Apple Threat Notification: How to protect against mercenary spyware
If you have recently received an Apple Threat Notification on your iPhone, iPad, or Mac follow these steps to protect your device.
First things first: If you’ve received an Apple threat notification follow these steps
If an Apple threat notification appears on your iPhone’s lockscreen, check that this notification is also present in your iPhone’s settings. Apple will also send an email notification to the email address you’ve linked to your Apple Account.
If you receive a genuine Apple threat notification on your iPhone it should appear as a notification sent to your lockscreen. You will also see a threat notification at the top of the settings page. Images: Apple.
If you have received these notifications, take immediate action by enabling lockdown mode and contacting the Digital Security Helpline.
Steps to enable lockdown mode on iPhone.
-
Enable Lockdown Mode by going to Settings > Privacy & Security > scroll down and click on Lockdown Mode > Click Turn on Lockdown Mode > scroll down and click on Turn on Lockdown Mode > Click Turn on & Restart > enter your password
-
Contact the Digital Security Helpline
Note: A genuine Apple threat notification will not ask you to click links, install apps, open files or profiles or provide your Apple account password or verification code by email or on the phone. To ensure that the threat notification is legit, you must log in to your Apple account where you should see a threat notification at the top of the page.
What are Apple threat notifications?
Apple threat notifications are notifications used to inform and help users who might have been targeted by a mercenary spyware attack.
Mercenary spyware is created by private firms and sold to governments and state-sponsored actors, allowing them to secretly access devices and surveil communications like phone calls, messages and emails. This kind of attack is highly sophisticated and extremely expensive, making it an advanced digital threat.
These types of attacks are individually targeted to high-profile people, usually based on who they are or what they do. For example, politicians, activists, and journalists.
As Apple has explained in a recent support article, “Apple threat notifications are high-confidence alerts that a user has been individually targeted by a mercenary spyware attack, and should be taken very seriously. We are unable to provide information about what causes us to issue threat notifications, as that may help mercenary spyware attackers adapt their behavior to evade detection in the future.”
Apple introduced this feature in 2021, and since then has notified users in 150 countries in total.
Cyber attacks are not needed for surveillance
In Apple’s support article on protecting against mercenary spyware, it notes that most Apple users will never be the target of such highly sophisticated attacks - which is fair - but what you might not realise is that you do not need to fall victim to a cyber attack to fall victim to surveillance. Individuals, governments and businesses are vulnerable to surveillance when they use Big Tech.
- Surveillance and control on a political level
When governments rely on tech providers, usually from the US, surveillance happens and the provider has the control. The perfect example of this can be seen in the case of Microsoft shutting down the Outlook Mail account of the Chief Prosecutor of the International Criminal Court (ICC), based in The Hague, Netherlands. Another example is Microsoft’s legal chief for France, M. Anton Carniaux, admitting that he cannot guarantee that the data of French citizens and businesses stored in Microsoft data centres, when located in Europe, is safe from the US quietly accessing the data. Just these two recent examples show the control and surveillance powers of Microsoft, and with that the need for digital sovereignty within the EU.
- Surveillance and control on the individual level
When you use services owned by tech giants like Meta, Google, or Microsoft, they make their profits from tracking, collecting, and selling your data to third-parties like advertizers who then target advertise. So the more Big Tech has access to, the better.
Even when you send an email using Gmail or Outlook, they have access. So while you might not fall victim to a mercenary spyware attack in which a high-profile person is spied on - you are already spied on by Big Tech, and they already have access to everything you do when using their services.
With this in mind, if you still use Big Tech providers for your communications like email and messenger, or cloud storage for storing confidential documents, you must consider switching to private alternatives that offer end-to-end encryption by default as this ensures that you and only you (and the intended recipient) can access the data.
Luckily, there are already excellent alternatives available!
- Replace Gmail or Outlook → Tuta Mail
- Replace Google Calendar or Outlook Calendar → Tuta Calendar
- Replace DropBox or Google Drive → Tuta Drive (Coming soon!)
Check out full guide on switching from Big Tech products
Receiving an Apple threat notification is unlikely, but surveillance is a given
So in the highly unlikely case that you do receive an Apple threat notification, you now know what steps to follow. And if you are concerned about threat notifications, you should actively take steps to stop Big Tech surveillance because that happens every time you use their products - you just don’t get a warning notification!