Israel Israel NSO Group Pegasus surveillance policy

Apple's Unattributed Spyware Alerts Expose the Missing Feedback Loop in Israel's Export Licensing

Apple's alerts reached users in 110 countries and name no vendor. Israel's licensing regime has no formal way to act on such evidence. Fix that, don't ban the sector.

Mercenary spyware alerts vs. Israel's export licensi… People of Internet Research · Israel 150+ Countries notified by Apple Cumulative total since Apple began… 110 Countries in Aug 13 wave Apple named no vendor or country. 18 → 6 Firms applying for DECA permits Applicants fell between 2021 and 2… peopleofinternet.com
Mercenary spyware alerts vs. Israel's … People of Internet Research · Israel 150+ Countries notified by Apple 110 Countries in Aug 13 wave 18 → 6 Firms applying for DECA permits peopleofinternet.com

Key Takeaways

On August 13, 2026, Apple sent a new batch of threat notifications to users in 110 countries, and for the first time it also showed the warning on the iPhone lock screen. Apple says it has now notified users in more than 150 countries in total. It also says it "does not attribute the attacks or resulting threat notifications to any specific attackers or geographical regions." No vendor is named in the alerts, and none of the coverage we reviewed ties this wave to an Israeli company.

That absence is the policy story. Israel is where the best-known mercenary spyware originates, and its Defense Ministry is the licensor of that trade. Apple's alerts are the largest body of evidence anyone has about where the trade ends up. They currently feed nothing into Israel's licensing decisions.

The strongest case for the current regime

Israel's defenders have a real argument. Defense exports there run under the Defense Export Control Law, which took effect at the end of 2007. Its regulator, the Defense Export Controls Agency (DECA), lists human-rights considerations among its decision criteria on the Ministry of Defense's DECA page. In December 2021 the agency tightened its end-user declaration for cyber and intelligence products. Buyers must limit use to investigating and preventing serious crime and terrorism, and the declaration names sanctions for breaches, including restricting or shutting down the system, according to Defence Connect's report of the announcement.

The tightening has had measurable effects. Ctech reported that 18 Israeli companies applied for DECA cyber export permits in 2021 and only 6 in 2022, and that export markets fell from more than 100 countries to fewer than 40. An industry source told the outlet that permits were once "handed out generously" and had turned into "real stinginess". Read Ctech's account of the licensing squeeze as evidence that licensing is not a rubber stamp.

Where the system still leaks

The pressure that produced this tightening came from outside Israel. On November 4, 2021, the US Commerce Department added NSO Group and Candiru to its Entity List. It cited evidence that they "developed and supplied spyware to foreign governments that used these tools to maliciously target government officials, journalists, businesspeople, activists, academics, and embassy workers," per the Bureau of Industry and Security announcement. Israel's own regime has no comparable, publicly documented trigger that turns evidence of abuse into a revoked licence.

Amnesty International's Security Lab published "Inside Pegasus" on July 16, 2026, based on NSO documents that entered the public record in the WhatsApp and Meta case against NSO. Its most relevant passage describes how the product is licensed. Each deployment is bound by limits on the number of targets, the number of simultaneous infections and the countries that may be targeted. A customer can add countries "subject to approval by NSO Group and most likely the relevant export authority." The same report notes that certain countries, such as the United States and Israel, are barred for most customers, but that "this is a policy rather than a technical limitation." In Amnesty's analysis, controls that rest on policy have to be enforced by someone.

The design creates a gap. A licence is granted at the point of sale, and abuse surfaces years later in forensic reports, court filings and, now, platform alerts. Apple describes its notifications as high-confidence and says it withholds its detection methods so attackers cannot adapt, which is a reasonable choice. But the result is that a licensor watching the alerts learns only that mercenary spyware is active somewhere. It cannot tell whether any Israeli-licensed system is involved.

We should also be clear about what this article does not claim. Apple's alerts do not implicate Israel, NSO or any named company. The alerts are consistent with a global market that includes many vendors. The Israeli-specific accountability question is an inference about system design, not a finding about this wave.

Proportionate fixes, not a ban

Our position favours a free press, open security research and a competitive cyber sector. That rules out both extremes. Blanket bans would push capability into unlicensed jurisdictions, where there is no end-user declaration and no shutdown clause. Doing nothing leaves journalists and activists exposed to tools that Apple says cost millions of dollars per campaign and are aimed at "a very small number of specific individuals."

A narrower package would fit the evidence:

None of this needs a new statute. Most of it can be done through DECA's existing licence conditions and reporting.

What to watch

Apple's policy of not attributing alerts is defensible, since attribution errors carry costs and detection methods stay secret. It also means the pressure to close the loop has to come from licensors. Israel tightened once under US sanction threat. The better course is to build the review mechanism itself and publish how it works, before the next round of alerts arrives.

Sources & Citations

  1. Apple Support: threat notifications and mercenary spyware
  2. Israel Ministry of Defense: DECA
  3. US Commerce BIS: NSO Group and Candiru added to Entity List
  4. Amnesty Security Lab: Inside Pegasus
  5. Ctech: Is Israeli spyware a dying sector?
  6. BleepingComputer: Apple's new Threat Notification alerts
  7. Defence Connect: DECA tightens cyber export restrictions