· via Hacker News – Front Page (native)
Apple now shows mercenary spyware threat alerts on the Lock Screen and in Settings
Apple's mercenary spyware warnings now appear directly on the Lock Screen and in Settings. Access Now explains what the alerts do and do not tell recipients, and what steps to take after one arrives.

Apple has changed how it warns people who may have been targeted by mercenary spyware. According to Access Now, whose explainer on the alerts surfaced on Hacker News' front page, threat notifications now appear directly on a device's Lock Screen and in Settings — a shift that began in September — instead of arriving only by email, iMessage or a banner inside users' Apple accounts. The goal, the organization says, is making the warnings harder to overlook.
What the alert actually tells you
An Apple threat notification means Apple detected activity on a device consistent with targeting by mercenary spyware: commercial surveillance technology of the kind sold by companies such as NSO Group, Paragon or Cytrox, often exclusively to government clients. It says little beyond that. As Access Now stresses, the alert does not reveal whether an attack succeeded, who is behind it or what the motive might be — answering those questions requires further analysis.
Treat it like a fire alarm
Access Now likens the notification to a fire alarm: it signals possible danger, but putting out the fire still requires the fire brigade. The first step is confirming the message is genuine, because scammers and phishers imitate these alerts. After that, the guidance is to seek expert support for a digital forensic investigation. Apple itself recommends that notified users enlist expert help, pointing specifically to the rapid-response assistance offered by Access Now's Digital Security Helpline, which serves journalists, activists and other civil-society users.
What forensics can and cannot prove
Forensics starts with preserving evidence quickly, since data that could reveal an intrusion is steadily overwritten while a phone or laptop stays powered on. Investigators then comb system files, logs and process histories — ideally touching as little personal content as possible — connect any traces to surrounding events such as travel, sensitive work or odd messages, and sometimes submit findings to peer organizations for independent confirmation.
A clean result is not an all-clear. Sophisticated spyware is designed to hide its traces, and competent investigators are frank about the limits of their methods; the absence of visible signs of compromise does not mean a device is safe.
The same skepticism applies to consumer security apps. Access Now argues that no single app or service can diagnose, prevent or mitigate every spyware attack: a "device is clean" verdict only means the tool found nothing matching the limited indicators it knows about. Leading spyware vendors test their products against popular detection tools before selling them, and consumer apps run sandboxed like any other app, leaving parts of the system they cannot inspect. Granting such an app broad permissions also hands its maker deep visibility into a user's life, so trust should determine which tools, if any, you use.
Practical steps after an alert
For recipients of an authentic notification — from Apple, or comparable warnings from WhatsApp, Facebook or Google — Access Now advises following the security recommendations in the message and then getting expert help to assess and contain the incident. Backing up the affected device can preserve evidence for later analysis, and victims of criminal attacks may consider reporting to authorities, though Access Now recommends consulting a lawyer first to judge whether that is safe.
On prevention, the basics carry most of the weight: install updates promptly, switch on high-security modes such as Apple's Lockdown Mode or Google's Advanced Protection on Pixel devices, tighten WhatsApp's account settings, keep separate devices for work and personal life, and reduce the number of apps and accounts on each one.
Why it matters
Moving these alerts onto the Lock Screen and into Settings is a small interface change with significant consequences for the small population that receives them. Warnings delivered by email or iMessage are easy to miss, filter out or fake; a persistent notice on the device itself is far more likely to reach the person who needs it. But as Access Now makes clear, the notification is only the alarm. Whether it changes the outcome depends on access to genuine forensic expertise — and on users resisting the false comfort of a one-tap scan that promises a clean bill of health.
- #apple
- #security
- #spyware
- #privacy
- #ios