Apple sent mercenary spyware warnings to users in 110 countries on August 13, 2026, bringing its total reach since 2021 to more than 150 countries. Recipients should verify the warning directly through account.apple.com, update every device, secure their Apple Account, and enable Lockdown Mode.
Research answer

Create a landscape editorial hero image for this Studio Global article: What did Apple’s August 13, 2026 threat-notification campaign to users in 110 countries reveal about the scope and operation of its mercenar. Article summary: Apple’s August 13 campaign showed that its mercenary-spyware warning system is a recurring, worldwide program—not a country-specific alert: Apple notified an unspecified number of people in 110 countries in that wave, an. Topic tags: general, general web, user generated, government. Style: premium digital editorial illustration, source-backed research mood, clean composition, high detail, modern web publication hero. Use reference image context only for broad subject, composition, and topical grounding; do not copy the exact image. Avoid: logos, brand marks, copyrighted characters, real person likenesses, fake screenshots, UI text, readable text, watermarks, ch
Apple’s August 13, 2026 notification wave confirmed that its mercenary-spyware warning system is a recurring global program, not a country-specific alert. The company said the latest campaign reached users in 110 countries; since launching the program in 2021, Apple says it has notified users in more than 150 countries.
Apple says it combines its own threat intelligence with investigations to identify activity consistent with an individually targeted mercenary-spyware attack. The company’s current delivery system can show a genuine warning on the iPhone Lock Screen and in Settings, send it to email addresses linked to the Apple Account, and display a banner after the user signs in at account.apple.com.
The Lock Screen delivery is important because it makes the warning harder to miss than an email alone. However, recipients should still verify the message independently by typing account.apple.com into a browser rather than following a link in an unexpected email or text.
An Apple threat notification is a high-confidence warning that Apple believes the recipient may have been individually targeted by an exceptionally sophisticated and well-funded spyware operation—potentially because of who they are or what they do. Apple says these attacks focus on a very small number of specific people and devices and are far more advanced than ordinary cybercrime.
The warning should therefore be treated as urgent, especially by people whose work involves journalism, activism, politics, diplomacy, human-rights advocacy, or sensitive investigations. Apple also emphasizes that most people will never be targeted by attacks of this kind.
A notification is not a public forensic report. It does not necessarily prove that the device was successfully infected, and it does not identify the spyware product, operator, government customer, or geographic origin of the attack.
Apple says its detection process cannot achieve absolute certainty. It also does not disclose the evidence behind individual warnings because doing so could help spyware operators adapt their methods. Apple consequently describes the notifications as high-confidence alerts rather than definitive attribution.
That distinction matters in public reporting. An alert can be a powerful lead, but confirming an infection generally requires additional technical examination. The absence of an Apple notification should not be treated as proof that someone was not targeted.
Apple recommends a rapid, practical response:
account.apple.com yourself. Do not use links from messages that could be phishing attempts.Real Apple threat notifications do not ask users for passwords or verification codes, and they do not ask recipients to install software, profiles, or files.
Mercenary spyware is designed to be difficult to see. An Apple notification can give a potential victim a rare starting point for preserving a device, seeking forensic analysis, and comparing an incident with other cases.
That process can reveal patterns that are invisible when each target is considered separately: repeated targeting, overlapping dates, common technical indicators, and links between victims in political, journalistic, or civil-society networks. Investigations have documented spyware targeting involving people in Poland and other European countries, while researchers have cautioned against assigning responsibility to a specific operator without sufficient evidence.
A recent Citizen Lab investigation illustrates the value of combining Apple warnings with forensic work. Researchers reported with high confidence that former European Parliament member Stelios Kouloglou’s device was infected with Pegasus on multiple occasions while he was serving on the committee investigating spyware abuse. The report also says he received multiple Apple threat notifications.
The broader lesson is that notifications can help transform a suspected individual attack into evidence of a wider surveillance campaign. They still do not provide a complete census of victims or, by themselves, establish who ordered an operation.
Apple’s August 13 campaign demonstrated the international reach and continuing operation of its mercenary-spyware alert program: users in 110 countries received warnings, and Apple says its notifications have now reached more than 150 countries since 2021.
For an individual recipient, the right interpretation is serious but precise: Apple believes the person was likely singled out by a highly capable attacker, but the alert alone does not confirm a successful infection or identify the attacker. Verification, device updates, stronger account security, Lockdown Mode, and expert assistance are the appropriate next steps.
Studio Global AI
This page includes a source-backed answer you can continue inside Studio Global.
Apple sent mercenary spyware warnings to users in 110 countries on August 13, 2026, bringing its total reach since 2021 to more than 150 countries.
Apple sent mercenary spyware warnings to users in 110 countries on August 13, 2026, bringing its total reach since 2021 to more than 150 countries. Recipients should verify the warning directly through account.apple.com, update every device, secure their Apple Account, and enable Lockdown Mode.
Researchers use these alerts as leads for forensic investigations that can connect individual targeting incidents to broader surveillance campaigns.