Start your 3-day free trial
Sign up to experience all premium features at no cost.
*Available only to new users. Each user is limited to one trial.


Pegasus spyware is associated with NSO Group and documented in targeted surveillance research. It is a surveillance tool, not a name for every slow or malfunctioning phone. Amnesty International’s forensic work describes traces found during investigations of suspected Pegasus attacks and the limits of what different device records can reveal. [1]
The practical question is your risk context and the evidence available. Use the wider digital privacy framework for everyday protection. A credible targeted-spyware warning calls for a different response from an unexplained battery problem: preserve relevant information, verify the warning, and obtain specialist help.
Key Takeaways
- Targeted mercenary spyware is expensive and selective; ordinary phone symptoms cannot identify Pegasus.
- An authentic Apple notification indicates high-confidence targeting, not necessarily confirmed infection.
- Lockdown Mode reduces attack surface and can limit normal functions; it is not a removal or diagnosis tool.
- High-risk response should protect people and evidence, not rely on a personal scan to declare the device clean.
Apple describes mercenary spyware attacks as exceptionally sophisticated and directed at a small number of individuals, including journalists, activists, politicians, and diplomats. Most people are not targets of this class of attack. [2] That context helps avoid panic, but it is not an exemption for anyone whose role or relationships create a plausible surveillance interest.
Think about the information an attacker might seek: confidential communications, sources, organizational plans, or access to other people. Risk can extend beyond a job title. A source, colleague, or family member may hold sensitive connections. A credible official warning or a specialist’s assessment matters more than a broad statement that only famous people are at risk.
Targeting, an attempted attack, and successful compromise are separate claims. A device might receive an exploit attempt that does not succeed. Investigators may find evidence supporting compromise, or they may lack enough records to decide.
State the finding at the level the evidence supports. Do not describe an official targeting notice as a completed forensic diagnosis.
For professional work, the journalist safety guide covers broader communication and organizational practices. This article focuses on the response to a specific surveillance concern and should not replace an employer’s security process or a source-protection plan.
Battery drain, heat, crashes, and data use have many causes. They can justify ordinary troubleshooting but do not identify Pegasus. Conversely, a phone can appear normal while surveillance is occurring. Neither a dramatic symptom nor a smooth-running device provides the evidence needed for an attribution claim.
An account login alert is also distinct from device compromise. Someone might have obtained an account password without infecting the phone. If sensitive material has been published, the doxxing response guide addresses exposure and threats. Do not collapse all privacy incidents into a spyware diagnosis.
| Observation | Reasonable interpretation | Next useful action |
|---|---|---|
| Battery or performance change | A nonspecific device issue | Troubleshoot through official support |
| Unexpected account session | Possible account access | Secure access from a trusted device |
| Authenticated Apple threat notice | High-confidence targeted attack concern | Seek specialist response and preserve the notice |
| Specialist forensic finding | Evidence with stated limits | Follow the investigator’s containment plan |
| No notice or no detected indicator | Limited negative information | Do not use it as a guarantee of no compromise |
The keylogger guide explains a narrower input-capture function. A botnet concerns coordinated control of devices. These labels describe different properties and cannot be inferred merely from an unfamiliar process or high data use.
For a wider distinction between device monitoring, account access, and sharing settings, use the general spyware recovery framework; ordinary checks do not rule out a sophisticated targeted attack.
Apple’s current guidance describes threat notifications through supported device interfaces, account email, and an account-page banner. Go independently to the known Apple account website and sign in to check for the notification. Use a trusted device if yours may be compromised. Do not rely only on the appearance of a message or the sender name shown by an email client. [2]
Apple says these notifications never ask you to click a link, open a file, install an application or profile, or disclose your account password or verification code through email or a phone call. A message requesting such actions needs independent verification. A real security concern is also an opportunity for impersonators; urgency does not make their instructions trustworthy.
Save the authentic notice and the time you received it. Keep the copy in a place appropriate to the sensitivity of your work. If an organization supports you, contact its security team through an established channel.
Apple’s guidance also points to the Access Now Digital Security Helpline for expert assistance. Reach such services through their known public channels rather than a stranger’s offered contact.
The notice expresses high confidence that you have been targeted by mercenary spyware. It does not name every possible attacker, prove the attack succeeded, or establish that Pegasus specifically was used in your case. Keep the language accurate when informing colleagues so an initial warning does not become an unsupported public allegation.
Lockdown Mode is an optional protection intended for people who may face highly targeted attacks. Apple describes it as reducing attack surface by restricting some functionality. It changes the device’s behaviour; it does not scan for Pegasus, prove that an attack failed, or certify removal of existing spyware. [3]
Restrictions can affect message attachments and previews, some website technologies, communication features, connections, and new management profiles. The exact behaviour depends on the current platform and version. Normal calls, ordinary text messaging, and emergency functions remain available under Apple’s guidance, but some everyday interactions may become less convenient. Review the official page for the devices you use.
On supported iPhone and iPad versions, the control is under Settings, Privacy & Security, Lockdown Mode, followed by the supported activation and restart process. On a supported Mac, use System Settings, Privacy & Security, Lockdown Mode. Install current supported software and check the setting on each relevant device. Do not assume enabling it on one computer automatically enables it everywhere.
Website or application exclusions reduce the protection for the excluded activity. If a service breaks, consider a safer alternative or specialist guidance before routinely disabling the mode. Existing organizational management also needs careful handling; blocking new enrollment is not the same as removing a pre-existing management relationship. Coordinate with the responsible team instead of deleting profiles blindly.
Keep the warning, suspicious messages, approximate event times, device model, software version, and any steps already taken. Distinguish original observations from assumptions. This record helps a specialist select the relevant investigation path without repeatedly asking you to reconstruct events from memory.
Do not immediately wipe a device solely to obtain reassurance. A reset or repeated cleanup can change records useful to an investigation. Equally, do not leave sensitive communications on a suspect device just to preserve evidence. Contact expert support from a safer device and ask how to balance containment, evidence, and ongoing work in your situation.
Avoid installing unknown “Pegasus detector” applications or running copied commands without understanding their access. Backups and forensic exports can contain highly sensitive communications and account data. Do not upload them to public repositories, open file-sharing links, or random diagnosis services. Agree on a secure transfer method and scope with the legitimate investigator.
Amnesty’s methodology concerns particular artifacts and investigative techniques, not a universal consumer pass/fail test. [1] Evidence availability differs between platforms and versions. Missing indicators may reflect limited records or coverage. A specialist should explain both what was found and what the assessment cannot exclude; a negative search is not a guarantee of absence.
Use a trusted device to review high-impact account access, recovery methods, and active sessions. Notify relevant people through an agreed safe channel if their communications may be affected. Share only what they need to act. A broad public announcement may expose sources or reveal response steps before a safety plan is in place.
Update supported devices, consider Lockdown Mode according to your risk, and follow specialist containment guidance. The zero-day guide explains why patch availability and successful installation are distinct. “Zero-click” means a particular attack may not require the target to click; it does not mean all spyware behaves identically or that user decisions never matter.
Review tracking boundaries when using a VPN before choosing a network tool as an answer to device compromise. A surveillance process operating on the endpoint may access information before a connection is encrypted or after it is decrypted. Changing the network route cannot establish that the endpoint is trustworthy.
Agree on a contact, a safer communications channel, and the scope of the investigation. Record which devices were assessed, which software versions were involved, and what the findings actually support. An assessment of one phone does not automatically cover a laptop, account, or later period of use.
Keep protective settings and updates under review without constantly searching for alarming symptoms. If new evidence appears, return to the responsible specialist with the record rather than repeating unverified self-tests. The goal is a defensible risk decision and a workable communication plan, even when the historical evidence cannot provide complete certainty.
No. Battery changes have many ordinary causes and cannot identify a specific spyware tool. Credible warnings or forensic evidence require a different response.
No. It indicates high-confidence targeting by mercenary spyware. Whether an attack succeeded and which tool was involved require further evidence.
No. Notifications are not a complete guarantee of detection. Consider your risk context and any credible evidence independently of whether an alert arrived.
It is a protective mode, not a removal or diagnosis tool. Existing compromise and evidence needs should be assessed with qualified support.
Seek guidance first when credible targeted compromise is suspected. Resetting may alter evidence, while containment and safe communication need an individualized plan.
Avoid it. Backups can contain sensitive communications and credentials. Use an agreed secure process with a legitimate investigator and a clear investigation scope.
No universal personal test can guarantee absence. Tools and indicators have coverage limits; a qualified assessment should state those limits explicitly.
Disclaimer: This is general information, not a forensic diagnosis, attribution, or individualized safety plan. High-risk surveillance can affect sources and physical safety. Obtain qualified help and follow any evidence-preservation requirements relevant to your situation.
Sources:
Sources checked 5 October 2026.
Related Articles:
Sign up to experience all premium features at no cost.
*Available only to new users. Each user is limited to one trial.