Apple warns another wave of iPhone users they are being targeted by spyware-for-hire
The company sent a fresh round of high-confidence alerts on 13 August, the latest in a program that has quietly notified targets in more than 150 countries since 2021.

Key points
- Apple sent a new batch of threat notifications to iPhone users on 13 August 2025, warning them they were targeted by mercenary spyware.
- The alerts go out several times a year and have reached users in more than 150 countries since the program began in 2021.
- Apple does not name the spyware behind any single alert, but has cited NSO Group's Pegasus as a historical example.
- Typical targets include journalists, activists and diplomats, not ordinary consumers.
- Recipients should enable Lockdown Mode, verify the alert at account.apple.com, and speak to a security expert.
Apple has pushed out another round of what it calls threat notifications, warning a small group of iPhone owners that someone paid a lot of money to spy on them. Users on Reddit began sharing screenshots of the alerts on 13 August, and the story was first reported by BleepingComputer.
The alerts aren't new. Apple has been sending them since 2021, several times a year, whenever its own investigators believe a specific person has been hit by mercenary spyware: commercial hacking tools sold to governments and other buyers to break into a phone silently and read everything on it.
The best-known example is Pegasus, made by Israeli firm NSO Group. Apple itself points to Pegasus as the type of tool it's warning about. Forensic work on previous rounds of these alerts, by groups such as Citizen Lab and Amnesty International's Security Lab, has confirmed Pegasus infections on some recipients' phones. Whether this batch involves Pegasus or another vendor's product, Apple isn't saying. We've tracked NSO Group across four stories in the last 90 days, including a July report on a Pegasus infection found on the phone of an EU lawmaker who was himself investigating Pegasus.
Who actually gets these alerts?
Not you, in all likelihood. Apple is explicit that the vast majority of iPhone users will never be targeted this way. Recipients tend to be journalists, human rights activists and opposition politicians. These campaigns are expensive, and Apple quotes its own figure: the attacks "cost millions of dollars" per deployment, burning out quickly once defenders spot them, so operators save them for people they really want to watch.
Apple describes the notifications as "high-confidence alerts" based on its own threat intelligence, meaning the information security teams gather about ongoing attacks. The company won't explain what triggers a specific alert, on the reasonable grounds that spyware vendors would use that information to hide better next time. It also refuses to attribute individual alerts to any particular government or company. Attribution of commercial spyware operations is genuinely hard, and single-source claims deserve skepticism.
How do I know the warning is real?
A genuine Apple threat notification will never ask you to click a link, hand over your password, or share a verification code. If a message does any of those things, it's a scam.
Real emails come from threat-notifications@email.apple.com. Apple also shows the warning banner at the top of your account page when you sign in at account.apple.com. That's the safest check.
| What to do | Why |
|---|---|
| Sign in at account.apple.com | Confirms the alert is genuine |
| Turn on Lockdown Mode | Cuts off many spyware entry points |
| Update iOS immediately | Closes known flaws these tools abuse |
| Contact a security expert | Groups like Access Now run a free digital helpline |
What should a recipient do next?
Apple recommends switching on Lockdown Mode, a hardened setting built into iPhones that disables features spyware likes to abuse, such as certain message previews and web technologies. From there, get help. Access Now runs a free Digital Security Helpline for civil society targets, and Citizen Lab has handled many of these cases.
For everyone else the practical lesson is smaller: keep your iPhone updated, and treat any "Apple" email demanding a click with suspicion. The real ones never do.



