An unprecedented number of Apple customers reported receiving an official warning from the company in recent days, alerting them to targeted cyberattacks utilizing advanced spyware, according to findings from researchers and digital rights organizations tracking such incidents. The current wave began last Friday, when Apple dispatched a broad series of notifications to users across 110 countries, warning them that they had become targets of an attack. Consequently, over the weekend, public and private reports flooded communication and support networks.
From time to time, the tech giant issues warning batches to users it estimates were targeted as high-value individuals or whose devices were already compromised. These involve malware typically used by state actors, which Apple categorizes as "commercial spyware" or "spyware for hire". In recent years, the company noted that it sent similar alerts to users in more than 150 countries. However, this latest wave is considered the largest recorded to date.
Mohammed al-Maskati, who manages the team of researchers on the helpline for the organization Access Now, said that since Friday, a record number of requests for assistance have been logged – including from users who received similar warnings in the past. According to al-Maskati, this represents an increase of roughly 30% to 40% compared to typical inquiry volume following Apple warning waves. Cyber security firm iVerify also confirmed it detected an unusual spike in reports regarding these alerts.

Ukrainian fighters also targeted
Alongside private inquiries, many shared news of receiving the alert on social media. One recipient is a service member in the Armed Forces of Ukraine participating in combat against Russia. The fighter, who requested anonymity for security reasons, said he initially suspected the notification was a phishing scam until he verified the data with Apple. "To be honest, I was quite surprised," he said. "I didn't think I was important enough to be targeted as such an investment. But I'm flattered."
He added that he knows other soldiers in the Ukrainian military who received identical warnings in recent days, noting that it raised concern among them. The Computer Emergency Response Team of Ukraine (CERT-UA) did not offer a response to the reports.
Tip of the iceberg
John Scott-Railton, a senior researcher at Citizen Lab (a research organization investigating state-sponsored spyware attacks for about 15 years), noted that the findings indicate digital surveillance is far more widespread than commonly believed. "The scale and geographic distribution of public reports are unprecedented," Scott-Railton said. "For every public message like this, you can assume there is a massive iceberg of alerts that the public will never see. This is a clear indication that something much larger is happening behind the scenes."
According to researchers, part of the increase in response volume is also attributed to a change in Apple's notification methods. Starting this year, the company displays the warning prominently on the iPhone lock screen, in Settings, via the email address linked to the Apple account, and upon logging into the account through a web browser.
What should you do?
Security experts and Apple made clear that users who received the message must take it with the utmost seriousness. The immediate recommendation is to enable "Lockdown Mode" – an advanced security feature from Apple that dramatically reduces the attack surface on iPad, iPhone, and Mac computers. Apple previously noted that there are no known cases where a device operating in Lockdown Mode was successfully breached. Amnesty International stated that the warning notices Apple dispatches are not ordinary phishing messages, but a severe indication that your device might be targeted by advanced surveillance actors.
Does the alert mean the device was already hacked?
The alert means Apple detected an attempt to breach the device. The alert itself does not determine that the attack succeeded. Past forensic examinations conducted by Amnesty International, Citizen Lab, and Access Now showed that in many cases, alerts did indeed confirm actual infections with destructive spyware like Pegasus (including in India, Serbia, Jordan, Algeria, and Armenia).
Spyware leaves almost no trace: These software programs collect information covertly and transmit it to a third party – often government operators – without the user noticing any change in device activity.
What should you do if you receive the message?
Immediately enable "Lockdown Mode": This Apple feature hardens device defenses, blocks specific file types and calls, and dramatically reduces the possibility of a breach.
Contact forensic support (for journalists and activists): Civil society organizations and Amnesty International's security lab offer targeted forensic support for journalists, human rights activists, and civil society members who are at high risk.
Maintain caution even without an alert: If you are unsure but fear you were targeted as a potential victim, it is recommended to enable Lockdown Mode as a preventive safety measure.



