Apple’s spyware alerts reached 110 countries, and the change was in how they arrived
The notification wave went out on 13 August; what is new is that the warning now appears as a push alert on the iPhone Lock Screen. That may be producing the appearance of unprecedented scale as much as the targeting itself.
Apple told TechCrunch it had sent mercenary-spyware threat notifications to users in 110 countries, and that the programme has reached customers in more than 150 countries since it began in late 2021. The company declined to give a number of recipients: 110 is a count of countries, not of victims. The alert text reads, verbatim, “Apple detected a mercenary spyware attack targeted at your iPhone,” but Apple’s own hedge is that a device “may have been targeted,” and that the company “can never achieve absolute certainty.” The dispatch date was Thursday 13 August. The operational change is the delivery: for the first time the warning surfaces as a push alert on the iPhone Lock Screen, alongside the email and Apple-account-page banner Apple has used since 2021. Recipients are directed to Lockdown Mode, which Apple says has never been defeated in a confirmed case.
John Scott-Railton, senior researcher at The Citizen Lab, told TechCrunch that the geographic spread of public posts about receiving notifications was “pretty unprecedented,” and characterised the visible cases as a fraction of a much larger unseen set. Mohammed Al-Maskati, the Bahraini human rights activist who directs Access Now’s Digital Security Helpline, told the same outlet that a record number of people contacted the helpline after this batch. The claim that recipients include members of Ukraine’s military comes from Access Now, not from Apple, and is not independently confirmed. Adam Boynton, a senior enterprise strategy manager at Jamf — a company that sells device management, and therefore has a commercial interest in the finding — said “the economics of mercenary spyware mean the target list increasingly includes executives, negotiators, and anyone holding privileged access.” Apple has named no vendor and no government.
Assessment: The thing to distrust this week is the word unprecedented. Scott-Railton was precise: he was describing public posts about notifications, not measured targeting. Apple simultaneously changed the alert from something a user might find in an inbox to something that lights up a locked phone. A delivery change that makes warnings unmissable will generate more public disclosure at a constant rate of attack, and nobody has separated the two effects. Two follow-ons matter more than the wave. If Citizen Lab or Amnesty’s Security Lab publish forensic attribution in the coming days, that is the story. And the geographic breakdown of the 110 is not public — for a Gulf readership, Al-Maskati’s helpline is the likeliest route to on-the-record regional recipients.