
Source: Facebook
First of all: I am layman when it comes to cyber security. I did my best to investigate these threat messages to mitigate attacks that could result in me losing my Apple ID (and access to my Apps).
If you believe you are an actual high value target of cyber attacks such as a journalist, DO NOT bother reading my blog post, go straight to a cyber security expert to keep you account safe!
Every so often, Apple sends a small number of iPhone users a genuinely serious warning: a Threat Notification telling them they’re likely being targeted by „mercenary spyware“ — state-sponsored-grade surveillance tools like NSO Group’s Pegasus. Apple has done this since 2021, notifying people in more than 150 countries so far, usually in batches that occasionally make headlines.
It’s rare. But if you’re the kind of person who might realistically receive one, or you just want to be ready rather than caught of guard, here’s what to know in advance and exactly what to do if it happens.
What the notification actually looks like
Apple’s genuine threat notification shows up in three places at once, never just one:
- A banner at the top of the page when you log into appleid.apple.com directly
- An email to the address tied to your Apple ID
- An iMessage to your phone
The wording is consistent and specific. It typically says something close to: „Apple detected that you are being targeted by a mercenary spyware attack that is trying to remotely compromise the iPhone associated with your Apple ID… This attack is likely targeting you specifically because of who you are or what you do.“
It never asks you to call a number, pay a fee, or enter your password through a link in the message itself — it simply tells you to check your account directly.
Who actually gets this warning
This is not a mass alert. Apple has been clear that mercenary spyware attacks target a small, specific set of people — historically journalists, human rights activists, political dissidents, lawyers, and diplomats — because of their profession or the information they have access to, not because of anything random. If you don’t fall into a category like that, the odds you’ll ever receive one are very low. But if you do, it’s worth taking seriously and acting on right away.
How to prepare before you ever see it
This is the part most people skip, and it’s the part that actually matters — because if the notification ever arrives, you want your accounts already locked down, not scrambling to fix them mid-attack.
- Turn on two-factor authentication for your Apple ID, if it isn’t already (Settings -> [your name] -> Sign-In & Security). This is the single biggest thing standing between an attacker and your account even if your password leaks.
- Use a strong, unique Apple ID password, stored in a password manager – not reused from anywhere else.
- Keep iOS updated automatically. Most spyware exploits rely on unpatched vulnerabilities; Apple regularly patches the specific flaws these tools rely on. Settings -> General -> Software Update -> Automatic Updates.
- Know what Lockdown Mode is before you need it. It’s a built-in, one-tap feature (Settings -> Privacy & Security -> Lockdown Mode) that drastically reduces your phone’s attack surface — disabling message link previews, certain wireless connections, and other high-risk features. It’s the tool Apple itself recommends if you’re targeted. It’s inconvenient day-to-day, which is exactly why it’s worth understanding in advance rather than reading about it for the first time in a panic.
- Bookmark appleid.apple.com yourself. That way, if a notification ever arrives, you can go check your account by typing the address or using your saved bookmark, rather than clicking anything inside the message.
- Back up your data regularly (iCloud or encrypted local backup), so that if you ever do need to factory-reset or replace a device, you’re not also losing everything.
What to do when you get it
- Go to appleid.apple.com directly (typed manually or via your bookmark) and confirm the threat notification banner is there. That confirms it’s genuinely from Apple.
- Enable Lockdown Mode immediately (Settings -> Privacy & Security -> Lockdown Mode).
- Reach out to expert help. Apple’s own support documentation directs affected users to the Digital Security Helpline at Access Now, a nonprofit that provides free, rapid-response support specifically for this kind of targeted attack.
- Don’t publicly speculate about the source right away. Apple deliberately withholds technical detail about how it detects these attacks, since revealing too much helps the attackers evade detection next time — and going public too early can tip off whoever’s behind it.
- Assume the device may be compromised and treat sensitive conversations, contacts, and files accordingly until you’ve gotten expert guidance.
- Update iOS immediately if you haven’t already, and consider whether other devices tied to the same Apple ID (iPad, Mac) need the same precautions.
The one-sentence takeaway
If you ever get this notification, verify it by going straight to appleid.apple.com yourself, turn on Lockdown Mode and having 2FA, automatic updates, and backups already set up beforehand means you’re not scrambling to do basic security hygiene in the middle of an active attack.