Skip to content
Rush Commerce
Field Notes3 min read

Apple's spyware alerts now land on the Lock Screen

Apple notified users in 110 countries of mercenary spyware attacks and moved the alert on-device. The email version is a phishing template — verify it properly.

On August 13 Apple sent another round of mercenary spyware threat notifications, this time reaching users in 110 countries. The batch itself isn't new — Apple has run this program since 2021. What changed is where the alert shows up: it now appears on the iPhone's Lock Screen and in Settings, not just in an email. That's a small product change with a real consequence for how you verify one.

What actually happened

Per BleepingComputer, Apple pushed notifications through email and iMessage to the addresses and numbers on the user's Apple Account, with the mail coming from threat-notifications@email.apple.com. Users can confirm an alert by signing in at account.apple.com, where it appears at the top of the page. Malwarebytes reports the addition of the on-device Lock Screen and Settings alert, which previously did not exist.

Apple calls these high-confidence alerts that a specific person was targeted. It does not name the spyware, the operator, or the country. It recommends Lockdown Mode, current software, and expert help. Apple has notified users in more than 150 countries across the life of the program.

Why a mercenary spyware alert matters for your business

Mercenary spyware is not aimed at your five-person shop. Journalists, activists, diplomats. The part that lands on you is the email.

An unsolicited message claiming Apple detected an attack on your phone, urging immediate action, sent from a domain most people have never seen — that is the exact shape of a credential-harvesting campaign, and it now has an authentic version circulating in 110 countries to launder it. The rule for your team is the same rule as for a bank alert: never act from the message, act from the account. Open account.apple.com by typing it, or check the device itself. The on-device Lock Screen alert is the one channel an outside attacker can't forge.

Decide the Lockdown Mode question before you need it, too. It blocks most message attachments, breaks some link previews, and disables certain web technologies — which means it will break a workflow or two on the day someone turns it on in a panic. Pick who would enable it, test it on one device this month, and write down what stops working. Same discipline as any other break-glass control: rehearse it while nothing is on fire.

Key takeaways

  • Apple notified users in 110 countries on August 13; alerts now surface on the Lock Screen and in Settings, not just email
  • The legitimate email comes from threat-notifications@email.apple.com — and is a ready-made template for phishers
  • Verify by typing account.apple.com or reading the device, never by clicking a link in the message
  • Test Lockdown Mode on one device now so you know what it breaks before you need it

Out-of-band verification should be a habit, not a hope. We build internal tools and approval flows where confirming something real takes one step your team will actually take. Tell us where your process leaks, or see what we build.

Sources: BleepingComputer, Malwarebytes, Apple Support.

  • #apple
  • #spyware
  • #mobile-security
  • #phishing
  • #lockdown-mode
TR

Tommy Rush — Founder, Rush Commerce

Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More

Get The Rush Report weekly — one email, zero fluff.