AI “Apple Support” Calls Steal iPhone Passcodes

Help Net Security · Medium sophistication
Last updated August 26, 2026

Researchers say a phishing-as-a-service platform called AnonyMousKIT targets people who recently lost or had an iPhone stolen by pretending to be “Apple Support.” The operation uses email/SMS/WhatsApp and AI-assisted voice calls to convince victims to share their iPhone passcode and follow a security link, allowing thieves to remove Activation Lock and resell the device.

Key findings

  • AnonyMousKIT is a phishing-as-a-service platform designed to harvest Apple ID-related credentials to remove Activation Lock from stolen iPhones.
  • Attackers use accurate device identifiers (serial number/IMEI), model, and live Find My status to make lures more believable.
  • Victims are contacted via email, SMS, WhatsApp, recorded calls, and live/AI voice agents impersonating “Apple Support.”
  • SOCRadar recovered evidence from the operation, including “200 call logs and 55 transcripts,” showing a scripted workflow that asks for the victim’s device passcode and then pushes a security link/code process.
  • The operation is organized like a reseller ecosystem: developer → buyers/licensors → operators running branded storefronts (506 domains / 168 storefront brands identified).

Who’s being targeted

  • Commonly targeted roles: All employees, Executives, IT/Helpdesk, Finance (high-value targets who may be socially engineered under pressure).
  • Affected industries: Consumer technology (mobile devices), Retail/consumer services (device support), General public / individuals (stolen-device victims).
  • Attack channels: vishing, smishing, email, sms, whatsapp, recorded_call.
  • Impersonated: Apple Support (persona: “Alice Dias” / “Alice from Apple Support”), Apple Support (voice agent persona), Apple/Find My / Apple Support (implied).

Awareness takeaways

  • Train employees that no legitimate support agent will ask for a device passcode; treat any such request as a scam.
  • When a call pressures you to click a link or enter a code, stop and verify using official, known-good channels (e.g., Apple Support app/official site), not the caller’s instructions.
  • Warn staff that attackers may use real device details (serial/IMEI, model, Find My status) to make scams sound credible, accuracy does not equal legitimacy.
  • Include stolen-device scenarios in awareness training, since people are more likely to comply when they believe recovery is possible.

Red flags to watch for

  • Unsolicited call claiming Apple Store has your device and asking for your passcode
  • Pressure/timing tied to a theft/loss event to rush verification
  • A legitimate support agent would not ask for your device passcode over the phone
  • Being coached live over the phone to click a link and read back/enter a code
  • Text message link related to a “recovery case” you didn’t initiate
  • Story uses device model/serial details to gain trust but still asks for sensitive actions
  • Unsolicited recovery messages that push you to verify via a link or message reply
  • Messages arrive across multiple channels (SMS/WhatsApp/email) to increase pressure
  • Uses your real device details to feel legitimate
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You lose your iPhone… and an hour later, “Hi, this is Alice from Apple Support. The Apple Store is holding your phone for security.” This is AnonyMousKIT, a phishing-as-a-service scam. The AI voice already knows your iPhone model, serial, even Find My status, then asks you to say your four- or six-digit passcode to ‘confirm ownership.’ Next, they say, “I’m sending a security link now,” and coach you through tapping a text message and entering an unlock code while you’re still on the call. Once they have your passcode and that code, they can remove Activation Lock and resell your phone. A real Apple Support agent will never ask for your iPhone passcode or coach you through a link on a call. If anyone does, hang up and contact Apple using the official Support app or website you open yourself.

Similar attacks

AI Voice “Apple Support” Phishing + Fake IT Helpdesk

AI Voice “Apple Support” Phishing + Fake IT Helpdesk

This news roundup describes real social-engineering operations where attackers impersonate trusted support teams to trick people into giving up secrets. One campaign uses email/SMS/WhatsApp plus AI voice calls pretending to be Apple Support to steal iPhone passcodes, while another uses phishing…

August 27, 2026
AI “Apple Support” Calls Steal Passcodes & 2FA

AI “Apple Support” Calls Steal Passcodes & 2FA

Researchers uncovered a phishing-as-a-service platform (“AnonyMousKIT”) used by phone thieves to trick victims into handing over iPhone passcodes, Apple ID passwords, and live 2FA codes so thieves can remove Apple’s Activation Lock. The operation uses Apple-branded emails/pages and AI voice agents…

August 26, 2026
FBI Warns of Social Media Reset-Code Scams

FBI Warns of Social Media Reset-Code Scams

The FBI says criminals are using social engineering to take over social media accounts, steal explicit content, and sell or post it online along with victims’ personal information. Reported tactics include pretending to be a social media company representative, spamming victims with password-reset…

August 12, 2026
Vishing Lures, Fake Identities, and Repo-Trap Attacks

Vishing Lures, Fake Identities, and Repo-Trap Attacks

This recap describes multiple real-world social-engineering-driven attacks, including vishing calls that push employees to spoofed login pages and a supply-chain trick where cloning/opening a GitHub repo in developer tools triggers malware. It also highlights an unusual case where an AI model…

August 10, 2026
Deepfake FBI Videos Push Victims to Fake IC3 Sites

Deepfake FBI Videos Push Victims to Fake IC3 Sites

The FBI warned that scammers are impersonating IC3 leadership using AI-generated (deepfake) videos and spoofed IC3 websites to trick prior fraud victims into sharing more personal and financial information. In one example, victims are contacted on Facebook Messenger by someone posing as an FBI…

July 21, 2026
Fake Advisors, ClickFix, and Chrome Sync Spying

Fake Advisors, ClickFix, and Chrome Sync Spying

This roundup describes several real-world social-engineering and human-abuse techniques, including trojanized “installer” lures (ClickFix), large-scale phone-based investment fraud, and stalkers misusing Chrome Sync after brief physical access. The items include clear workflows that can be turned…

July 16, 2026