Apple threat notifications and spyware: what everyone should know

Since 2001, Apple has been warning its users when they may have been targeted by spyware, using email, iMessage, and banners in their accounts. But in September of this year, the company began to place these threat notifications directly in users’ device Lock Screen and Settings — making them harder to miss. Here’s what you need to know about Apple threat notifications and spyware attacks in general, and what they mean for your digital security.

Put simply, that Apple detected activity in your device signalling that you have been targeted  with so-called mercenary spyware, that is, the sophisticated commercial surveillance technology that is sold by companies like NSO Group, Paragon, or Cytrox, often exclusively to government clients.

This alert does not tell you whether or not the spyware attack succeeded, nor does it provide information about who might be behind the attack or what their motives may be. Further analysis is required for you to see a clearer picture.

A threat notification is like a fire alarm; it draws your attention to the possibility of danger, but you still need the fire brigade. If you have received an authentic Apple threat notification, you should immediately seek expert support from trusted professionals or organizations who can help you conduct a digital forensic investigation. Be careful, however, to ensure that the message is authentic to avoid scams or phishing

A forensic investigation process takes time, but it will help you better assess and take control of the situation. 

If you are a member of civil society, such as an activist, journalist, or human rights defender, you can contact Access Now’s Digital Security Helpline to get more tailored advice. As Apple says, “we strongly suggest notified users enlist expert help, such as the rapid-response emergency security assistance provided by the Digital Security Helpline at the nonprofit Access Now.”

When dealing with a spyware attack, it is important to preserve the evidence that a spyware attack or attempt may have left in your device as soon as possible. Time is of the essence, as data is being overwritten every minute that a phone or laptop stays on. Investigators would work with you to preserve that evidence.

Next, investigators would often search system files, logs, and process histories for traces of spyware. Data should be collected in such a way as to minimize, as much as possible, the amount of sensitive data and content that is accessed, such as your personal photos, contacts, or communications. If traces are found, investigators would typically contextualize these findings by connecting them to circumstances and life events surrounding the dates of the traces, including potential travel, sensitive work or conversations, or suspicious messages or device activity. Please note, however, that a lot of sophisticated spyware attacks may not be associated with anything suspicious that you can observe; the lack of obvious signs of an attack does not mean you are safe.

In addition, investigators may also try to test their own findings by submitting their work to peer organizations for an independent analysis. This practice helps solidify and confirm the validity of an investigation’s findings or identify areas where further research may be needed.

Not necessarily.

A good investigator may not always be able to find evidence to identify a spyware infection, nor can they always find a solution for mitigating the threat, but they are always conscious of their own limitations. In some cases, they may be able to suggest other methodologies or techniques for identifying and preventing spyware, but they rarely issue a blanket statement or guarantee that you are fully safe. That is for good reason; spyware evolves quickly, and it is designed to hide its traces.

The short answer is that no single app or service will diagnose, prevent, or mitigate all spyware attacks. You may see ads for digital tools that scan your phone and tell you that your “device is clean,” but what they are actually telling you is that they did not find anything on your device that matches the small set of indicators that they know about. 

It’s important not to let such seemingly “easy” solutions give you a false sense of security, especially if they lead you to neglect taking simple, but important steps that can significantly help you protect yourself from spyware and other threats.

It depends. Some services can help you detect some forms of surveillance technology, and that can be useful. For example, they can flag known spyware, or nudge you to take certain security measures, like running a system update. 

That said, you should understand that these services also tend to downplay their limitations, which in the case of a serious spyware infection could matter more than their capacities. The leading mercenary spyware vendors test their products against popular detection tools before selling them, because staying invisible is their primary selling point. Security apps available to consumers will not be able to scan your entire device, either, as they operate under restrictions similar to those of any other app. They may therefore fail to inspect the parts of your system where dangerous spyware may be lodged. 

You should also understand that if you choose to use a security app or service, it’s critically important that you choose wisely. When you download an app and give it authorization to examine your device, you’re giving the company behind it access to a detailed portrait of your life. If you don’t know and trust the organization or company behind the app or other tool you are using, you should not use the service at all.

Again, if you have received an authentic Apple threat notification or similar alert from WhatsApp, Facebook, or Google, you should follow the security recommendations in the notification message. As we note above, you should first ensure the message is authentic to avoid scams or phishing

Once you’ve verified the authenticity of the alert, you should also seek expert help to conduct a forensic investigation to assess the type of attack you may have faced. A trusted technologist or organization can also help you take measures to contain the threat and regain control. If you suspect that you may be a victim of a criminal cyber attack, you may also consider reporting the incident to a relevant governmental authority or specialized agency; however, we strongly recommend consulting with an attorney to help you determine if it’s safe to do so. 

Even if you cannot immediately get your device tested for spyware, you may wish to preserve the potential evidence of attack for future investigations by making a backup of the affected device. 

For anyone interested in preventing a spyware attack, a few simple steps can go a long way: install all your updates promptly, and enable high-security settings like Lockdown Mode or, if you have a Pixel device, Google’s Advanced Protection. WhatsApp also offers Strict Account Settings to increase your protection. You should also minimize your attack surface by keeping separate devices for your personal and work life, and by reducing the number of apps and accounts that you keep in your device. 

That said, let’s be real. Security is never a state that you reach, but a practice that you keep. Everyone’s threat profile is unique, and you may benefit from a personalized assessment and ongoing education to stay aware of emerging threats. In other words, while a threat notification or a security app may be useful, you should strive to remain alert, take note if you see or experience anything odd, and always seek trusted support when you need it.