Independent reporting on American politics
STATE BEACON

Apple alerts users in 110 countries to mercenary spyware, cumulative notifications now exceed 150 nations

On 13 August 2026 Apple pushed lock‑screen warnings to iPhone users in 110 countries, bringing the total number of nations it has ever warned about mercenary spyware to more than 150.

By State Beacon·
iPhone displaying the lock‑screen push notification about mercenary spyware

Apple sent lock‑screen push notifications on 13 August 2026 to users in 110 countries, raising the cumulative total of nations ever warned about mercenary spyware to more than 150, according to a TechCrunch report that quotes Apple directly.

Apple’s lock‑screen alert system

Since its debut in 2021, Apple’s spyware‑alert feature has appeared on the lock screen of iPhones, iPads and Macs when the company’s security algorithms detect a high‑confidence indication of a government‑grade intrusion. The alerts are part of a broader suite of protections that includes Lockdown Mode, a setting that hardens the device against zero‑day exploits and makes it substantially harder for spyware to gain a foothold.

Citizen Lab researcher John Scott‑Railton highlighted the latest batch on X, noting that the notifications are a rare glimpse into the scale of state‑sponsored surveillance campaigns. Apple has repeatedly said that, despite the alerts, it has not observed a device being compromised while Lockdown Mode was active.

The 13 August 2026 notification batch

The TechCrunch article confirms that Apple dispatched the notifications on Thursday, 13 August 2026, targeting users in 110 countries. The text of the alert reads: “Apple detected a mercenary spyware attack targeted at your iPhone. There are actions you can take now to protect your data and device.” The wording is identical to previous alerts, but the geographic reach is the largest single batch to date.

Apple adds that the cumulative count of countries it has ever notified now exceeds 150. The figure is presented as a simple tally – the company does not break down how many alerts were sent in each nation, nor does it disclose the total number of devices that received the warning.

Because the notification appears on the lock screen, it is visible even when the device is otherwise idle, prompting immediate user action. Apple’s guidance directs users to enable or verify Lockdown Mode and to follow a set of steps that include updating to the latest iOS version and reviewing app permissions.

Apple’s financial backdrop

Apple’s ability to roll out a global security push at this scale rests on a balance sheet that remains among the strongest in the technology sector. The most recent Form 10‑Q filed on 31 July 2026 shows the following key figures for the fiscal year ending 27 June 2026:

Apple’s principal financial metrics as of 27 June 2026 (Form 10‑Q)
Metric Value Unit Source
Net income 101,464,000,000 USD SEC Form 10‑Q, filed 31 July 2026
Total assets 383,266,000,000 USD SEC Form 10‑Q, filed 31 July 2026
Shareholders’ equity 107,520,000,000 USD SEC Form 10‑Q, filed 31 July 2026
Shares outstanding 14,608,963,000 shares SEC Form 10‑Q, filed 31 July 2026

These numbers illustrate a company with more than $100 bn in net profit and a balance sheet that comfortably supports large‑scale security initiatives. Apple’s revenue figure from the 2018 Form 10‑K (US$265.6 bn) is included for historical context, showing that the firm has maintained a multi‑hundred‑billion‑dollar revenue base for many years.

Implications for users and the spyware market

The notification batch arrives at a moment when governments and private actors alike are intensifying the use of “mercenary” spyware – tools sold to the highest bidder and often employed in political espionage. By publicly acknowledging the presence of such threats in 110 countries, Apple is effectively mapping the global footprint of these tools, even if the map is coarse.

For users, the immediate impact is a clear call to action: enable Lockdown Mode, install the latest OS updates, and review app permissions. The alert’s wording – “mercenary spyware attack” – is unusually specific, signaling that Apple believes the threat originates from commercial surveillance vendors rather than nation‑state actors directly.

From an industry perspective, Apple’s approach contrasts with the more opaque practices of other platform providers that often rely on post‑incident disclosures. By pushing a proactive warning, Apple forces a public conversation about the prevalence of state‑grade surveillance tools and the responsibility of device manufacturers to protect end‑users.

Analysts have noted that the sheer number of countries involved suggests a supply chain that is both diverse and resilient. The fact that Apple has not observed a successful breach of a device protected by Lockdown Mode reinforces the feature’s technical merit, but it also raises the question of whether attackers are shifting tactics to target less‑protected devices or to exploit zero‑day vulnerabilities that bypass the mode entirely.

Open questions

  • Apple has not disclosed how many devices received the alert, nor the proportion of its global install base that resides in the 110 targeted nations.
  • The company did not specify which spyware families or vendors were implicated, leaving security researchers to infer the threat from the “mercenary” descriptor.
  • It remains unclear whether the cumulative “over 150 countries” count includes the 110‑country batch or represents a separate tally of earlier alerts.
  • Apple’s statement that no device has been hacked while Lockdown Mode was enabled is based on internal monitoring; independent verification is not publicly available.

These gaps highlight the limits of publicly available data and underscore the need for continued scrutiny from independent security labs and journalists.

What comes next?

Apple is expected to continue refining its detection algorithms and may expand the lock‑screen alert to cover additional threat vectors, such as malicious ad‑networks or supply‑chain compromises. The company’s next quarterly filing, due in October 2026, will likely include updated figures on security‑related expenditures, which could provide insight into how much Apple is investing in these defenses.

For regulators and policymakers, the notification batch adds pressure to address the trade of mercenary spyware, a market that has already drawn scrutiny in Europe and the United States. Apple’s public stance may influence forthcoming legislation that seeks to curb the sale of surveillance tools to repressive regimes.

Until more granular data emerges, users should treat the alert as a prompt to harden their devices now, while the broader tech community watches for any signs that the underlying threat is evolving.