Apple sent a fresh wave of mercenary spyware threat notifications to iPhone users in 110 countries on August 13, 2026, pushing the cumulative tally of nations it has warned targets about since 2021 past 150.
What makes this round different is delivery: for the first time, the alert lands as a push notification directly on the Lock Screen rather than sitting in an inbox where it could go unread for days.
Apple threat notifications are not routine malware warnings. They are high-confidence signals reserved for individuals believed to have been singled out by mercenary spyware commercial-grade surveillance tools built by private vendors and historically linked to state-sponsored operations, most notably NSO Group’s Pegasus.
Mercenary Spyware Alert
Unlike mass cybercrime campaigns, these attacks cost millions of dollars to mount and target vanishingly small numbers of people, typically journalists, human rights defenders, diplomats, and politicians. Apple has been explicit that it will not disclose the technical indicators behind its detection, since revealing them would allow attackers to adapt and evade future surveillance.
A genuine notification arrives through three synchronized channels: an on-device alert on the iPhone Lock Screen and in Settings (now flagged with a red badge), an email from threat-notifications@email.apple.com, and a banner at the top of a user’s account page after signing in at account.apple.com.
Apple stresses that these notifications never include clickable links, file attachments, or requests for a password or verification code; any message that does is a phishing attempt impersonating the real alert.

This notification wave lands amid an escalating legal and technical fight against NSO Group. In June 2026, Meta disrupted a fresh Pegasus-linked spear-phishing campaign on WhatsApp targeting users in Jordan and Lebanon, and asked a US court to hold NSO in contempt for violating a permanent injunction issued after the company was ordered to pay roughly $168 million in damages for exploiting WhatsApp’s infrastructure against more than 1,400 people.
Separately, Amnesty International’s Security Lab published its most comprehensive technical dissection yet of Pegasus’s evolution in July 2026, while judicial probes in Spain and France into government-linked Pegasus abuse remain stalled due to a lack of cooperation from Israel.
If you receive a notification, forensic responders recommend not factory resetting the device immediately, since a wipe destroys the evidence investigators need. Instead:
- Enable Lockdown Mode across every Apple device tied to the account. Apple says it knows of no successful mercenary spyware attack against a device with Lockdown Mode active since it launched in iOS 16.
- Update to the latest OS, currently iOS 26.6, released July 27, 2026.
- Contact Access Now’s Digital Security Helpline, available 24/7, for tailored forensic guidance.
- Change your Apple Account password from a separate trusted device and review connected devices and configuration profiles.
Apple reiterates that the overwhelming majority of users will never be targeted by mercenary spyware, but general hygiene remains essential: keep devices updated, use passcodes plus Face ID or Touch ID, enable two-factor authentication and passkeys, install apps only from the App Store, and avoid links or attachments from unknown senders.
Site: Thecyberdef.com
Follow TheCyberDef on Google News, LinkedIn & X for the latest cybersecurity updates. Stay informed.