About Apple threat notifications and protecting against mercenary spyware
Apple threat notifications are designed to inform and assist users who may have been individually targeted by mercenary spyware attacks.
About Apple threat notifications
Apple threat notifications are designed to inform and assist users who may have been individually targeted by mercenary spyware attacks, likely because of who they are or what they do. Such attacks are vastly more sophisticated than regular cybercriminal activity, as mercenary spyware attackers apply exceptional resources to target a very small number of specific individuals and their devices. Mercenary spyware attacks cost millions of dollars and often have a short shelf life, making them much harder to detect and prevent. The vast majority of users will never be targeted by such attacks.
According to public reporting and research by civil society organizations, technology firms, and journalists, individually targeted attacks of such exceptional cost and complexity have historically been associated with state actors, including private companies developing mercenary spyware on their behalf, such as Pegasus from the NSO Group. Though deployed against a very small number of individuals — often journalists, activists, politicians, and diplomats — mercenary spyware attacks are ongoing and global.
Mercenary spyware attacks are exceptionally well funded, and they evolve over time. Apple relies solely on internal threat-intelligence information and investigations to detect such attacks. Although our investigations can never achieve absolute certainty, Apple threat notifications are high-confidence alerts that a user has been individually targeted by a mercenary spyware attack, and should be taken very seriously. We are unable to provide information about what causes us to issue threat notifications, as that may help mercenary spyware attackers adapt their behavior to evade detection in the future.
Since 2021, we have sent Apple threat notifications multiple times a year as we have detected these attacks, and to date we have notified users in over 150 countries in total. The extreme cost, sophistication, and worldwide nature of mercenary spyware attacks make them some of the most advanced digital threats in existence today. As a result, Apple does not attribute the attacks or resulting threat notifications to any specific attackers or geographical regions.
How threat notifications are delivered
If Apple detects activity consistent with a mercenary spyware attack, we notify the targeted user in the following ways:
An Apple Threat Notification alert appears on the user’s iPhone, on the Lock Screen and in Settings.
Apple sends an email notification to email addresses associated with the user’s Apple Account.
A threat notification banner is displayed at the top of the user’s Apple Account page after they sign in to account.apple.com.

Apple threat notification on the Lock Screen.

Apple threat notification in Settings.
If you receive an Apple threat notification
Apple threat notifications provide additional information and recommend steps that users can take to help protect their accounts and devices, including enabling Lockdown Mode. We strongly suggest notified users enlist expert help, such as the rapid-response emergency security assistance provided by the Digital Security Helpline at the nonprofit Access Now. Recipients of Apple threat notifications can contact the Digital Security Helpline 24 hours a day, seven days a week through their website. Outside organizations don’t have any information about what caused Apple to send a threat notification, but they can assist targeted users with tailored security advice.
Apple threat notifications never ask the user to click any links, open files, install apps or profiles, or provide an Apple Account password or verification code by email or on the phone. To verify that an Apple threat notification is genuine, sign in to account.apple.com. If Apple sent a threat notification, it’s clearly visible at the top of the page after sign-in.
As of 2026, we notify targeted users directly on iPhone and via email sent from Apple Threat Notifications (threat-notifications@email.apple.com). Notification types may vary based on the user’s device model and software version.
Guidance for all users
Although the vast majority of users will never be targeted by mercenary spyware, all users can continue to protect themselves from general cybersecurity threats by following best practices for security:
Update your devices to the latest software, which includes the latest security fixes.
Protect your devices with a passcode, Touch ID, or Face ID.
Use two-factor authentication and a strong password for your Apple Account.
Turn on Stolen Device Protection.
Install apps from the App Store.
Use strong and unique passwords online — and passkeys where available.
Don’t open links or attachments from unknown senders.
If you haven’t received an Apple threat notification but have good reason to believe you may be individually targeted by mercenary spyware attacks, you can enable Lockdown Mode on your Apple devices for additional protection. If you require emergency cybersecurity assistance for other reasons, the Consumer Reports Security Planner website offers a list of emergency resources that may be able to assist you.
Information about products not manufactured by Apple, or independent websites not controlled or tested by Apple, is provided without recommendation or endorsement. Apple assumes no responsibility with regard to the selection, performance, or use of third-party websites or products. Apple makes no representations regarding third-party website accuracy or reliability. Contact the vendor for additional information.