An alert wave unlike any before it
On 13 August 2026, Apple sent threat notifications to iPhone users in 110 countries warning them they may have been individually targeted by mercenary spyware. Citizen Lab senior researcher John Scott-Railton called the scale and geographic spread "pretty unprecedented," noting that for every public report of a notification, "there's a huge notification iceberg the public will never learn about" (Citizen Lab). Access Now's Digital Security Helpline reported 30-40% more requests for assistance than after previous alert rounds (TechCrunch). For the first time, Apple pushed some of the warnings via lock-screen alerts, not just email and in-app notices — a design choice that turns a private security notice into something the target's household, colleagues, or a border agent scrolling past a locked phone might also see.
Apple has run this program since late 2021 and has now notified customers in over 150 countries total, describing the threats as coming from "extreme cost, sophistication, and worldwide" mercenary spyware operators it declines to attribute to any government or region (The Hacker News). That neutrality is deliberate: Apple's targets are typically journalists, activists, politicians, and diplomats, and naming a suspected state client risks turning a security feature into a diplomatic incident.
The steelman for a harder line
Digital rights groups have a genuinely strong case here, and it deserves to be stated plainly before it's argued against. The European Parliament's PEGA Committee of Inquiry — after 215 interviews and fact-finding missions to Israel, Poland, Greece, Cyprus, and Hungary — found in its 2023 report that Pegasus and similar tools had been used to illegally monitor journalists, lawyers, and opposition politicians in at least four EU member states, calling it a genuine "threat to democracy" (European Parliament). The Committee didn't recommend a blanket ban; it called for EU-wide rules limiting spyware to judicially authorized, narrowly defined cases, mandatory notification to targets, and a common definition of "national security" so the term stops functioning as a blank check. That is a reasonable, proportionate ask — the kind of framework this publication would normally endorse over prohibition. If a wave this size is still getting through in 2026, three years after PEGA, the honest conclusion is that voluntary export discipline and patchwork national rules have not caught up with the market.
Where the deterrence actually broke down
The clearest test of accountability to date is WhatsApp v. NSO Group. A federal jury found NSO liable in May 2025 and awarded $167 million in punitive damages over the 2019 hacking of roughly 1,400 WhatsApp users, including journalists and activists (Amnesty International). In October 2025, Judge Phyllis Hamilton of the Northern District of California made the injunction against targeting WhatsApp users permanent — but cut the punitive damages to just $4 million, a 97% reduction, citing insufficient legal precedent for treating spyware harms as comparably severe to other punitive-damages cases (CyberScoop). NSO is appealing anyway.
That outcome is the real story behind Apple's growing alert volume. A permanent injunction protects one platform's users going forward; it does nothing to the spyware vendor's ability to sell to a different government, target a different app, or simply wait out an appeal. A $4 million penalty is a rounding error against contracts that run into tens of millions per client. Litigation is proving good at establishing liability and bad at imposing a cost that changes vendor behavior — which is exactly why detection-side tools like Apple's notifications, not courtroom damages, are absorbing the load.
The proportionate path is export control, not device bans
The policy lesson isn't that platform hardening has failed — Apple says it has never seen a device compromised while Lockdown Mode was active, which is a strong argument for expanding that feature's visibility and default availability rather than treating it as a niche setting. The lesson is that the enforcement gap sits upstream, at the point of sale and export, not downstream at the point of detection. PEGA's recommended EU regulation, a binding definition of qualifying end uses, and licensing review of export hubs like Cyprus would do more to shrink the spyware market than any number of after-the-fact lawsuits. Courts can bankrupt one vendor at a time years after the harm; export controls and procurement bans can foreclose a sale before it happens.
None of this justifies treating commercial intercept tools as categorically illegitimate — states have lawful, narrow uses for targeted intrusion against genuine terrorism and organized-crime suspects under judicial warrant, and a blanket prohibition would simply push that capability to less accountable, non-Western vendors. But a regime where the deterrent effect of a landmark U.S. jury verdict evaporates to $4 million on appeal, while a single Apple alert wave reaches 110 countries in one week, is not a functioning market discipline. Apple's notifications are working. The question policymakers in Brussels, Washington, and beyond still haven't answered is what happens before the alert has to go out at all.