Apple's Threat Notification: What to Do in the First Hour
Key Intel / TL;DR
  • Apple sent mercenary spyware threat notifications to users in 110 countries on August 13, part of a program running since 2021 that has reached more than 150 countries.
  • Apple calls these high-confidence alerts that a person was individually targeted, which means somebody selected a name rather than scanning a range.
  • The historical target set was journalists, activists, politicians, and diplomats, and that set now overlaps with executives in litigation, acquisitions, and government contracting.
  • Do not factory reset the device. A wipe destroys the only copy of the evidence that would tell you who and why.
  • The device is almost always personal, which is why most corporate incident response plans have no first step for this.

Picture the notification arriving while you are in an airport lounge, somewhere in the twenty minutes between boarding groups. It tells you that someone has targeted your device with mercenary spyware. Your first instinct will be to do something to the phone right now.

That instinct is the expensive one.

On August 13, Apple sent a fresh round of threat notifications to users across 110 countries. The company has run the program since 2021, sends alerts multiple times a year, and has now reached people in more than 150 countries. Apple describes these as high-confidence alerts that a user has been individually targeted, and says they should be taken very seriously (BleepingComputer).

Individually targeted is the phrase that carries the weight.

What the Word “Individually” Actually Costs

Most of what hits your users is priced for volume. A phishing campaign goes out to 40,000 addresses because the per-message cost rounds to zero, and the operator only needs a fraction of a percent to convert. Nobody chose you. You were in a range.

Mercenary spyware inverts that math. These are commercial products licensed to government customers, and the reporting on what they cost is public. A leaked NSO Group price list from 2016 put Pegasus at $650,000 to reach 10 phones, on top of a $500,000 installation fee and annual maintenance at 17% of the total (Deccan Herald). That is $65,000 a target before the operator has done any work, on a decade-old price list, for a generation of the product that predates the zero-click chains in use now.

To put that in perspective, somebody signed off on more per phone than most companies spend on their entire annual security awareness program. When a buyer commits that, they are not fishing.

Think of it as the difference between a thief walking a parking garage pulling door handles and a thief who arrives already knowing your plate number. The first one is a volume business and your defense is to be less convenient than the car beside you. The second already made the decision at a desk somewhere before he got out of the vehicle, and being slightly harder than average does nothing.

The notification means you got the second one.

Why Business Readers File This Under Somebody Else

Apple’s own framing names the historical target set: journalists, activists, politicians, and diplomats. Every executive who reads that list concludes, reasonably, that it does not describe them.

Now put yourself in the shoes of the person buying the license. The customer is a government, and governments have commercial interests. Consider who ends up adjacent to that set without ever thinking of themselves as a target:

  • An executive at a company in active litigation with a state-owned enterprise.
  • The deal team on an acquisition that a foreign ministry would rather not see close.
  • Anyone at a supplier holding a defense, energy, or telecommunications contract.
  • The general counsel or outside counsel on any of the above, who holds the same information with a fraction of the security program.
  • A board member who also sits on the board of something political.

None of those people describe themselves as activists. All of them hold something a state customer would pay a per-target fee to read.

The First Hour

The common reactions are the ones that cost you the most, so take them in order.

Do not factory reset the device

This is the instinct and it is wrong. A wipe removes the implant and it removes every trace of the implant at the same time. You lose the ability to establish what was taken, when the access started, whether it reached your mail, and which of your accounts were exposed while it ran.

Weigh what the reset buys against what it costs. It gets you a clean phone, which you could also get by picking up a different phone. It costs the only copy of the evidence, and nothing replaces that.

The forensic record on the device is the only artifact that answers the questions your legal team, your insurer, and your regulator are going to ask in about three weeks.

Stop using the device, but leave it powered on

Set it down and pick up something else. Do not log into accounts from it, do not change passwords on it, and do not use it to read the notification a second time. Every credential you touch on a compromised device is a credential you have handed over fresh.

Leaving it powered on preserves volatile state that a forensic examiner can work with. Powering it down or letting it die throws away part of the record. Put it in airplane mode if you need to stop it talking, and hand it to somebody qualified.

Change credentials from a different device

Start with the account that controls the others: the Apple ID itself, then mail, then anything holding financial or legal authority. Do this from a machine that was never in scope, and enable a hardware security key where the account supports one.

The order matters. Resetting your mail password from a phone that is still compromised is a rotation the attacker watches you perform.

Verify the threat notification independently

Somebody will try to phish people with a fake version of this alert, because the panic it creates is exactly the emotional state a social engineer wants. Do not act on links or attachments inside the message. Sign into your Apple account directly, in a browser you opened yourself, and confirm the notification exists there.

Call in help before you improvise

Apple’s own guidance is to enable Lockdown Mode, keep the device updated, and consult a security expert. Lockdown Mode is a real control and it is worth turning on. It is also a forward-looking control that does nothing about an implant already resident, so treat it as the fix and not the investigation.

The Program Gap Nobody Has Closed

Notice what is true about every device we have been discussing. It belongs to the person, not the company.

Mercenary spyware goes after the phone in someone’s pocket, because that is where the messages, the location history, the microphone, and the camera live. Corporate mobile device management may or may not touch it. Your endpoint detection tooling certainly does not. Your logging captures nothing.

This is the same structural blind spot behind vishing campaigns that call the phone your policy does not cover, and it produces the same result. The attack lands in the one place where the organization has spent nothing, has no visibility, and has no authority to act.

So the practical question for a security leader is not whether to buy something. It is whether anybody in your organization knows what to do in the first hour, on a device you do not own, belonging to a person who does not report to you.

Three things to settle before you need them

  1. Name the phone call. Decide now who an executive contacts when this arrives, and make sure that person can reach a forensics capability the same day. A number in a policy nobody has dialed is not a plan.
  2. Write down the do-not-wipe instruction and give it to the people most likely to receive one. The instinct to reset is universal, it happens in the first ten minutes, and a single sentence delivered in advance is what prevents it.
  3. Decide in advance who gets a loaner. The executive needs a working phone within the hour or they will keep using the compromised one. Have a provisioned device available rather than discovering the gap during the incident.

Each of those is a decision written down before the day it is needed, which makes them the cheapest controls in this article and the ones most organizations skip. Our incident response planning guide covers the broader version of this, and executive protection as a converged discipline covers why the personal and corporate halves cannot be run separately.

If You Got One

Somebody spent real money to read your messages, and they picked your name off a list to do it. That is unpleasant information and it is also useful, because it tells you the value of what you are carrying is higher than you had been treating it.

Set the phone down. Make the call. The evidence on that device has a shelf life, and the reset button does not have an undo.


Do your executives know who to call in the first hour? Contact Grab The Axe for an executive protection and device exposure assessment, or start with our free Human Attack Surface Score.

Distribute Intel
Chris Armour
Director of Information Security
Chris Armour
The Breaker & Builder.

Operating on the philosophy that 'you can't build a secure system if you don't know how to break it,' Chris leads our engineering division. A top 1% National Cyber League competitor, he hardens our digital infrastructure against the very exploits he has mastered.

View Author Page →