Unprecedented Wave of Apple Spyware Alerts Signals Escalation in "Mercenary Spyware" Attacks
CUPERTINO, CA – August 17, 2026 – Apple customers across 110 countries have been hit with an unprecedented wave of threat notifications this past weekend, alerting them to suspected "mercenary spyware" attacks targeting their devices. Experts investigating these sophisticated cyber threats describe the recent surge as the largest ever recorded, prompting serious concerns about the escalating prevalence and reach of government-backed surveillance tools.
On Friday, Apple initiated a mass notification campaign, dispatching alerts to users believed to have been targeted or compromised by powerful spyware typically deployed by state-sponsored actors. While Apple regularly issues such warnings in batches, this latest installment has proven to be exceptional in its scale and global reach.
Mohammed Al-Maskati, director of the Access Now team of investigators – a digital rights group often recommended by Apple to victims of spyware – confirmed the unprecedented influx. Since Friday, his team has seen a record high number of individuals seeking assistance, a 30% to 40% increase compared to previous notification waves. Even individuals who had received prior alerts are among the new complainants. Cybersecurity firm iVerify has also corroborated this trend, reporting a significant surge in Apple threat notifications.
The widespread nature of these alerts is also evident on social media, with an unusually high number of users publicly sharing their experiences. Among them is a Ukrainian Armed Forces soldier currently fighting against Russia, who initially dismissed the notification as a scam until verifying its authenticity with Apple.
"I was a bit surprised to be honest, I wouldn’t have thought I was important enough for them to target me like this. I am flattered though," the anonymous soldier told TechCrunch, adding that other members of Ukraine’s military have received similar warnings, causing understandable concern. The Computer Emergency Response Team of Ukraine (CERT-UA) has not yet commented on whether they are aware of a broader targeting of Ukrainian soldiers.
John Scott-Railton, a senior researcher at The Citizen Lab, a prominent digital rights group with over 15 years of experience investigating government spyware, emphasized the severity of the situation. "The scale and geographic diversity of public posts about receiving notifications are pretty unprecedented," said Scott-Railton. "For every public notification like this, you can imagine there’s a huge notification iceberg that the public will never learn about. This is a clear indication that something bigger is going on." He believes the reports highlight that spyware attacks may be far more prevalent than generally perceived.
Both Al-Maskati and Scott-Railton suggest that the increased volume of alerts could also be partly attributed to Apple’s enhanced notification methods. As of this year, Apple now delivers warnings directly to iPhone lock screens, within the Settings app, via email associated with the Apple account, and upon web login to an Apple ID. "Apple’s new notification method has helped raise awareness of the issue’s importance, making it harder for users to ignore," Al-Maskati noted.
Apple has not yet responded to requests for comment regarding this latest wave of alerts.
For those who have received such a notification, experts strongly advise taking it seriously. While dedicated organizations exist to assist journalists, dissidents, and human rights defenders, other resources are available for individuals outside these categories to investigate the threat further.
Furthermore, Apple and security experts recommend immediately enabling Lockdown Mode, a specialized security feature designed to fortify iPhones, iPads, and Mac computers against sophisticated attacks. Apple has previously stated that it has no knowledge of any user with Lockdown Mode enabled successfully being hacked.
