers encounter. These tools are typically expensive, highly targeted and designed to compromise specific individuals rather than spread indiscriminately. Journalists, activists, politicians, diplomats and other high-profile targets have historically faced greater exposure to this type of surveillance.
That makes Apple’s notifications particularly important. Receiving one does not mean an iPhone owner has simply encountered a suspicious website or phishing message. Apple’s threat notification system is intended for cases where the company detects activity consistent with a targeted mercenary spyware attack.
Alongside the latest alerts, Apple has updated its guidance explaining how threat notifications work and what recipients should do next. The company recommends that anyone receiving a warning seek specialist security assistance and enable Lockdown Mode, an optional protection introduced specifically for people facing unusually sophisticated digital threats.
Lockdown Mode deliberately restricts certain iPhone, iPad and Mac features to reduce the number of potential routes an attacker can exploit. That comes with usability compromises, which is why it is not intended as an everyday setting for most Apple customers.
For users who have not received a spyware warning, the advice is considerably more conventional. Apple recommends keeping devices updated, protecting them with a passcode and biometric authentication, enabling two-factor authentication for Apple Accounts and using Stolen Device Protection. It also advises installing software from the App Store, using unique passwords or passkeys and treating unexpected links and attachments with caution.
Apple stresses that the overwhelming majority of its customers are unlikely to become targets of mercenary spyware. That distinction matters: these notifications should not be interpreted as evidence of a widespread iPhone compromise affecting ordinary users.
The geographic reach of the latest warnings is still significant, however. Commercial surveillance technology has developed into an international security issue rather than a problem confined to a handful of governments or regions. Smartphone makers can continue closing vulnerabilities and adding defensive features, but highly resourced attackers have strong incentives to find new ways around them.
For the relatively small number of people who receive one of Apple’s threat notifications, the message should therefore be treated less like a routine security recommendation and more like an indication that someone may have deliberately selected them as a target.

