Apple sends threat notifications to individuals in 92 countries, warning them that their iPhone may have been targeted by remote “mercenary spyware attacks”
Apple sent threat notifications to iPhone users in 92 countries on Wednesday, warning them that may have been targeted by mercenary spyware attacks.
TechCrunchManish Singh
Context & Ripple Effects
Apple had previously notified Indian opposition figures of possible state-backed iPhone attacks, making this broader alert cycle an escalation in the geographic reach of a notification system that flags high-risk targeting rather than confirms a compromise. The episode follows earlier warnings to Indian opposition leaders.
The language also matters: related coverage says Apple shifted its terminology from “state-sponsored” to “mercenary spyware,” softening the attribution framing amid political sensitivity around who may be behind such attacks. That distinction preserves the warning’s security value while avoiding a direct public allegation against a state actor.
First-order effects
Recipients in 92 countries are prompted to treat their iPhones as potentially targeted and seek immediate security or forensic assistance; the notice does not establish that any individual device was compromised.
Apple expands the visible scope of its high-risk threat-notification program while using “mercenary spyware” language that identifies the type of threat without publicly assigning responsibility.
Second-order effects
Digital-security responders and civil-society groups face more demand to validate alerts, support affected users, and distinguish attempted targeting from confirmed infection.
The terminology shift gives governments and other implicated parties less direct attribution to contest, while still keeping commercial spyware activity in public view.
Third-order effects
If these broad, non-attributed alerts continue, platform security notifications could become a more routine early-warning layer for politically sensitive and cross-border cyber targeting.
The pattern points to a security market in which spyware risk is disclosed through device-platform alerts, while definitive attribution increasingly moves to forensic investigators and independent researchers.
The trend: High-risk device security is shifting toward global user notifications that surface mercenary-spyware threats without necessarily naming the actors behind them.
I can easily imagine the following, totally made-up, conversation in Cupertino: IR Team at Apple: “We had at least 79.6 million compromised phones by this zero-click attack” Marketing: “no no.... We can't say that!!! On how many continents?” IR: “Seven. We even had an attack in..…
This suggests Apple's threat intel team is much more effective than we may have thought before. This was always hard to tell because Apple basically just doesn't talk about security. [image]
IMPORTANT: has @Apple recently sent you a #MercenarySpyware threat notification? This is serious. Seek expert help. If you're a journalist, activist, dissident, academic, etc. etc: ✅contact the @accessnow Digital Security Helpline. https://www.accessnow.org/help/
Apple has notified people in 150 countries that they were infected with mercenary spyware (Intellexa, NSO...). We knew spyware was global but this is next level. The market has grown tremendously since 2004, when Hacking Team was getting started. https://support.apple.com/... [im…
BIG BREAK ON @EconomicTimes by @aashisharyanET This comes as CERT-in has been warning Apple about vulnerabilities in its system several times in the past few months. @AshwiniVaishnaw @IndianCERT @GoI_MeitY
🚨Apple has sent threat notifications to iPhone users in 92 countries informing them they “are being targeted by a mercenary spyware attack” If you're a member of civil society + received an alert, you can request forensic support using our Get Help form👇https://securitylab.amnest…
2/ @Apple's notifications continue to play critical role in helping #MercenarySpyware targets get help & take action. And they keep leading to accountability. To date, Apple says they have notified users in 150 countries. That's a jaw-dropping illustration of the scale of the... …
NEW: Apple have just notified people in 92 countries who were targeted by highly-invasive spyware. Our experts @AmnestyTech Security Lab can check devices for signs of attack 🔍. Please share widely with any activists or journalists who may have received the latest Apple alert