Apple issues new mercenary spyware alerts to targeted iPhone users

Citizen Lab researcher John Scott-Railton urged recipients to verify the warning through Apple and seek expert security help.

By · Published

Primary source: X - John Scott-Railton

Why it matters

An Apple warning indicates individual targeting by a well-funded spyware operation, requiring account verification and specialized incident response.

Apple issues new mercenary spyware alerts to targeted iPhone users — Citizen Lab researcher John Scott-Railton urged recipients to verify the warning through Apple and seek expert security help.

Apple issued a new round of threat notifications on August 13th warning selected iPhone users that they had been individually targeted by mercenary spyware, according to John Scott-Railton (@jsrailton), a senior researcher at the University of Toronto's Citizen Lab.

Scott-Railton, who leads Citizen Lab's Targeted Threats team, told recipients in a six-post thread on X to seek expert security help immediately. He cited Pegasus, the spyware developed by NSO Group, as an example of the technology used in government-linked surveillance operations.

Apple also updated its threat-notification guidance on August 13th. Apple describes these warnings as high-confidence alerts that a person has been individually targeted, often because of their identity or work. Journalists, activists, politicians and diplomats are among the groups that have historically received them.

The warning does not identify the spyware vendor, the operator behind the attack or the activity that triggered Apple's detection. Apple says releasing those details could help spyware operators alter their methods and avoid detection.

Verify the alert through Apple

Recipients should first confirm the notification without interacting with links or attachments in the message. Apple says a genuine warning appears directly on the targeted user's iPhone, including on the Lock Screen and in Settings. Apple also sends an email to addresses associated with the user's Apple Account.

A copy of the warning should appear at the top of account.apple.com after the user signs in. If no alert is present there or in iPhone Settings, the message may be an impersonation attempt and should be reviewed by a security expert.

Apple's threat notifications never ask recipients to open a file, install an app or configuration profile, disclose an Apple Account password, or provide a verification code by email or phone. That distinction matters because a forged spyware warning gives an attacker a plausible pretext to send a phishing link to someone who already believes they are under surveillance.

Apple says it has sent these notifications several times a year since 2021 and has reached users in more than 150 countries. Apple has not specified how many people or countries were included in the August 13th round.

Seek specialized help

Scott-Railton urged recipients to avoid handling the incident alone. Apple's own guidance directs notified users to the Digital Security Helpline operated by Access Now (@accessnow), which provides free, around-the-clock incident response for qualifying members of civil society, including journalists, activists and human rights defenders.

Access Now can provide tailored security guidance and help investigate suspicious devices or messages. The nonprofit does not participate in Apple's detection process and does not receive information about why Apple selected a particular account for notification.

Users should preserve the warning and seek advice before erasing, replacing or extensively changing the affected device. A specialist may need device records to determine what happened and recommend steps based on the user's work, contacts and exposure.

Turn on Lockdown Mode

Apple and Scott-Railton also recommend Lockdown Mode for people who received a notification or have credible reason to expect sophisticated targeting. The optional setting reduces the device features available to an attacker by restricting message attachments, complex web technologies, unfamiliar FaceTime calls, service invitations, device connections and configuration profiles.

On an iPhone or iPad, users can enable it under Settings, Privacy & Security, and Lockdown Mode. The device restarts after activation. Apple recommends updating every device to the latest available software first and enabling Lockdown Mode separately on supported iPhones, iPads and Macs. Turning it on for an iPhone also activates it on a paired Apple Watch.

Lockdown Mode changes how some websites, messages and Apple services work. Those restrictions are deliberate: the setting removes functionality that sophisticated spyware developers can use as an entry point.

For people who have not received an Apple alert but want to review their broader exposure to phishing, account theft and data collection, the Consumer Reports Security Planner generates a personalized set of security recommendations. A confirmed Apple threat notification, however, calls for direct incident-response assistance rather than a routine security checklist.

Reader comments

Conversation for this story loads after sign-in.