Skip to main content

Apple's Largest Mercenary Spyware Warning Yet Reaches Users in 110 Countries

STATUS: Active. Commercial Surveillance Campaign SEVERITY: 6/10 AUDIENCE: Government, Defense, Critical Infrastructure Security Leads  

Aug 28, 2026

·

Blog

·

Secure Communications

Apple pushed its largest wave of mercenary spyware threat notifications to date, alerting targeted users across 110 countries directly on their iPhone Lock Screen for the first time, with this year's coverage describing a target base that now reaches beyond journalists and activists to executives and anyone holding privileged access to sensitive communications. 

What Happened and Why It Is Different 

The device was the target. Encryption never entered the fight. 

On August 13, 2026, Apple sent a fresh wave of mercenary spyware threat notifications to users in 110 countries, the largest single warning wave since the program began in 2021.1 Apple has now notified customers in more than 150 countries in total.1 For the first time, the alert appears directly on the recipient's iPhone Lock Screen, alongside the existing email and Apple Account banner.2

Apple does not name the spyware vendor, the government or private client behind an attack, or the individuals targeted, and the company says it does not attribute notifications to a particular attacker, government, or region.3 Commercial spyware in this class, the kind Apple's threat notification program exists to catch, is built to compromise a device fully, often without any action from the user, and to persist afterward across calls, messages, camera, and microphone. The cost and sophistication involved mean it is reserved for individually chosen targets rather than deployed at scale. 

The disclosure has already changed behavior downstream. Access Now, the nonprofit Apple directs notification recipients to for help, reports request volumes running 30 to 40 percent above its typical rate, including from people who received an Apple notification directly.4 Coverage of this wave also describes a widened target base: beyond the journalists, activists, and opposition figures historically associated with mercenary spyware, security researchers now include corporate executives, senior negotiators, and other individuals who hold privileged access to sensitive communications or systems.5

What They Found and What It Means 

Finding 
What It Means 
Operational Consequence 
Open Question 
Apple sent notifications to targeted users across 110 countries on August 13, its largest single wave since 2021, and now delivers the alert directly to the Lock Screen. 
Apple treats this as urgent enough to interrupt the device itself, not wait for an email to be opened. 
An organization can have personnel individually targeted with no internal awareness until the moment Apple's system flags it, if it flags it at all. 
How many targeted individuals were never notified because the compromise attempt didn't match a pattern Apple's detection currently catches. 
Apple does not name the spyware vendor, the client, or the target, and does not attribute notifications to any government or region. 
A received notification confirms targeting, not the attacker's identity, so the organization has no starting thread from Apple itself. 
Response has to start from “we were targeted” with no attacker profile, rather than from a named threat actor with known tactics. 
Whether the notified individual's role, access, or recent activity offers a better clue to the likely client than Apple's notification ever will. 
This year's coverage describes a widened target base beyond journalists and activists to executives, negotiators, and anyone holding privileged access to sensitive communications. 
Being high profile is no longer the qualifying trait. Holding privileged access is. 
Personnel who never considered themselves a plausible espionage target, procurement leads, program managers, negotiators, are now inside the addressable market for tools once reserved for heads of state and dissidents. 
Whether the organizations these individuals work for have any device policy that assumes this level of individual targeting is possible. 

Why This Matters

Old Assumption 
Current Reality 
BlackBerry Response 
Mercenary spyware is a risk for heads of state, journalists, and dissidents, not for the average government or defense employee. 
This year's notification wave specifically widens the described target base to executives, negotiators, and anyone with privileged access, regardless of public profile. 
BlackBerry® SecuSUITE® solution keeps sensitive coordination off the general-purpose device entirely, so compromising the phone doesn't hand over the conversation that mattered. 
If Apple hasn't sent a notification, the device hasn't been targeted. 
Apple's program only catches what its detection currently matches and makes no claim of comprehensive coverage, so an untargeted notification is not confirmation of safety. 
BlackBerry® UEM® solution continuous compliance monitoring watches for anomalous device behavior on an ongoing basis, rather than waiting on a single vendor's detection to confirm compromise. 
A notification alone tells an organization what it needs to know to respond. 
Apple deliberately withholds vendor, client, and target details, so a notified organization has to investigate its own exposure with no attacker profile to start from. 
BlackBerry® AtHoc® solution gives security teams a coordinated channel to move a notified individual, and anyone who worked closely with them, into an incident response process immediately, without waiting on attribution that may never come. 
IMMEDIATE 
Ask personnel with a real chance of holding sensitive access, executives, negotiators, program leads, whether they have received an Apple threat notification in the past 30 days. A received alert is often never escalated internally. 
IMMEDIATE 
Enable Lockdown Mode on any personal or corporate iOS device carrying sensitive coordination, particularly for personnel who travel internationally or negotiate on the organization's behalf. Apple states it has no confirmed case of a successful mercenary spyware compromise against a device with Lockdown Mode enabled. 
SHORT-TERM 
Move sensitive coordination for high-exposure personnel off the general-purpose device rather than relying entirely on hardening a device that also runs the full consumer app stack spyware is built to exploit. 
SHORT-TERM 
Extend device compliance monitoring to flag anomalous behavior on an ongoing basis, rather than relying solely on a single vendor's threat notification to confirm compromise. 
ONGOING
Track whether the organization's device policy has kept pace with a target base that now includes roles beyond the traditionally high-profile individuals mercenary spyware used to be reserved for. 

BlackBerry Secure Communications Position

A Lock Screen notification confirms that someone decided a specific person was worth an expensive, individually built attack. It does not confirm who, why, or whether the attempt succeeded, and it says nothing about what happens next. Hardening the device the notification arrived on is necessary. It is not sufficient. The conversations that made that person a target in the first place belong somewhere a device compromise can't reach. 

Citations:

  1.  If Apple sends you a push notification alerting you to a spyware attack, take it seriously. (TechCrunch, threat notification wave, Apple statement, August 13, 2026).

  2. Apple spyware warning hits iphones in 110 Countries (CyberGuy, coverage of the Apple Lock Screen spyware warning, August 19, 2026). 

  3. Unprecedented’ number of Apple users received recent spyware alert, say investigators (TechCrunch, Apple's threat notification attribution policy, August 17, 2026). 

  4. Apple threat notifications and spyware: what everyone should know (Access Now, via TechCrunch, August 26, 2026).

  5. Apple Delivers First Lock Screen Spyware Warning to Users in 110 Countries (TechTimes, coverage of the widened target base described in the August 15, 2026 notification wave). 

Get updates about the latest in-depth knowledge for secure communications.

Industry Discussion

On-Demand Webinar: What CI Fortify Doesn't Say About Communications

In July, CISA and other agencies released joint guidance titled "CI Fortify – Advice for Isolating Vital Systems," directing critical infrastructure operators to proactively isolate vital OT systems from unreliable third-party networks and sustain essential operations independently. Join us for an informative session about what CI Fortify asks operators to do, what it costs, and what it leaves unaddressed.

Watch now