Apple sent a new wave of mercenary spyware threat notifications on Friday, telling users in 110 countries that their devices had been individually targeted. The people who investigate those cases afterwards say the response has been the largest they have ever handled. Mohammed Al-Maskati, who directs the Access Now team that reviews reports to the nonprofit’s Digital Security Helpline, told TechCrunch that requests since Friday are running around 30% to 40% above what investigators usually see after an Apple notification batch, including from people who had been notified before. Security firm iVerify separately told TechCrunch it was seeing an influx of the same alerts.

Apple changed how a spyware notification reaches you
The volume is the headline, but the mechanism behind it is the part worth understanding. Apple’s own support document on threat notifications carries a published date of 13 August 2026 — the day before this batch went out — and it sets out four separate places an alert now appears: on the iPhone Lock Screen, in the Settings app, in an email to the addresses on the Apple Account, and as a banner at the top of account.apple.com after signing in. Apple’s page states that as of 2026 it notifies targeted users directly on iPhone and by email, with the exact mix varying by device model and software version.
Both Al-Maskati and John Scott-Railton, a senior researcher at The Citizen Lab, told TechCrunch the sheer number of people surfacing could be partly down to that new delivery method. That is an important distinction: a record number of people reacting to an alert is not the same as a record number of people being attacked. It may mean a record number finally noticed.
Scott-Railton put the wider point plainly to TechCrunch:
For every public notification like this, you can imagine there’s a huge notification iceberg that the public will never learn about. This is a clear indication that something bigger is going on.
How to tell a real Apple threat notification from a scam
This is the practical bit, and it cuts both ways: an alert this alarming is exactly what a phishing campaign would imitate. One recipient, a Ukrainian soldier who spoke to TechCrunch anonymously, said he assumed it was a scam until he checked with Apple directly.
Apple’s guidance is specific. A genuine threat notification never asks you to click a link, open a file, install an app or profile, or hand over your Apple Account password or a verification code by email or phone. To confirm one is real, sign in at account.apple.com yourself — not through any link in a message — and look for the banner at the top of the page. Apple also points notified users to the Access Now helpline, which runs 24 hours a day, and recommends turning on Lockdown Mode.
What Apple has not said
Apple did not respond to TechCrunch’s request for comment on this wave, so every figure describing its scale comes from Access Now, iVerify and Citizen Lab rather than from Apple. Two numbers are also easy to conflate: 110 countries is this batch, while the “over 150 countries” figure on Apple’s support page is the cumulative total since 2021. Apple states outright that it will not explain what triggers a notification, and does not attribute attacks to any specific attacker or region.
Android owners should not read this as somebody else’s problem. The commercial surveillance industry sells exploit chains for both platforms, and the targeting profile — journalists, activists, opposition figures, soldiers — has nothing to do with which phone the target happens to carry. What is genuinely different is the visibility: Apple has now built notification into four places you cannot easily miss, and that transparency is the standard every phone maker should be measured against.
Sources: TechCrunch (Lorenzo Franceschi-Bicchierai)





