Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Malware & Threats

Apple Sends Fresh Wave of Spyware Notifications to French Users

Apple this year sent at least four rounds of notifications to French users potentially targeted by commercial spyware.

iPhone security

Apple in early September sent a fresh wave of threat notifications to French users it believes might have been targeted by commercial spyware.

This is at least the fourth time the Cupertino-based tech giant has notified users in France of potential mercenary spyware attacks, according to an alert from the French national Computer Emergency Response Team (CERT-FR).

“This alert records all waves of notifications sent by Apple and known to CERT-FR since March 5, 2025. The list of notification campaigns referenced here is therefore not exhaustive: it only includes the campaigns known to CERT-FR,” the agency notes.

This year, Apple users in France received threat notifications in March, April, June, and September, but the company has been sending these notices since 2021.

The notifications are only delivered to a small number of users who might have been targeted by commercial spyware because of their identity or activities. Most users are never targeted by such attacks.

“These attacks are much more complex than the usual cybercrime activities and as consumer malware, because people who carry out such attacks use exceptional resources to specifically target a very small number of people and their devices. Attacks through mercenary spyware cost millions of dollars,” Apple notes in its description of the threat notifications.

Advertisement. Scroll to continue reading.

Some of the known commercial spyware families out there include Pegasus, Predator, Graphite, and Triangulation, and have been observed targeting activists, journalists, politicians, senior officials, and other individuals in strategic positions.

“The receipt of a notification means that at least one of the devices linked to the iCloud account has been targeted and would be potentially compromised,” CERT-FR explains.

The agency also points out that a threat notice may come months after the individual was targeted, underlining that people who receive them should take immediate action to secure their accounts and devices.

“The notifications sent indicate highly sophisticated attacks employing for most day-zero vulnerabilities, or even requiring no user interaction,” CERT-FR says.

The agency encourages individuals to keep the notification if they receive one, to avoid making changes to their software or devices – to preserve forensic evidence – and to contact CERT-FR for technical assistance.

The news comes just days after Apple announced that its new iPhone 17 and iPhone Air models include a novel memory protection feature designed to safeguard devices against sophisticated spyware attacks.

Related: Chinese Spies Impersonated US Lawmaker to Deliver Malware to Trade Groups: Report

Related: FreeType Zero-Day Found by Meta Exploited in Paragon Spyware Attacks

Related: Palestinian Lawyer Sues Pegasus Spyware Maker in France

Related: Rights Group Says Lebanese Staffer Targeted With NSO Spyware

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join this live webinar as we explore if detection-first security operations can keep pace with AI, or if it’s time to rethink prevention as the strongest default.

Register

CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps!

Register

People on the Move

ServiceNow has appointed Simon Mouyal as Chief Marketing Officer.

James Wilkinson has been named Chief Information Security Officer for the City of Dallas.

PNC Financial Services Group has appointed Christian Winward as CISO.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.