Skip to content

Timeline of Apple's Threat Notifications

Posted on:November 7, 2023 at 06:50 PM

What are Apple Threat Notifications?

Since November 2021, Apple has been actively issuing threat notifications to alert users who may be targets of state-sponsored attackers due to their identity or activities. These warnings are sent via email and iMessage to the contacts associated with the user’s Apple ID. The alerts inform users of potential unauthorized access to sensitive data or the possibility of their device’s camera or microphone being remotely activated. Apple advises those who receive these notifications to update their devices to the latest iOS version and to enable Lockdown Mode for added security.

How does Apple detect state-sponsored attacks?

The specifics of how Apple detects these state-sponsored attacks are largely undisclosed. Apple maintains that its detection methods are kept confidential to hinder attackers from modifying their strategies to evade discovery. However, we do know that victims have recieved threat notifications shortly after Citizen Lab has sent over the exploit chains to Apple:

We shared our observations of these exploit chains with Apple in October 2022 and in January 2023. Targets we found in the 2022 target pool reported receiving notifications from Apple in November and December 2022, and March 2023.

It is probable that Apple detects these intrusions by monitoring for atypical behavior patterns that align with known exploits, using analytics uploaded from devices to identify potential targets.

I am committed to keeping a close watch on these threat notifications and aim to maintain an up-to-date record of occurrences. If you have information regarding additional threat notifications from Apple and would like to contribute, please email me.

November 2021

In the aftermath of Citizen Lab’s revelation of the FORCEDENTRY exploit in September 2021, Apple took a firm stance against NSO Group, the entity behind the exploit. Apple’s legal action against NSO Group was complemented by a $10 million commitment to support cybersurveillance research and advocacy organizations. Moreover, Apple pledged to notify affected users of any activities consistent with state-sponsored spyware attacks, aligning with industry best practices.

November/December 2022

March 2023

June 2023

August 2023

October/November 2023


Further Reading