I'm a few weeks out from having a Level 3 IT diploma with my name on it — I'm about to go looking for actual paid work doing this — and I have already had the conversation I know I'm going to have for the rest of my career. Someone finds out I know computers, mentions their Mac's been acting strange, and the second I say the word "malware" they cut me off with the same six words, delivered with total confidence: "Macs don't get viruses though."
I use a Mac myself, for what it's worth. Mac mini on my desk, running my PDS, doing most of what I do day to day. I like the thing. This isn't me being bitter that I didn't buy the "better" platform. This is me being the person who has to sit across from someone, explain that their preference in computer has nothing to do with whether it can be compromised, and watch them not quite believe me, because a company spent six years and a small fortune making sure they wouldn't.
The ad that did the damage
The line has a birthday. May 2006, the first "Get a Mac" spot: Justin Long, calm, in the light blue t-shirt, standing next to John Hodgman playing a visibly ill PC. "I have that virus that's going around." "That's okay, I'll be fine." That was the opener for what became a six-year campaign built around one specific, quantified claim: 114,000 known viruses targeting PCs, none targeting the Mac.
That number wasn't invented, and the underlying comparison wasn't fabricated either — Apple even took the ad to the UK's Advertising Standards Authority when it got complained about, and won, because the claim was scoped specifically to Windows PCs and Apple could point to a genuinely enormous gap in known malware counts between the platforms. The ASA cleared it. Twice, more or less, across the TV and cinema versions. That's the bit that makes this so much more effective than an ordinary lie: it was technically true, ruled true by an actual regulator, and it still taught an entire generation the wrong lesson.
The wrong lesson being: Macs don't get viruses, full stop, structurally, forever. What was actually true was narrower and far less permanent — Macs weren't being targeted much, because almost nobody was buying them. In 2006, when the campaign started, Apple's share of the desktop market was in the low single digits. Even by 2013, over 90% of the world's computers were still running Windows. Malware authors write malware for the platform with the most victims on it, the same way a burglar doesn't case the one house on a street that nobody lives in. That's not an operating system being secure. That's an operating system being unpopular enough to not be worth the effort.
Apple knew this, eventually, or at least someone in legal did. The company kept a version of the "doesn't get PC viruses" claim on its own marketing pages until 2012, when it was quietly rewritten to the noticeably weaker "built to be safe" — a change nobody announced, and one that only got noticed because a journalist at Wired happened to be paying attention. Apple didn't correct the myth. It just stopped actively feeding it while leaving six years of adverts to keep doing the work.
2012 was also when the excuse ran out
The timing is not a coincidence worth glossing over. The same year Apple edited its own website, Flashback happened — a trojan that exploited an unpatched Java flaw, spread through drive-by downloads on compromised WordPress sites, and infected over 600,000 Macs worldwide, a few hundred of them reportedly inside Apple's own Cupertino offices. It was, at the time, the largest known Mac malware outbreak on record, and it happened specifically because Mac's install base had finally grown large enough to be worth criminals' time.
That's the whole thesis of this post in one outbreak. The myth was never really about architecture. It was about audience size, and the moment the audience got big enough, the "immunity" evaporated on schedule.
It hasn't stopped evaporating since. Palo Alto Networks' Unit 42 team tracked a 101% jump in macOS infostealers in just the second half of 2024 alone. One strain, Poseidon, accounted for roughly seven in ten infostealer detections on Mac by the end of that year, according to Malwarebytes' most recent threat report. Backdoor malware aimed at macOS reportedly rose a further 67% into 2025. None of this is a fringe security-vendor scare story dressed up to sell antivirus subscriptions, though I'll grant that's always worth being sceptical of — it's the same pattern Flashback demonstrated in 2012, just thirteen years and a much bigger install base further along. Macs are popular enough now that not targeting them would be the strange business decision.
It was never just a Mac problem to not have
Look at the wider picture for a second, because the "Macs don't get viruses" line only sounds plausible if you've already accepted a much shakier premise underneath it: that some other platform is the one that gets them instead, and everything else is safe by comparison. It isn't. Every general-purpose operating system that's popular enough to be worth attacking has been attacked, and the list of proof isn't short.
Windows is the obvious one, and I don't need to relitigate that here — but it's worth naming the scale properly rather than treating it as background noise. WannaCry, in 2017, encrypted somewhere north of 200,000 machines across 150 countries in a matter of hours, using a leaked NSA exploit against a Windows networking flaw that had already been patched a month earlier and simply hadn't been installed. It took down parts of the NHS, Renault's production lines, and FedEx's operations, among plenty of others. That's not "Windows gets viruses" as an abstract truism. That's a single weekend, a single unpatched protocol, and hospitals diverting ambulances because of it.
Linux doesn't get to sit this one out either, despite having its own version of the Mac myth among people who run it. Mirai, first found in 2016, specifically targets Linux-based embedded devices — routers, IP cameras, DVRs — by brute-forcing default logins nobody bothered to change, and it enslaved over 600,000 devices at its peak to run some of the largest DDoS attacks on record. It's still active today, spun off into variants like Mozi and Gayfemboy, still working the exact same trick on the exact same operating system that a lot of Linux users will tell you is architecturally immune. (One of those variants is genuinely called Gayfemboy. I have no explanation for that. I checked three separate sources before I believed it myself, and I still don't fully believe it.) The vulnerability there was never the kernel. It was the same thing it always is: humans not changing a default password.
Even the platforms with the most locked-down reputation in the industry aren't exempt. Pegasus, the spyware developed by NSO Group, has compromised fully updated iPhones — arguably the most tightly sandboxed consumer operating system that exists — via zero-click exploits that require no user interaction at all, no dodgy download, no clicked link, nothing. If iOS, a platform Apple controls end to end and reviews every app for, can be compromised with zero user error involved, "my computer is a brand I trust" was never going to be a security model on its own, on any platform.
Every single one of these examples has a different mechanism. Different vulnerability, different delivery method, different motive. What they share is the only thing that actually matters here: a large enough number of people using the thing to make attacking it worthwhile. That's the one variable that predicts malware activity across every operating system that's ever existed, and it's the one variable Apple's advertising spent six years training people to ignore in their specific case.
What this actually costs the rest of us
Here's the headache, and it's not really the malware. Malware is a technical problem with technical solutions. The headache is that I now have to spend part of every relevant conversation dismantling a piece of successful advertising before I can get to the actual work.
It's not usually stupidity on the other end of that conversation, either, which is the part that grates most. It's a person repeating something they were told clearly, repeatedly, by a company they trusted, in adverts specifically engineered to be memorable and reassuring. The ASA ruled the claim technically defensible. That's not "gullible person believed an obvious lie." That's "reasonable person believed a claim a regulator agreed was accurate," and now I'm the one stood in their kitchen trying to explain the difference between "accurate in 2007" and "accurate now," which is a much harder sell than just being right.
And it compounds. Someone who genuinely believes their Mac can't get infected doesn't install anything to check. Doesn't think twice about the cracked app download, the fake browser update, the too-good deal in a DM. Every single one of the infostealer families racking up those detection numbers relies on exactly that — a user clicking through a prompt they'd have hesitated over on a PC, because on a Mac they've been told, explicitly, by an advert with a jingle, that there's nothing to hesitate about. The myth isn't just wrong. It's actively load-bearing for the attacks currently working best against the platform.
The trolls got there before the malware did
The other cost of the campaign is less technical and mostly just tedious, but it's worth naming because it's the same myth wearing a different coat. Anyone who was anywhere near 4chan in the years that campaign was airing will remember how quickly "Macs don't get viruses" got turned into ammunition against the people who believed it — the "Macfag" era, the smug reaction images lifted straight from the ads themselves, the running bit of waiting for the inevitable outbreak just to enjoy it happening to someone who'd been insufferable about their laptop. It wasn't really about security either. It was about a marketing campaign so confident and so smug that it became a target in its own right, and the people mocking it were, technically, more correct about the actual state of Mac security than Apple's own website was at the time.
I don't think that makes the trolling admirable. Most of it wasn't. A lot of it was just early-internet cruelty looking for an excuse. But it's a genuinely strange footnote that the most accurate public pushback against "Macs don't get viruses," for years, was coming from an anonymous imageboard rather than from Apple itself correcting the record. The company that started the myth left it uncorrected until a journalist forced the issue. The people calling it out for free were doing it to be mean, not to be accurate — and ended up being both.
I still use one. That's not the point
None of this is an argument for switching platforms, and I'd rather head that reading off before someone tries it in the replies. I chose a Mac because I prefer the hardware, the OS, the whole shape of using it day to day. That preference has survived me knowing exactly how exposed the machine actually is, because a preference and a security posture are two entirely separate decisions, and Apple's advertising spent six years successfully merging them into one in the public imagination.
That's the whole complaint. Not that Macs are unsafe. Every platform is unsafe to some degree, and macOS still does plenty right. It's that an advertising campaign, cleared by a regulator, technically accurate at the time it aired, managed to install a piece of permanent, incorrect certainty in people who had no reason to update it, and I'm the one who has to do the updating now, one kitchen-table conversation at a time, for a myth I didn't write and Apple never formally took back.