Apple sends spyware alerts to iPhone users in 110 countries — here's what to do

By: Anton Kratiuk | today, 12:40
Apple sends spyware alerts to iPhone users in 110 countries — here's what to do

Apple sent emergency threat notifications to iPhone and iPad users across 110 countries on August 13, 2026 — the latest wave in a warning program that has now reached more than 150 countries since it launched in 2021. The alerts target a narrow group: journalists, activists, politicians, and diplomats who may have been hit by so-called mercenary spyware, the kind sold by contractors like NSO Group (maker of Pegasus). If you received one, treat it as real.

What the alert means

The notifications appear on the iPhone Lock Screen and inside Settings, and are also sent by email and to your iCloud account page — a delivery upgrade Apple calls a significant improvement for making sure recipients actually see them. The message says your device "may have been targeted" by a spyware attack, not that it was definitely compromised. Apple bases these alerts on its own internal threat intelligence and acknowledges that it "can never achieve absolute certainty." The company does not name specific attackers or countries behind any given wave.

Recipients are directed to contact Access Now's Digital Security Helpline, a nonprofit that provides free, round-the-clock support for people facing digital surveillance. Third-party security organisations won't know why Apple sent the alert, but they can help assess individual risk.

Researchers at Citizen Lab have credited Apple's notification system with real-world impact — TechCrunch alert analysis notes the alerts helped expose the Polish government's use of spyware against political opponents during elections, setting a precedent for civil society accountability.

The UK context

The alerts arrive at an awkward moment for British iPhone users. In early 2025, the UK government issued a secret Technical Capability Notice demanding Apple build a backdoor into iCloud's encrypted storage. Apple responded by disabling its Advanced Data Protection feature for all UK users — meaning stronger end-to-end encryption is still unavailable in Britain, per Privacy International TCN analysis. Apple's threat detection runs separately from iCloud encryption, but the dispute underlines the tension between government access demands and the security tools Apple uses to protect high-risk individuals.

What everyone else should do

Even if you haven't received an alert, a few basic steps reduce your risk considerably:

- Update your iPhone or iPad to the latest software version. - Use a strong passcode alongside Face ID or Touch ID. - Enable two-factor authentication on your Apple account. - Turn on Stolen Device Protection in Settings. - Only install apps from the App Store. - Don't tap links in unexpected messages.

Apple is not disclosing what triggered this particular wave of alerts. The company says there is no reason to panic, but urges anyone flagged to act promptly.