Apple warns another wave of iPhone users they are being targeted by spyware-for-hire

The company sent a fresh round of high-confidence alerts on 13 August, the latest in a program that has quietly notified targets in more than 150 countries since 2021.

ThreatVectr Newsdesk· 4 min read
Photoreal news-editorial image, 16:9 full-frame composition edge to edge: a darkened workstation monitor displaying a blurred generic search results page with a
Share

Key points

  • Apple sent a new batch of threat notifications to iPhone users on 13 August 2025, warning them they were targeted by mercenary spyware.
  • The alerts go out several times a year and have reached users in more than 150 countries since the program began in 2021.
  • Apple does not name the spyware behind any single alert, but has cited NSO Group's Pegasus as a historical example.
  • Typical targets include journalists, activists, politicians and diplomats, not ordinary consumers.
  • Recipients should enable Lockdown Mode, verify the alert at account.apple.com, and speak to a security expert.

Apple has pushed out another round of what it calls threat notifications, warning a small group of iPhone owners that someone paid a lot of money to spy on them. Users on Reddit began sharing screenshots of the alerts on 13 August, and the story was first reported by BleepingComputer.

The alerts are not new. Apple has been sending them since 2021, several times a year, whenever its own investigators believe a specific person has been hit by what the industry calls mercenary spyware: commercial hacking tools sold to governments and other buyers, usually to break into a phone silently and read everything on it.

The best-known example is Pegasus, made by Israeli firm NSO Group. Apple itself points to Pegasus as the type of tool it is warning about. Forensic work on previous rounds of these alerts, by groups such as Citizen Lab and Amnesty International's Security Lab, has confirmed Pegasus infections on some recipients' phones. Whether this week's batch involves Pegasus, another vendor's product, or something tracked under a different name, Apple is not saying.

Who actually gets these alerts?

Not you, in all likelihood. Apple is explicit that the vast majority of iPhone users will never be targeted this way. The people who do receive the notifications tend to be journalists, human rights activists, opposition politicians, lawyers and diplomats. These campaigns are expensive, sometimes millions of dollars per target, and the tools burn out quickly once defenders spot them, so operators save them for people they really want to watch.

Apple describes the notifications as "high-confidence alerts" based on its own threat intelligence, meaning the information security teams gather about ongoing attacks. The company will not explain what triggers a specific alert, on the reasonable grounds that spyware vendors would use that information to hide better next time. It also refuses to attribute individual alerts to any particular government or company. That caution is standard practice, and worth keeping in mind: attribution of commercial spyware operations is hard, and single-source claims should be treated with care.

How do I know the warning is real?

A genuine Apple threat notification will never ask you to click a link, install an app or profile, hand over your password, or share a verification code. If a message does any of those things, it is a scam.

The real emails come from threat-notifications@email.apple.com, and Apple also shows the warning banner at the top of your account page when you sign in at account.apple.com. That is the safest way to check. If the alert is there, it is real.

What to do Why
Sign in at account.apple.com Confirms the alert is genuine
Turn on Lockdown Mode Cuts off many spyware entry points
Update iOS immediately Closes known flaws these tools abuse
Contact a security expert Groups like Access Now run a free digital helpline

What should a recipient do next?

Apple recommends switching on Lockdown Mode, a hardened setting built into iPhones that disables features spyware likes to abuse, such as certain message previews and web technologies. From there, get help. Access Now runs a free Digital Security Helpline for civil society targets, and Citizen Lab has handled many of these cases before.

For everyone else, the practical lesson is smaller: keep your iPhone updated, and treat any "Apple" email demanding a click with suspicion. The real ones never do.

© 2026 Threat Vectr