Independent Reviews
Plain smartphone and closed laptop on a dark office desk beside a small lamp
Mobile Privacy Published 15 Aug 2026 5 min read2 sources

Apple Warns Targeted iPhone Users About Mercenary Spyware

A new alert round reached users in 110 countries. Apple says genuine notifications indicate high-confidence individual targeting and should be verified directly through the user's account.

By VPN Rocks Editorial Team

The short version

What you need to know

  • Apple confirmed a new round of high-confidence threat notifications on 13 August, with BleepingComputer reporting recipients in 110 countries.
  • A genuine warning can be checked by manually signing in at account.apple.com; Apple says its notifications never ask for a password, verification code, installation, attachment or link click.
  • A VPN protects network transport but does not stop an iPhone exploit or remove device-level spyware. Verified recipients should enable Lockdown Mode and seek specialist help.

What has Apple warned users about?

Apple confirmed that it sent a new round of threat notifications on 13 August. BleepingComputer reports that users in 110 countries received alerts saying their iPhones had been individually targeted by a mercenary-spyware attack.

These are not routine notices sent to every iPhone owner. Apple describes them as high-confidence alerts based on its own threat intelligence and investigations, while acknowledging that detection can never provide absolute certainty. The company does not identify the operator, government, spyware product or technical trigger behind an individual warning, so this batch should not be labelled Pegasus without evidence.

How to check that an alert is genuine

Open account.apple.com yourself rather than following an unexpected message. After signing in, a genuine threat notification appears prominently at the top of the page. Depending on device and software version, Apple may also show an iPhone alert on the Lock Screen and in Settings, and send an email to an address linked to the Apple Account.

Apple says a real notification will never ask the recipient to click a link, open a file, install an app or configuration profile, provide an Apple Account password or disclose a verification code. A message that makes one of those requests may be phishing even if it copies the language of a real spyware warning.

What recipients should do now

If the warning is visible inside the account, take it seriously. Apple recommends enabling Lockdown Mode and contacting the Access Now Digital Security Helpline for rapid specialist assistance. Avoid using the potentially targeted device for sensitive conversations until qualified help has assessed the situation.

Most people will never be targeted by mercenary spyware. Apple's broader advice still applies: install current software and security fixes, protect the device with a passcode and biometrics, use two-factor authentication or passkeys, enable Stolen Device Protection and avoid unknown links and attachments.

Where a VPN helps — and where it does not

A reputable VPN encrypts traffic between a device and the VPN server and can hide the user's usual public IP address from many sites. That can reduce exposure to a hostile local network, but it does not patch iOS, block a zero-click exploit or inspect what malicious code does after reaching the phone.

A VPN also cannot verify an Apple warning, find spyware already installed or make a compromised device safe for sensitive work. Lockdown Mode, updates, account security, independent verification and expert incident response address the relevant risks.

VPN Rocks view

The most important consumer lesson is not to treat every dramatic Apple-themed email as proof of a sophisticated attack. Verify the alert through a separately opened account page first; that one step distinguishes Apple's high-confidence warning from a phishing copy designed to steal the very credentials it claims to protect.

For a confirmed target, ordinary anti-malware slogans are not enough. Mercenary spyware is unusually capable and selective, so specialist help and reduced device attack surface matter more than adding another network privacy layer.

Primary reading

Sources and further reading

We add plain-English context and practical advice. These links let you inspect the underlying reporting, research and official guidance directly.

Useful next steps