Secretus logo

Apple Spyware Threat Notification: What to Do Before You Rotate Secrets

·9 min read

Apple sent a new round of mercenary-spyware threat notifications on August 13, telling TechCrunch that the warnings reached targeted users in 110 countries. Apple's updated support guidance describes these notifications as high-confidence alerts that a person has been individually targeted. They should be treated as a real security incident, even though an alert does not by itself prove that the device was successfully compromised.

The first response should not be to click through an email, start changing every password on the warned iPhone or paste the alert into an ordinary work chat. Verify the warning independently, enable Apple's protective controls, preserve evidence and move sensitive recovery work to a separate device that is not part of the suspected compromise.

What Apple confirms

Apple updated its threat-notification guidance on August 13, 2026. The company says these alerts are designed for people who may have been individually targeted by highly sophisticated mercenary spyware, often because of who they are or what they do. Apple names journalists, activists, politicians and diplomats as frequent categories of target, while emphasizing that the vast majority of users will never face this type of attack.

Apple says it relies on internal threat intelligence and investigations. The company cannot achieve absolute certainty, but calls the alerts high confidence. Since 2021, it has issued them several times a year and has notified users in more than 150 countries in total. Apple does not attribute a notification to a particular attacker or country and withholds the detection details so spyware operators cannot adapt to evade them.

What is reported about the August 2026 notification wave

TechCrunch reports that Apple sent the latest batch on Thursday, August 13, to targeted users in 110 countries. Apple did not disclose how many people received an alert, which countries were included, what spyware family may have been involved or whether any device was successfully infected. The Hacker News also covered the notification wave, citing TechCrunch for the 110-country figure.

That sourcing matters: 110 is the geographic reach Apple provided to TechCrunch, not a count of victims, infections or compromised devices. A notified user was targeted with activity that Apple associates with mercenary spyware; determining what happened on the device requires expert and potentially forensic analysis.

How a genuine Apple threat notification appears

Apple's current guidance says an alert can appear directly on the iPhone Lock Screen and in Settings. Apple also sends an email to addresses associated with the user's Apple Account, and displays a banner at the top of the account page after sign-in.

A genuine Apple threat notification will never ask you to click a link, open a file, install an app or configuration profile, or disclose an Apple Account password or verification code by email or phone. Instead of trusting a link inside a message, enter account.apple.com yourself. If Apple issued the notification, the banner will be visible after you sign in.

What to do in the first hour

  1. Move to a separate, trusted device. Use it to read official guidance, contact help and coordinate the response. Avoid discussing sensitive details or opening new secrets on the warned device.
  2. Verify the notification independently. Type account.apple.com into the browser yourself and check for the threat-notification banner. Do not provide credentials to anyone who calls or messages about the alert.
  3. Update supported Apple devices. Apple and Access Now recommend installing the latest operating-system security updates.
  4. Enable Lockdown Mode. Apple recommends this optional, extreme protection for people facing highly sophisticated targeted attacks. For complete coverage, Apple says to update and enable it separately across supported iPhone, iPad and Mac devices.
  5. Ask for expert help. Apple specifically directs notified users to Access Now's Digital Security Helpline. Its mandate focuses on civil-society groups, journalists, activists and human-rights defenders; other users should seek a qualified incident-response specialist.
  6. Preserve potential evidence. Access Now advises recipients not to erase the device immediately, because erasure may not prevent reinfection and can destroy useful evidence. Coordinate backup and forensic steps with the expert assisting you.

Do not rotate secrets on the suspected device

A password change is useful only if the new value is created and used outside the attacker's view. If spyware controls the device, it may capture the replacement password, session token, recovery code or private conversation as soon as it appears on screen. Changing credentials from the warned iPhone can therefore hand the attacker the new keys.

From a clean device, prioritize the Apple Account, primary email, password manager, communications accounts, cloud storage, financial access and any work identity the target used. Review trusted devices and active sessions, revoke access where appropriate, replace recovery codes and move away from SMS-based recovery when stronger options are available. Coordinate the order with an expert so account changes do not destroy evidence or alert an active operator before the investigation is ready.

Separate incident coordination from secret delivery

Targeted spyware can turn the victim's normal communication device into part of the incident boundary. A work chat, email thread or call on that device may reveal who is helping, what accounts are being changed and where the target plans to go next. Establish an alternate contact method from a clean endpoint and verify every participant before discussing sensitive response details.

  • Keep the incident channel for assignments and status, not passwords or recovery codes.
  • Use temporary, scoped credentials instead of disclosing permanent administrator access.
  • Record who authorized a credential change and when it was completed, without copying the secret into the case notes.
  • Assume secrets displayed or typed on the suspected device may need replacement.
  • Do not send forensic files or device backups through an ad-hoc secret-sharing service; use the evidence-handling process defined by the response team.

Where Secretus fits—and where it does not

Secretus can help an authorized responder transfer a temporary password, token or recovery code without leaving the plaintext in an email or chat transcript. A short-lived, one-time Standard Mode link can reduce persistent copies, while Team Split can support a pre-planned multi-person release process.

Secretus cannot detect or remove mercenary spyware, verify that an Apple notification is genuine, preserve forensic evidence or make a compromised endpoint safe. If the link is opened on the targeted device, spyware may capture the revealed value. Use Secretus only from independently trusted endpoints, after recipient verification, and rotate the transferred credential when the response task ends.

What remains unknown

Apple has not disclosed the number or identities of recipients in the latest wave, the countries involved, the spyware vendor, exploit chain, operator or success rate. The alert indicates high-confidence targeting, not confirmed infection. Avoid attributing it to Pegasus, a government or any named company without evidence from the individual forensic investigation or a subsequent authoritative disclosure.

Sources

Share a secret the safe way

Start a 14-day trial to send; recipients open one-time links without an account.

Try Secretus