Apple has started showing its mercenary spyware warnings directly on the iPhone Lock Screen and in Settings, rather than relying on an email and a note buried in the owner's Apple Account page. The alert now says plainly that Apple has detected a targeted spyware attack against that specific iPhone, and that there are steps the owner can take right away.
The change is small in engineering terms and large in practical ones. A threat notification is only useful if the person it is meant for actually sees it, and email is where security warnings go to be ignored.
Apple describes these as high confidence alerts, issued only when it believes an individual has been singled out by a mercenary spyware operation, and it says they should be taken very seriously. The company puts the scale of the program at targets in more than 150 countries since it launched in 2021, with the most recent round of notifications reaching people in 110 countries. Malwarebytes wrote up the change and Apple's accompanying guidance.
Who actually gets one of these
Mercenary spyware is the commercial end of the surveillance market: highly targeted campaigns, usually traced back to private vendors selling to government customers. The initial targets are chosen for who they are and what they know, which in practice means journalists, lawyers, opposition politicians, activists and the occasional executive. Almost nobody gets one of these notifications by accident.
That is exactly why the rest of us should pay attention to them. Exploit chains built for a handful of carefully chosen phones do not stay rare. They get resold, reverse engineered from the patch that fixes them, copied by competing vendors, or folded into criminal toolkits once the technique is public. The iOS attack chains we have picked apart in the past, including the four zero-day Operation Triangulation chain, started life the same way.
Scammers will copy this alert, so verify it
A dramatic full screen warning that tells you a government may be reading your messages is close to a perfect phishing template, and it will be cloned. There is a reliable check: a genuine Apple threat notification is always listed when you sign in to your Apple Account directly. If a warning appears there, it is real. If it only appears in a message, a call or a web page, it is not.
What Apple tells a target to do next
Apple's own advice for anyone who receives one is deliberately basic: install the latest software updates, lock the device with a passcode or biometrics, turn on two factor authentication with a strong Apple Account password, enable Stolen Device Protection, install apps only from the App Store, use unique passwords or passkeys, and do not open links or attachments from unknown senders. Keeping up with security updates matters more than any single setting here, since the patches are what close the chains these operations rely on, as the recent WebKit fixes show.
Two additions are worth making on top of Apple's list. Anyone plausibly in scope should turn on Lockdown Mode, which strips out the attack surface these campaigns lean on hardest. And a target should get expert help rather than troubleshooting alone; Access Now runs a Digital Security Helpline for precisely this situation. A person who receives one of these alerts is not dealing with a run of the mill infection, and the response should not be a run of the mill antivirus scan.
This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.