An Apple threat notification is not a routine security warning. Apple issues these high-confidence alerts when its threat intelligence indicates that someone may have been individually targeted by sophisticated mercenary spyware.
Receiving an alert does not necessarily mean that the spyware successfully infected the device. It also does not identify the spyware operator or explain why the person was targeted. However, Apple says recipients should take the warning seriously and obtain expert assistance.
Attackers may impersonate Apple and use spyware concerns to steal passwords or verification codes. Recipients should therefore confirm the notification before following any instructions.
Apple threat notifications may appear:
On an iPhone’s Lock Screen.
Inside the iPhone’s Settings application.
In an email sent to an address associated with the Apple Account.
As a banner at the top of the Apple Account website.
Instead of following a link inside an email or message, manually enter account.apple.com into a browser and sign in. A genuine notification will be displayed prominently at the top of the account page.
Apple says its threat notifications will never ask recipients to click a link, open a file, install an application or configuration profile, or disclose their Apple Account password or verification code.
Any communication making these requests should be treated as a possible phishing attempt.
Apple describes its threat notifications as high-confidence warnings that a user may have been individually targeted by mercenary spyware.
These attacks are significantly more sophisticated than ordinary cybercrime. They frequently involve commercial surveillance tools developed for highly targeted operations against a small number of individuals.
Journalists, activists, politicians, diplomats and human-rights defenders have historically been among those targeted. Nevertheless, the notification alone does not prove that a device was successfully compromised.
A forensic investigation may be required to determine whether an attempted infection succeeded and what information may have been exposed.
Recipients should not immediately erase or factory-reset the affected device. Resetting it may remove forensic evidence that investigators could use to identify an attempted or successful compromise.
Access Now recommends preserving the device and creating a backup when an immediate forensic examination is unavailable. Because information stored in system logs can be overwritten over time, expert assistance should be requested as quickly as possible.
Apple directs notified users to Access Now’s Digital Security Helpline, which provides emergency assistance to eligible civil-society groups, including independent journalists, activists and human-rights defenders.
People outside the organization’s support mandate should contact a trusted cybersecurity professional with experience in mobile-device forensics.
The appropriate order of forensic preservation and security changes may depend on the individual case. When possible, recipients should coordinate these actions with a qualified investigator.
Apple and Access Now recommend the following protective measures:
Update the iPhone and other Apple devices to the latest available software.
Enable Lockdown Mode on supported devices.
Use a strong, unique Apple Account password.
Confirm that two-factor authentication is enabled.
Review the devices connected to the Apple Account and remove anything unfamiliar.
Enable Stolen Device Protection.
Install applications only from the App Store.
Avoid links and attachments from unknown senders.
Apple recommends updating devices before enabling Lockdown Mode to obtain the complete set of available protections.
On an iPhone, Lockdown Mode can be activated under Settings > Privacy & Security > Lockdown Mode. It restricts certain applications, websites, invitations, attachments and device connections to reduce the attack surface available to highly targeted spyware.
Lockdown Mode must be enabled separately on an iPhone, iPad and Mac. Enabling it on an iPhone automatically activates it on a paired Apple Watch.
A consumer security application reporting that a device is clean does not prove that no compromise occurred. Mobile security applications have limited access to protected areas of the operating system, while sophisticated spyware is specifically designed to avoid detection.
The absence of unusual battery consumption, unexpected applications or suspicious messages also cannot establish that a device is safe. Some advanced spyware attacks require little or no interaction from the target and may leave few visible symptoms.
A person who receives a legitimate threat notification may subsequently encounter fraudulent messages from criminals claiming to offer Apple support or spyware-removal services.
Recipients should never provide passwords, device passcodes or two-factor authentication codes to an unsolicited caller. CySecurity.news has separately reported how fake Apple Support agents target device owners using phishing messages and AI-generated voice calls.
Apple has sent threat notifications to users in more than 150 countries since 2021. Although most people will never receive one, anyone who does should verify it directly, preserve potential evidence, obtain expert assistance and take immediate steps to strengthen the security of every connected device.
A new investigation by the digital rights research group Citizen Lab has revealed how weaknesses inside global telecom infrastructure were allegedly exploited to secretly monitor mobile phone users in more than ten countries over the past three years.
The findings, reviewed by Haaretz, highlight how parts of the global mobile network system, originally developed decades before smartphones existed, continue to expose users to modern surveillance risks despite the arrival of 4G and 5G technologies.
According to the report, researchers uncovered two separate surveillance operations that appear to be linked to commercial spyware and cyber intelligence vendors selling tracking capabilities to government clients worldwide. One of the operations reportedly used telecom infrastructure connected to Israeli providers 019Mobile and Partner Communications, although both companies denied involvement.
Researchers say the operations relied on weaknesses in SS7, an older telecom signaling protocol used globally to route phone calls, text messages, and roaming traffic between mobile operators. SS7 was designed during a period when telecom networks trusted one another by default, long before today’s cybersecurity threats emerged. Security experts have warned for years that attackers can abuse the protocol to monitor phone activity, intercept communications, or identify a user’s location.
The report states that some surveillance firms were able to impersonate legitimate mobile carriers and gain access to these legacy telecom systems in order to track users internationally. A second operation was reportedly linked to Fink Telecom Services, a Swiss company previously named in a 2023 investigation by Haaretz and Lighthouse Reports involving telecom surveillance services supplied to cyber intelligence vendors, including Rayzone.
Last week, British regulators reportedly moved to ban similar telecom signaling abuse practices, describing them as a major source of malicious activity affecting mobile networks. However, the new findings suggest that even newer systems built for 4G and 5G communications are vulnerable to similar exploitation.
One example highlighted in the report is Diameter, a signaling protocol widely used in 4G roaming and many 5G environments to manage subscriber connectivity and authentication. Although Diameter was introduced with stronger security protections than SS7, researchers found that attackers are still capable of abusing the system to conduct tracking operations.
In the first campaign identified by Citizen Lab, researchers documented more than 500 location-tracking attempts between November 2022 and 2025 across countries including Thailand, Bangladesh, Norway, Malaysia, South Africa, and several African nations. The investigation reportedly began after researchers observed a Middle Eastern businessman being repeatedly tracked over a four-hour period through international telecom queries.
Citizen Lab found that telecom identifiers associated with 019Mobile were used to send location-tracking requests through infrastructure connected to Partner Communications, which supports 019Mobile’s services. Another network route reportedly passed through Exelera Telecom, a communications and cloud services provider that also manages international fiber-optic infrastructure. Exelera did not publicly respond to requests for comment.
019Mobile’s head of security denied involvement and stated that the company operates as a virtual provider using another carrier’s infrastructure rather than maintaining its own roaming agreements. Researchers noted that attackers may have forged the company’s telecom identity to access the network.
Although Citizen Lab did not publicly identify the companies behind the operations, the report referenced several possible actors, including Cognyte. Internal files reviewed by Haaretz reportedly showed that Cognyte’s former parent company, Verint Systems, sold an SS7-based tracking product called SkyLock to a government customer in the Democratic Republic of Congo.
According to the report, SkyLock could reportedly locate mobile devices globally by exploiting telecom roaming systems. The documents also pointed to commercial relationships with telecom operators in Thailand, Malaysia, Indonesia, Vietnam, and Congo, several of which overlap with countries mentioned in the surveillance campaign.
Researchers also uncovered a more advanced surveillance method known as SIMjacking. The technique exploits vulnerabilities inside SIM cards by sending hidden binary text messages containing secret instructions. Once received, the SIM card can silently transmit the device’s location back to the attacker without displaying any visible warning or notification to the user.
Citizen Lab identified more than 15,700 suspected SIMjacking-related tracking attempts since late 2022. Researchers noted that when Haaretz and Lighthouse Reports first exposed Fink Telecom Services in 2023, the company had not yet been linked to the SIMjacking technique.
Cybersecurity experts warn that these attacks are especially concerning because they target weaknesses within telecom infrastructure itself rather than requiring malware installation or phishing attacks on individual devices. Researchers also cautioned that many telecom providers continue operating old and new signaling systems together, creating additional opportunities for attackers to bypass modern protections.
Fink Telecom Services, Exelera Telecom, Verint, and Cognyte did not publicly respond to the allegations referenced in the report. Partner Communications stated that it had no connection to the incident and rejected attempts to associate the company with the activity described by researchers.