Apple Threat Notification alerts have landed in users’ inboxes again, with reports emerging on 13 August that a fresh batch of warnings about mercenary spyware attacks on iPhones had been dispatched. If one landed in yours, you are in a select and unwelcome club, but you are not alone, and the feature itself has been quietly running since 2021.

What the Apple Threat Notification alerts actually say

The notifications tell recipients that Apple has detected a ‘mercenary spyware attack targeted at your iPhone.’ Apple relies on its own threat intelligence and internal investigations to make that call, and stresses these are not routine warnings. ‘Although our investigations can never achieve absolute certainty, Apple threat notifications are high-confidence alerts that a user has been individually targeted by a mercenary spyware attack, and should be taken very seriously,’ the company has stated. The bar, in other words, is deliberately high before Apple pulls the trigger.

Apple does not identify which spyware sits behind any individual alert, so there is no confirmed link between this particular wave and any named tool. Apple has historically cited NSO Group’s Pegasus as an example of mercenary spyware associated with this category of attack, and forensic work following previous notification waves has confirmed Pegasus infections in some cases, but that connection cannot be assumed for the current batch.

The company is similarly tight-lipped about methodology. ‘We are unable to provide information about what causes us to issue threat notifications, as that may help mercenary spyware attackers adapt their behaviour to evade detection in the future,’ Apple explained. No government, company, or geographical region is attributed in individual alerts either.

Scale, targets, and what to do if you received one

According to a support document Apple has previously published, the company sends these alerts to users in more than 150 countries when it detects highly targeted attacks against specific iPhone users. The potential target list has historically included journalists, activists, politicians, and diplomats. The attacks themselves are, by design, rare and ruinously expensive to mount. ‘Mercenary spyware attacks cost millions of dollars and often have a short shelf life, making them much harder to detect and prevent,’ Apple noted. ‘The vast majority of users will never be targeted by such attacks.’

The scale of a previous notification wave gives useful context for how Apple operates this programme. TechCrunch reported that an earlier round of alerts was sent to individuals in 92 nations at 12 p.m. Pacific Time on a Wednesday, illustrating both the breadth of Apple’s monitoring and the co-ordinated, time-stamped way it rolls these warnings out globally.

If a notification has reached you, Apple recommends treating it with full seriousness. Alerts arrive via email (typically from threat-notifications@email.apple.com) and iMessage, sent to the addresses and phone numbers tied to your Apple Account. You can verify authenticity by signing in directly to account.apple.com, a genuine notification will appear at the top of the page once you are logged in. Apple will never ask you to click a link, open a file, install an app or profile, or hand over an Apple Account password or verification code as part of a legitimate alert; any message that does is a fake.

For those who have received a confirmed notification, Apple advises enabling Lockdown Mode and contacting a cybersecurity expert. Given that the company’s own language frames these as high-confidence, individually targeted alerts, that is advice worth following without delay. BleepingComputer contacted Apple for a statement on the current notification wave but had not received a response at the time of publication.

Apple sends these alerts multiple times a year and has done since 2021, meaning the 13 August wave is the latest in a rolling programme rather than an exceptional event, though for anyone on the receiving end, the distinction probably feels academic.

Share.

Software engineer and video game uber-nerd.

Comments are closed.

Exit mobile version