
Apple has sent a new round of threat notifications to iPhone users it believes may have been targeted with mercenary spyware.
The warnings are issued to people facing sophisticated surveillance attacks involving tools similar to NSO Group's Pegasus spyware.
Apple uses threat notifications when it detects activity suggesting a user has been individually targeted by mercenary spyware operators. These attacks are typically expensive, highly sophisticated, and aimed at a small number of high-value targets rather than the general public.
Citizen Lab’s John Scott-Railton urged recipients to treat the alert as a serious security incident and seek expert assistance. Scott-Railton is a senior researcher at the University of Toronto's Citizen Lab, a research group known for investigating commercial spyware and targeted surveillance against journalists, activists, politicians, and civil society organizations.
A threat notification does not necessarily mean an iPhone was successfully compromised. It means Apple has detected indicators consistent with an attempted targeted attack.

@jsrailton | X
Scott-Railton advised recipients to confirm that a warning is legitimate by checking their iPhone's Settings or signing in directly at account.apple.com, where genuine Apple threat notifications should also appear.
This is important because scammers may impersonate Apple and send fake security warnings.
Scott-Railton warned that legitimate notifications should not ask users to download files, install configuration profiles, provide passwords or verification codes, or reply to someone claiming to represent Apple.
Anyone receiving a message that cannot be verified through their Apple account should avoid interacting with it and seek expert advice.
Lockdown Mode recommended for high-risk users
Commercial spyware such as Pegasus can provide operators with extensive access to a compromised smartphone, including messages, photos, location data, and other sensitive information.
Some advanced spyware campaigns use zero-click exploit chains that can compromise a device without requiring the victim to open a file or tap a malicious link.
Scott-Railton recommended enabling Apple's Lockdown Mode for users who believe they are at elevated risk.
Lockdown Mode reduces the iPhone's attack surface by restricting features and technologies that have previously been abused in sophisticated exploit chains, including certain message attachments, web functionality, incoming connection requests, and configuration changes.
Apple designed the feature primarily for people likely to face targeted surveillance, such as journalists, human rights workers, political figures, and other high-risk users.
Recipients of a confirmed threat notification should seek specialist security assistance rather than treating the incident as ordinary malware.
Scott-Railton pointed civil society members to Access Now's Digital Security Helpline, which assists journalists, activists, human rights defenders, and other at-risk users.
Affected users should also keep their devices fully updated and avoid making unnecessary changes to a potentially compromised phone before receiving expert guidance, as doing so could destroy forensic evidence.
Anyone who receives an authentic Apple mercenary spyware notification should assume the attacker may have significant technical resources and obtain qualified security assistance as soon as possible.







Leave a Reply