Skip to content
Apple

Apple Moved Its Spyware Warning to the Lock Screen

Cybersecurity
Apple sent a fresh round of threat notifications on 13 August, and changed how they arrive. The warning now lands on the iPhone Lock Screen — which makes it far harder to miss, and far easier for someone to imitate.
By Mr Wangdoo  |  Wangdoo.com  |  August 14, 2026  |  9 min read
Transparency notice: Everything Apple states here is taken from its support document “About Apple threat notifications and protecting against mercenary spyware,” published 13 August 2026. The figure of 110 countries in this specific round is not in that document and is attributed in the text. Wangdoo has not received a threat notification and cannot verify the appearance of any individual alert.

On 13 August 2026, Apple issued another round of threat notifications to people it believes have been individually targeted by mercenary spyware, and published a rewritten support document the same day.

Apple’s document does not say how many people were notified in this round. It states that notifications have gone to users in over 150 countries since the programme began in 2021. AppleInsider and 9to5Mac report the current round reached 110 countries, a figure Apple confirmed to reporters but has not published itself.

What changed

Apple states in the new document that “as of 2026” it notifies targeted users directly on iPhone. Regional versions of the same support page still list the older arrangement — a banner on the Apple Account website, plus an email and iMessage. The document published on 13 August lists three delivery routes.

On the deviceAn Apple Threat Notification alert on the iPhone Lock Screen and in Settings
By emailSent to addresses associated with the Apple Account, from [email protected]
On the webA banner at the top of account.apple.com after signing in

Apple adds that notification types may vary by device model and software version. The practical reading is that the Lock Screen alert is not guaranteed on every device — someone on an older iPhone or an out-of-date iOS release may still receive only the email and the account banner. Apple does not publish a minimum version.

A Lock Screen alert with a permanent entry in Settings is difficult to miss. An email can sit unread, be filtered as spam, or be dismissed as phishing — and the people Apple is trying to reach receive a great deal of targeted phishing.

How to tell a real one from a fake

A Lock Screen alert is a more attractive thing to counterfeit than an email banner, and Apple has published images of exactly what the real one looks like.

Apple lists what its notifications never do.

NeverAsk you to click any link
NeverAsk you to open files
NeverAsk you to install apps or configuration profiles
NeverAsk for your Apple Account password or a verification code, by email or on the phone

To verify: sign in to account.apple.com directly, typing the address rather than following any link. If Apple sent you a threat notification, it appears clearly at the top of the page after sign-in. If nothing is there, the message you received did not come from Apple.

Nobody legitimate charges to remove spyware after one of these alerts. Apple does not offer that service, does not endorse anyone who does, and directs recipients to a free nonprofit helpline instead. A real warning that creates urgency is exactly the cover a follow-up scam needs.

How to check, and what to do

Two places show whether Apple has sent you one: Settings on the iPhone, where the alert persists after the Lock Screen banner is dismissed, and account.apple.com. If neither shows anything, Apple has not sent you one.

If it is there, Apple’s guidance in sequence:

1. UpdateInstall the latest software, which Apple notes carries the latest security fixes
2. Turn on Lockdown ModeSettings → Privacy & Security → Lockdown Mode. Requires a restart. Apple’s wording is “your Apple devices” — it is set per device, so an iPad and a Mac need enabling separately
3. Get expert helpThe Digital Security Helpline at Access Now, free, 24 hours a day. Apple names no alternative
4. Pay nobodyApple performs no forensic examination itself and endorses no paid removal service
Video: enabling Lockdown Mode on iPhone (not a Wangdoo production)

Apple notes that outside organisations have no information about what caused it to send a notification, but can give tailored security advice.

Lockdown Mode is protection, not a cure. Apple presents it as a way to reduce a device’s exposure to attack. It is not described as removing anything already present, and Apple offers no spyware removal tool and performs no forensic examination. Anyone who needs to know whether a device was actually compromised needs the expert help Apple points to, not a settings toggle.

The same applies across devices. Apple’s wording is to enable Lockdown Mode on “your Apple devices” — plural. A threat notification relates to the Apple Account rather than to one handset, so an iPad or Mac signed in to the same account needs enabling separately.

What the notification means

Apple describes these as high-confidence alerts that a user has been individually targeted, and says they should be taken very seriously. It also concedes that its investigations can never achieve absolute certainty.

Apple relies solely on internal threat-intelligence to detect these attacks, will not explain what triggered any individual notification — publishing detection criteria would let operators adjust to evade it — and declines to attribute the attacks to any specific attacker, government or region.

On who is targeted: Apple states the notifications go to people targeted “likely because of who they are or what they do,” and names journalists, activists, politicians and diplomats. It says the attacks cost millions of dollars, have a short shelf life, and that the vast majority of users will never be targeted by them.

Apple cites Pegasus from the NSO Group as an example of the category, attributing that characterisation to public reporting and research by civil society organisations, technology firms and journalists rather than to its own detection work.

The guidance for everyone else

Apple lists seven measures for users generally, none of which are specific to spyware.

1Update devices to the latest software, which includes the latest security fixes
2Protect devices with a passcode, Touch ID or Face ID
3Use two-factor authentication and a strong password for the Apple Account
4Turn on Stolen Device Protection
5Install apps from the App Store
6Use strong, unique passwords — and passkeys where available
7Don’t open links or attachments from unknown senders

Apple also states that anyone who has not received a notification but has reason to believe they may be individually targeted can enable Lockdown Mode without waiting for one.

My Take — Mr Wangdoo

Moving the alert to the Lock Screen is the right call and an overdue one. A warning that arrives by email, aimed at people whose inboxes are already a target-rich environment for impersonation, was competing against the exact thing it was warning about.

The trade-off is that Apple has now created a highly recognisable, highly alarming notification format, and published pictures of it. That is a template. The verification instruction — type account.apple.com yourself and look for the banner — is the most useful line in Apple’s document, and the one most likely to be skipped by someone reading an alarming alert at speed.

Apple’s role is narrower than the alert implies. It detects, it notifies, it recommends Lockdown Mode, and it hands the recipient to a nonprofit helpline. It does not investigate the device, does not say what it found, and does not name who was responsible. Each has a defensible reason. The net effect is that the person receiving Apple’s most serious notification is told almost nothing about what happened to them.

Common questions

How do I check whether an Apple threat notification is genuine?

Apple’s stated method is to sign in to account.apple.com directly, typing the address rather than following a link. A genuine threat notification appears clearly at the top of the page after sign-in. Apple states its notifications never ask you to click links, open files, install apps or profiles, or provide your password or a verification code.

Does the notification mean my device was hacked?

Apple describes the notifications as high-confidence alerts that a user has been individually targeted, while stating its investigations can never achieve absolute certainty. Apple does not say in its document whether a targeted device was successfully compromised, and does not perform forensic examination.

Why won’t Apple say what triggered it?

Apple states it cannot provide information about what causes it to issue threat notifications, because doing so could help mercenary spyware attackers adapt their behaviour to evade detection in future. For the same reason, it does not attribute attacks to any specific attacker or region.

Does Lockdown Mode remove spyware already on my device?

Apple does not describe it that way. Lockdown Mode is presented as reducing a device’s exposure to attack by restricting features commonly exploited. Apple offers no spyware removal tool and states it does not perform forensic examination, which is why it directs recipients to the Access Now helpline for expert assessment.

Can I turn Lockdown Mode off again?

Yes. It is set in the same place it is enabled — Settings, then Privacy & Security, then Lockdown Mode — and switching it off also requires a restart. It is enabled per device, so an iPad or Mac turned on separately has to be turned off separately.

What does Lockdown Mode actually change?

Per Apple’s documentation: most message attachment types are blocked, along with links and link previews; certain complex web technologies are blocked, so some sites load slowly or incorrectly and web fonts may not display; incoming FaceTime calls are blocked unless you have called that person within the past 30 days; and a locked iPhone will not connect to a computer by cable. It requires a restart to enable.

Sources

  1. Apple — “About Apple threat notifications and protecting against mercenary spyware,” support document, published 13 August 2026. support.apple.com
  2. Apple — Lockdown Mode support documentation. support.apple.com
  3. Access Now — Digital Security Helpline and Apple threat notifications. accessnow.org
  4. AppleInsider — “New wave of Apple threat notifications reach 110 countries,” 14 August 2026. appleinsider.com
  5. 9to5Mac — “Apple sends fresh wave of mercenary spyware warnings worldwide,” 13 August 2026, for the 110-country figure. 9to5mac.com
Mr Wangdoo avatar
Mr Wangdoo
Founder and editor-in-chief of Wangdoo.com. Covering AI, cybersecurity, EVs, smart home, and emerging tech from Dublin, Ireland. All opinions are documentation-based; nothing here has been hands-on tested unless explicitly stated.