
A Ukrainian soldier fighting on the front lines against Russia got a notification on his iPhone telling him he’d been targeted with military-grade spyware. His first instinct was that it was a scam. It wasn’t. And he’s apparently not alone, not by a long shot.
According to TechCrunch, Apple sent out a new wave of spyware threat notifications on Friday to customers across 110 countries, warning them that their devices had been targeted with what the company calls “mercenary spyware,” the kind of surveillance tool typically sold to governments. The scale of this particular batch appears to be the largest Apple has ever sent.
Mohammed Al-Maskati, director of the investigative helpline team at Access Now, a digital rights organization that Apple recommends victims contact, told TechCrunch that his team has received a record number of people reaching out for help since Friday. That’s 30% to 40% more than the group usually sees after Apple sends a notification batch. Cybersecurity firm iVerify also confirmed it was seeing an unusual influx of Apple threat notifications hitting users at the same time.
So what’s actually going on here? A few things, probably. John Scott-Railton, a senior researcher at The Citizen Lab who has spent over 15 years tracking government spyware, put it plainly: “For every public notification like this, you can imagine there’s a huge notification iceberg that the public will never learn about. This is a clear indication that something bigger is going on.” The public posts alone, he said, show a scale and geographic spread that researchers haven’t seen before.
But part of the spike may also be a function of Apple changing how it delivers these warnings. Starting this year, Apple now pushes alerts to users through multiple channels at once:
- The iPhone lock screen
- The Settings app
- The email address tied to the user’s Apple account
- The Apple Account web portal when users log in
That’s a meaningful shift. Previously, a notification could be easier to miss or dismiss. Now Apple is making sure users actually see it. Al-Maskati credited this approach with helping people take the issue more seriously: “Apple’s new notification method has made it harder for users to ignore.” It’s also possible, of course, that more notifications simply means more spyware infections. The two explanations aren’t mutually exclusive.
The Ukrainian soldier, who asked to remain anonymous for obvious safety reasons, told TechCrunch he was surprised to be targeted. “I wouldn’t have thought I was important enough for them to target me like this,” he said. He also mentioned that other people in Ukraine’s military had received the same alert and “were a bit worried.” Ukraine’s national computer emergency response team did not respond to a request for comment.
Apple has sent these alerts in batches to people in more than 150 countries over the past few years. The company has not commented on this latest wave. That silence is worth noting. Apple markets itself as a privacy-first company, and its threat notification system is one of the few concrete actions it takes to warn users about real-world attacks. But it rarely explains its methodology, the specific spyware involved, or who it believes is responsible for a given campaign. Users are warned, then largely left to figure out the rest on their own.
If you receive one of these notifications, treat it seriously. Apple and security researchers recommend enabling Lockdown Mode on your iPhone, iPad, or Mac. It’s a restrictive security setting that significantly limits attack surface. Apple says it has no record of anyone running Lockdown Mode being successfully compromised. That’s about as close to a strong endorsement as you’re going to get from a company that still won’t tell you exactly what hit you.