Apple is warning users they may be targets of government-grade spyware

If you got a security notification from Apple this week, don’t dismiss it. Apple has sent out a new wave of warnings to users it believes have been targeted by mercenary spyware, the kind of sophisticated surveillance software that governments pay millions of dollars to deploy against specific individuals. John Scott-Railton, a senior researcher at the University of Toronto’s Citizen Lab, was among the first to flag it publicly, writing on X that “that means tech like Pegasus used by governments to spy on you.”

According to Engadget, Apple told TechCrunch it has also updated how it presents these warnings, making it easier for recipients to find relevant information quickly. Alongside the notification, Apple has published a new support page explaining what mercenary spyware is and what targeted users can do about it.

So what exactly is mercenary spyware? Apple’s own page describes it as surveillance tools sold by private companies to state actors and governments. The buyers then use those tools to go after specific high-value targets, typically journalists, activists, politicians, and diplomats. These aren’t mass surveillance dragnets. They are expensive, highly targeted attacks. Most iPhone users will never face one. But for those who do, the tools are notoriously hard to detect and harder to block.

Apple is upfront about the limits of its detection system. The company admits its investigations “can never achieve absolute certainty.” But it also calls these notifications “high-confidence alerts” that should be taken seriously. It won’t say exactly how it identifies targeted users, which is a reasonable call. Publishing that methodology would hand spyware vendors a roadmap for evading detection.

Getting the notification does not automatically mean your data has been stolen. It means Apple detected behavior on your device that looks consistent with a mercenary spyware attack. That distinction matters, but it doesn’t mean you should relax. Apple recommends several concrete steps for anyone who receives one of these warnings:

  • Enable Lockdown Mode, which restricts message attachments, FaceTime calls, Apple service invitations, and shared photo albums
  • Update your device to the latest software version immediately
  • Contact a digital security expert, specifically the Digital Security Helpline run by the nonprofit Access Now, which offers rapid-response emergency assistance

The bigger picture here is worth paying attention to. Apple has been sending these notifications since 2021, and each new round is a reminder that commercial spyware is still very much an active threat. Companies like NSO Group, the maker of Pegasus, have faced legal action and export restrictions, but the industry hasn’t gone away. New vendors keep emerging, and governments keep buying.

Apple’s willingness to notify users is genuinely useful. But it also raises a question the company hasn’t fully answered: if the threat is real enough to warrant a warning system, why are the protections still largely reactive? Lockdown Mode helps, but it’s an opt-in feature that most users don’t know exists. For people in high-risk categories, that’s a significant gap. The notifications are a good start. They shouldn’t be the last line of defense.