Apple Warns Users in 110 Countries of Mercenary Spyware — For the First Time, Straight to the Lock Screen
August 13's threat notification wave is the largest in the program's history, and the first delivered as a push alert instead of email. Devices in Lockdown Mode have never been compromised since the feature launched in 2022.
Apple sent a fresh wave of threat notifications to iPhone users in 110 countries on August 13 — the largest single warning wave since the program launched in 2021, and the first time it arrived as a push alert on the Lock Screen instead of an email that can sit unread for a week.
The notifications warn recipients they may have been individually targeted by mercenary spyware — commercial surveillance tools built by vendors like NSO Group, whose Pegasus software Apple has cited as an example in past disclosures, though the company doesn’t name a specific vendor in the alerts themselves. These tools cost millions of dollars to deploy and are used almost exclusively against journalists, human rights activists, politicians, diplomats, and dissidents rather than the general public — Apple is explicit that most users will never receive one of these notifications.
The delivery-channel change matters more than it might seem. Email-based threat notifications have a real failure mode: a target doesn’t check that inbox, or the message lands in spam, or days pass before they see it — and mercenary spyware campaigns move fast once a target is selected. A Lock Screen push alert closes that gap. It’s the same logic Apple applied to Find My and emergency alerts — critical, time-sensitive information belongs where a user will actually see it within minutes, not buried in an inbox.
Anyone who receives a warning is directed to enable Lockdown Mode, the extreme hardening setting Apple shipped in 2022 that disables message attachment previews, most JIT JavaScript compilation, wired connections when locked, and other features spyware exploits typically abuse. The claim Apple keeps repeating — and that has held up across four years of disclosed campaigns — is that no device running Lockdown Mode has been successfully compromised by mercenary spyware since launch. Apple also points targeted users to Access Now’s Digital Security Helpline, a nonprofit that provides free, around-the-clock incident response for exactly this threat category.
The scale here — 110 countries in a single wave — says less about a single new spyware campaign and more about how widespread commercial surveillance tooling has become as a category. Threat notification programs like Apple’s, plus similar efforts from Google’s Threat Analysis Group, are now a standing feature of the mobile security landscape rather than a rare event. For high-risk individuals — anyone in journalism, activism, or public office who hasn’t already enabled Lockdown Mode — this wave is as good a prompt as any to turn it on before a notification arrives, not after.