Apple changes the channel of its mercenary spyware notices and they now appear directly on the iPhone lock screen
Apple has sent a new batch of mercenary spyware warnings to iPhone users in 110 countries. The novelty of this round, sent on August 13, is not so much in the content of the message as in the channel through which it arrives: For the first time, the alert appears directly on the iPhone lock screen in the form of a push notification, rather than relying solely on email or a web notice from your Apple account.
The news became public after John Scott-Railton, senior researcher at the Citizen Lab digital threat research laboratory at the University of Toronto, published screenshots of the notice received by several users on X, warning that it was Pegasus-type technology used by governments for surveillance. Apple, along with sending the notifications, has also published an updated support page that explains what this type of threat consists of and what steps anyone who receives one of these alerts can follow.
A notice that now appears on the lock screen
Since Apple began sending these types of notifications in 2021, the delivery mechanism has been one of its weak points. The notices arrived by email, iMessage or through a banner on the Apple account website, channels that at-risk people can easily overlook, mark as spam, or outright mistrust them because they seem like a phishing attempt.
With this change, the alert becomes show up as a permanent notification on the lock screenalso supported by a fixed row within the device’s Settings app. This is a relatively simple design change, but it significantly reduces the chance that a person targeted by such a sophisticated attack will ignore the warning for days or even weeks.
What exactly does the Apple notification say
The message that affected users receive is direct: “Apple has detected a mercenary spyware attack targeting your iPhone. There are actions you can take now to help protect your data and your device”. Apple insists that its investigations “they can never achieve absolute certainty”but describes these notifications as highly confident notices that should be taken very seriously.
The company also does not reveal which specific signals trigger the sending of a notification.and justifies it explicitly: providing details about the detection process could help attackers adapt their behavior to avoid being discovered in the future. Apple also remembers that receiving the notice does not automatically imply that the device is compromised, but rather that it has detected activity compatible with an attack of this type. Although the company does not identify the specific spyware behind each notice, it usually cites Pegasus, from the Israeli NSO Group, as a historical example of this type of tools.
One of the data that has had the most weight in the coverage of this news has to do with the Isolation Mode (Lockdown Mode)the extreme security feature that Apple introduced with iOS 16 that blocks most message attachments, incoming FaceTime calls from strangers, and invitations to Apple services, among other restrictions. According to Apple itself, they are not aware of any mercenary spyware attack that has been successful against a device with this protection activated, almost four years after its launch.
What to do if you receive a notification
Apple recommends that anyone who receives one of these notices Immediately activate Isolation Mode and verify the notice directly through account.apple.comsince these alerts never request passwords or personal information by email or message.
The historical targets of these types of attacks are usually journalists, activists, politicians and diplomats.profiles with an especially high value for state actors willing to invest large sums of money in highly sophisticated surveillance tools. Apple assures that the vast majority of its users will never be the target of an attack of this typealthough the fact that the company has already notified people in more than 150 countries since 2021 confirms that the phenomenon of mercenary spyware, far from subsiding, is still fully active.
Apple is not the only company that uses this type of notice. Google and WhatsApp have also sent similar notifications to their users in recent years, sometimes linked to the same surveillance campaigns detected by Apple on iOS devices. This overlap between different manufacturers and services reinforces the idea that mercenary spyware is not a problem exclusive to one specific manufacturer, but rather a cross-cutting threat that affects any platform capable of becoming the target of a well-funded surveillance operation.
