may-akda: Katie Boquetti | Editoryal: Craig Taylor
This week’s blog has a compliment buried in it for Apple hardware security. You see, criminals have been stealing iPhones for a long time, but they are effectively admitting now that they can’t beat Apple’s hardware security (something called the Ligtas na Enclave) to make use of the stolen phone. So rather than attack the phone to break into it, they attack the one component Apple can’t patch: you and me. 🙂
Meet “Alice from Apple Support.” She is an AI voice agent, she speaks three languages, she knows your exact phone model and where it is sitting right now, and she is unfailingly polite as she walks you through reading your passcode out loud. She is also fake, and she costs her operators about a dime per call to run.
That price is another part of the real story here. For over a decade of iPhone releases, a convincing phone con needed a skilled human working one victim at a time. AI just turned that craft into a subscription product that runs at scale, in your language, with your details. The old warning signs we taught people, the bad grammar and the generic “Dear Customer,” are mostly gone now.
Before you go on to the article, my advice is to take a moment to enable “Apple’s Stolen Device Protection” something that’s off by default. Enabling this requires iOS 17.3 or later and takes a couple of minutes. Details on this feature are found here: https://support.apple.com/en-us/102568, it’s off by default, steps to enable are in the checklist below.
If your iPhone gets stolen and Find My iPhone can’t show you where it is (thieves often drop it in an inexpensive Faraday bag to kill the signal), expect an AI-generated phone call at some point trying to talk you out of your passcode. Don’t take the bait and add this insult to your injury of a stolen iPhone! Simply repeat this mantra: “nobody legitimate ever asks for your passcode, password, or verification code". Apple has said so plainly here. Refuse that single request, and the entire operation has nothing left to work with.
Apple made the hardware the hardest thing to hack and attack, so now hackers attack you instead! Stay sharp and watch out for these AI-generated phone calls when your phone’s been stolen.
— Craig Taylor, CEO CyberHoot
Here is a scenario worth knowing before it happens to you or someone in your office. Your iPhone gets lost or stolen, and a few days later, you receive a call from someone who sounds like a calm, friendly Apple Support rep. She knows your phone model. She knows where your phone currently sits on a map. She asks for your passcode so she “can help remove the lock.”
She is not from Apple. She is not even human. She is an AI voice agent, rented by a criminal, built to talk you out of your passcode, your Apple ID password, and your two-factor code, one polite sentence at a time.
Security researchers at SOCRadar recently documented this operation. It goes by the name AnonyMousKIT, and it is worth a few minutes of your attention, no matter how large or small your organization is.
AnonyMousKIT is a phishing service built for one job: unlocking stolen iPhones by tricking the owner into handing over their credentials. Apple’s Activation Lock ties a phone to its owner’s Apple ID, so a stolen phone stays useless until the thief removes that lock. Instead of hacking around Activation Lock, criminals pay for access to a slick platform that contacts victims directly and asks nicely.
The platform runs like a small software company. It sells credit bundles, offers subscription tiers, and reaches victims across five channels from a single stolen phone’s data: email, text message, WhatsApp, a recorded voice call, and a live AI voice agent.
The AI persona behind these calls goes by “Alice from Apple Support,” and she speaks English, Spanish, and Portuguese depending on the target. Researchers recovered 200 call records tied to this persona, most placed to phone numbers in Brazil between August 2025 and May 2026.
A typical call follows a simple script. Alice confirms she is speaking with the phone’s owner, asks for the four- or six-digit passcode, and reads the numbers back to double check. She then explains that someone visited an Apple Store to try removing the Activation Lock, and asks whether a recovery text arrived yet. That question sets up the next request, the Apple ID password and a live two factor code.
Running all 200 of these calls cost the operator under twenty dollars total. Convincing, multilingual phone scams now cost about a dime each to attempt. That price drop deserves your attention more than any headline number of victims.
The scam works because it uses real information pulled straight from the stolen device, including the exact Apple model number and its live location from Find My. Victims who click a linked message land on a page styled to look like an official Apple site, complete with an animated map showing where their phone sits right now.
Email remains the busiest channel in this scheme. The most common subject lines read “Your device has been found” and “Alert,” sent from accounts made to look like Apple, Find My, or Apple Support. Many of these emails route through one free Gmail account, and most include the name of a real city where the victim lives, which makes a mass-produced message feel personal.
AnonyMousKIT sits inside a larger family of similar kits. Researchers found dozens of related installations across many domains, some launching within the same second and sharing back end infrastructure, a sign that a handful of operators run several branded storefronts at once.
Here is a genuinely encouraging detail buried in the report. The “unlock tools” these storefronts advertise mostly serve as bait. Nearly all of the targeted phones run Apple chips new enough that no public exploit reaches their Secure Enclave. The criminals need your passcode and your login because there is no shortcut around Apple’s hardware protection. Your best defense already works.
Apple has stated plainly that the company will never ask for your password, your device passcode, or a two factor code, and will never ask you to tap Accept on a two factor prompt. Treat any call, text, or email asking for these details as fake, regardless of how much accurate detail it seems to carry about your device.
Beyond enabling Stolen Device Protection (you already did that right?), keep sharing these tips and best practices with your team. The #1 best habit: never, ever, give your passcode, password, or verification code to anyone who calls, texts, or emails you first, even when they sound friendly and know details about your phone. Share this article with your team this week, talk about it for five minutes at your next meeting, and you will already be safer today than you were yesterday.
Does Apple ever call, text, or email asking for my passcode or two factor code? No. Apple has said clearly it will never ask for your password, device passcode, or a two factor code, and it will never ask you to tap Accept on a two factor prompt. Treat any request for these details as fake.
How did the scammer know my phone model and location? The scam pulls this information directly from your stolen device, including its Apple model number and its live Find My status. That accuracy makes the message feel legitimate, even though it comes from a criminal, not Apple.
Does an AI voice really sound convincing enough to fool people? Yes, and that is worth taking seriously. The persona behind these calls runs in three languages and follows a natural, calm script that walks victims through confirming ownership and reading back a passcode, all for about a dime per call.
What do I do if I get one of these calls or messages? Hang up or ignore it. Never share a passcode, password, or verification code with anyone who contacts you first. Forward suspicious messages to reportphishing@apple.com and reach out to Apple directly through official channels if you want to confirm anything.
Does this scam actually break into the phone’s hardware? No. Nothing here involves a technical exploit. The entire scheme depends on you handing over your own credentials. Refuse that one request, and the scam has nothing left to work with.
Tuklasin at ibahagi ang pinakabagong mga uso sa cybersecurity, mga tip at pinakamahusay na kagawian – kasama ng mga bagong banta na dapat abangan.
May-akda: Katie Boquetti | Editoryal: Craig Taylor Editoryal ni Craig Taylor: Ang blog ngayong linggo ay may...
Magbasa nang higit pa
Paminsan-minsan, may malware na may kasamang kakaibang trick na sapat na matalino para mapahinto ang mga security researcher at...
Magbasa nang higit pa
May-akda: Craig Taylor Hindi ako maaaring bumisita sa isang coffee shop, maglaro ng golf, makipag-usap nang palakaibigan sa...
Magbasa nang higit paMas matalas ang mata sa mga panganib ng tao, gamit ang positibong diskarte na nakakatalo sa tradisyonal na pagsubok sa phish.
