An unknown number of people in 110 countries received an unwanted message from Apple on Thursday: their iPhone had been targeted by sophisticated surveillance software. Affected users see the notification on their lock screen.
On August 13, Apple once again notified users whose devices, according to the company's assessment, had been targeted in an attack using so-called mercenary spyware. People in 110 countries are affected; since these warnings began in 2021, Apple has now reached more than 150 countries in total. How these commercial surveillance tools work and who typically ends up in the crosshairs is covered in our overview of Pegasus and commercial spyware on the iPhone.
Key Facts at a Glance
- Apple sent threat alerts to users in 110 countries on August 13 – the largest number in a single round.
- The warning appears on the lock screen, as an entry in the settings, via email, and as a banner on the account page.
- Apple does not disclose how many people are affected or which countries are involved.
- The recommendation focuses on the Lockdown Mode, for which Apple has yet to discover a successful attack.
- Since August 2025, Germany and Austria have been subject to an EU ban on the use of surveillance software against journalists. This ban does not apply in Switzerland.
How the warning is received
Apple describes three ways to receive threat notifications in its support document. On iPhones, the notification appears on the lock screen and also as a separate entry at the top of the settings, above airplane mode and Wi-Fi. Additionally, an email is sent to the addresses registered with the Apple account from threat-notifications[at]email.apple.com. And users who log in to their account page will see a banner there.
The message on the device is brief: Apple has detected a mercenary spyware attack on this iPhone, and there are steps you can take now to protect your data and device. Tapping on it opens further instructions. According to Apple, the exact form of these instructions depends on the device model and system version.
Apple has emphasized one detail for years, and it's the most important one for everyone else: Genuine threat notifications never contain links and never request data, app installations, or passwords. Anyone receiving such a message with a link is dealing with a phishing attempt. You can verify this by logging into account.apple.com – the genuine notification is listed at the top.
An overview of the waves since 2021
Apple sends out these warnings several times a year. The number of affected countries in each round varies, without Apple ever disclosing how many individuals are behind them or which countries are involved.
| Time | Countries in this round | Note |
|---|---|---|
| November 2021 | First round | Threat notifications start |
| April 2024 | 92 | Change in terminology from "state-sponsored" to "mercenary spyware"„ |
| July 2024 | 98 | |
| May 2025 | 100 | First public confirmations from those affected in Europe |
| August 2026 | 110 | Largest number so far in a single round |
The change in wording in spring 2024 had a political background: Apple initially spoke of state-sponsored attacks and rephrased this after complaints from India. Today, Apple's documentation simply states that such attacks are historically associated with state actors. The company deliberately does not disclose how it detects these attacks – the reasoning being that attackers could otherwise adapt their tactics. Even when Apple introduced the feature in 2021, its communication to affected users was intentionally vague on this point.
Two recipients of the May 2025 data wave are publicly known: Italian journalist Ciro Pellegrino and Dutch commentator Eva Vlaardingerbroek. A subsequent forensic investigation by Citizen Lab revealed that Pellegrino was infected with the Graphite spyware from Paragon, which was installed via an iMessage attack that required no action from the recipient.
Why the Lockdown Mode is central
The key technical recommendation for affected users is to activate Lockdown Mode. This disables a number of functions that could serve as entry points, making a device significantly more difficult to attack.
There is a compelling argument for this: Apple stated in March that it is not aware of a single case in which a device with the Lockdown Mode activated has been successfully attacked. This is not a guarantee, but a remarkable track record for a security feature that has now been in use for four years.
The price for this is convenience. If you want to know what limitations the mode imposes in everyday use and how to activate it, you can find this information in the instructions for activating Lockdown Mode. Apple explicitly points out that it can also be activated by anyone who has not received a warning but has good reason to believe they are being targeted.
In addition to the Lockdown Mode, Apple refers users to the Digital Security Helpline of the non-governmental organization Access Now, which is available 24/7. These organizations do not receive information from Apple about what triggered the warning, but they can help secure the device.
What applies in Germany, Austria and Switzerland
No direct link to German-speaking countries can be established for this wave – Apple does not name any countries, and warnings have so far only been publicly confirmed by individuals elsewhere. However, the legal framework here differs significantly from the rest of the world.
Since August 8, 2025, the European Media Freedom Act, Regulation (EU) 2024/1083, has been in force. Article 4 generally prohibits authorities from using surveillance software against journalists; this is only permissible in individual cases, with judicial confirmation, and where there is an overriding public interest. This is directly applicable law in Germany and Austria.
Switzerland is neither a member of the EU nor the EEA. The media freedom law does not apply there; Swiss journalists are solely reliant on national law. This doesn't change anything about threat notifications – Apple sends these worldwide – but it does change the question of what authorities are legally permitted to do within their own country.
That this question is not merely theoretical in Germany is demonstrated by our own history: The Federal Criminal Police Office (BKA) confirmed the use of Pegasus as early as 2021. The same software that Apple warns its customers about is an official tool in Germany.
A warning that triggers an investigation
The practical value of these notifications extends beyond the individual recipient. John Scott-Railton, lead researcher at the Canadian Citizen Lab, which was the first to publicize the latest round, describes the mechanism as follows: A warning creates a signal that an entire group has been targeted. Some of those affected then seek help, and this leads to investigations that uncover further cases.
His example is Poland, where the previous government's handling of surveillance software became one of the country's biggest scandals. Without Apple's notifications, Scott-Railton argues, the matter would never have come to light. The Pellegrino case shows the same pattern on a smaller scale: only the warning led to the forensic investigation, which in turn brought the specific vendor to light.
That's where the real value of a report lies, one that has virtually no impact on almost all readers. Each round of reporting increases the likelihood that systematic abuse will actually come to light. For a company that has been litigating against providers of such software since 2021, this is not a side effect.
Those who do not receive the warning do not need to do anything
For the vast majority of people, this news changes nothing. Mercenary spyware costs enormous sums per target and is used against very small groups – journalists, activists, lawyers, diplomats, opposition members. Apple itself states that the overwhelming majority of users are never attacked.
Apple's general recommendations remain the same: current system version, device code, two-factor authentication, activated protection for stolen devices, apps from the App Store, strong passwords or passkeys, no attachments from unknown senders.
What's worthwhile is being vigilant against fake alerts. A genuine threat notification without a link is easily distinguishable from a fake one with a link – provided you know how. Would you permanently enable Lockdown Mode as a precaution, or would the restrictions in your daily life be too significant? Let us know in the comments what convenience you would be willing to sacrifice for greater security. (Image: Apple / Apfelpatient)
- App Store Commission: Apple wants 15 percent in the USA
- The iPhone X and MacBook Pro 2018 are now considered outdated
- Apple opens second training center in Houston


