What to do if Apple tells you your iPhone was targeted by spyware
Apple's latest wave of threat notifications reached users in 110 countries. The alert is real, it is aimed at named individuals, and it always arrives through the same three channels — which is also how you spot a fake.
Apple sent another wave of threat notifications this week, and this time they landed with users in 110 countries. This is not the generic security prompt that asks you to update your software. It is a message telling one specific person that Apple’s systems saw activity consistent with a mercenary spyware attack aimed at that account.
The distinction matters because it changes the right response. An ordinary security warning applies to millions. This one applies to a few dozen, and it tends to reach journalists, activists, politicians, diplomats and lawyers — people attacked for what they do, by attackers with resources no ordinary scammer has.
How to tell the alert really came from Apple
The company sets out on its own support page that the notification always appears at the top of the page once you sign in at account.apple.com, and only then is it backed up by an email and an iMessage to the contacts on the account.
That gives you a working rule. Apple never asks you to click a link, open an attachment, install an app or hand over a password in order to see the warning. If the message in front of you does any of those things, it is an imitation riding on the news. Close it and go to Apple’s site yourself, typing the address by hand.
If the alert is genuine
The first step Apple recommends is turning on Lockdown Mode, an optional setting that strips out the features this kind of attack usually exploits. It limits message attachments and previews, switches off more complex web technologies, blocks unsolicited incoming invitations and stops wired connections while the phone is locked. The phone becomes less convenient and considerably harder to get into. Apple has said it has not seen a successful compromise on a device running Lockdown Mode.
After that, the sensible move is specialist digital security help rather than trying to clean the device yourself, plus keeping the operating system and apps current, because these attacks live off flaws that have not been patched yet.
The wider read
Apple has run the programme since 2021 and has now notified people in more than 150 countries, but it never names a spyware maker or a government, and it does not say how many individuals each wave covers. The 110 countries give you the scale without the names.
For almost everyone reading this it will never happen, and the value sits elsewhere: it is a reminder that phone security is a digital literacy problem, which is exactly where Portugal keeps falling short — among the best networks in Europe, and barely half the population with basic digital skills. Worth watching what Apple is doing on other fronts too, such as its move to have the OpenAI case against it thrown out.
By Oliver Grant
Chart: Tugadaily · data from Apple