Crypto Scammers Posed as Apple/Google Support

The Record · Medium sophistication
Last updated September 9, 2026

U.S. prosecutors say a group led by Malone Lam ran social engineering scams that stole over $245 million in cryptocurrency. The scammers allegedly called crypto holders while pretending to be customer support from Apple or Google, talked victims into handing over key account details, and in at least one case persuaded a victim to install remote desktop software to enable theft.

How the attack worked

Prosecutors said a group led by Malone Lam ran social engineering scams that stole more than $245 million in cryptocurrency. The core method was straightforward: members called crypto holders and pretended to be customer service representatives from Apple or Google. Through these calls, they convinced victims to hand over key account details that enabled the actual theft of funds.

In at least one documented incident, the scam went further. Instead of simply extracting information verbally, the caller convinced the victim to download a remote desktop program. Once installed, the group used that remote access to directly steal account information, bypassing the need to talk the victim through each step.

Why it succeeded

The operation was not opportunistic. It relied on specialized roles, including database hackers, target identifiers, callers, money launderers, and even residential burglars who targeted hardware wallets. This division of labor let the group scale the scam and refine each stage.

Targeting was also data-driven. The group gained access to databases of information about people with large amounts of cryptocurrency, allowing callers to focus on victims likely to have significant funds worth stealing. This combination of credible-sounding impersonation and pre-existing knowledge about a victim's holdings made the calls more convincing than a random cold call would be.

What to watch for

  • Unsolicited phone calls claiming to be from Apple or Google support, especially ones tied to account security concerns
  • Requests for login credentials, recovery details, or other sensitive account information over the phone
  • Pressure to act quickly to avoid losing access to funds or accounts
  • A support caller asking to install remote desktop or remote access software
  • Remote sessions that seem to go beyond fixing a specific stated issue

How to build resistance

  • Treat unsolicited support calls as suspicious. Hang up and contact the company using an official number you look up yourself, not one provided by the caller.
  • Never share account credentials or recovery details by phone, regardless of how legitimate the caller sounds.
  • Avoid installing remote desktop tools at the request of an unexpected caller, since remote access can lead directly to full account takeover.
  • For individuals or employees managing significant crypto assets, apply extra verification steps to any account-related request, since attackers may already have data indicating who holds large amounts of cryptocurrency.

This case illustrates how phone-based impersonation, combined with targeted victim data and a willingness to install remote software, can result in large financial losses even without any technical exploit of the underlying crypto platforms.

Key findings

  • Prosecutors said Malone Lam led a scam group that stole more than $245 million in cryptocurrency.
  • Attackers called crypto holders and pretended to be customer service or Apple/Google representatives to obtain key account details.
  • The group used targeted victim data, including access to databases identifying people with large crypto holdings.
  • In at least one incident, the group convinced a victim to install remote desktop software and then used that access to steal account information.
  • The operation reportedly included specialized roles: database hackers, target identifiers, callers, money launderers, and residential burglars targeting hardware wallets.

Who’s being targeted

  • Commonly targeted roles: Executives and high-net-worth individuals, Customer support/helpdesk teams, Finance teams (fraud awareness), Employees who manage or hold crypto assets.
  • Affected industries: Cryptocurrency holders / consumers, Financial services / digital assets.
  • Attack channels: vishing.
  • Impersonated: Apple or Google customer support, Customer service / technical support.

Red flags to watch for

  • Unsolicited call claiming to be Apple/Google support
  • Requests for sensitive account details over the phone
  • Pressure to act to avoid losing access or funds
  • A support caller asking to install remote access software
  • Unclear or unverifiable reason for urgent “support”
  • Remote session used to access accounts rather than fix a specific issue
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

How did the scammers steal cryptocurrency from victims?

Attackers called crypto holders while posing as customer service or representatives from Apple and Google, convincing victims to hand over key account details that enabled crypto thefts.

Did victims install any software during these scams?

In at least one incident, the group convinced a victim to download a remote desktop program, then used that access to steal account information.

How did the scammers know who to target?

The group used access to databases containing information about people with large amounts of cryptocurrency to identify targets.

What should someone do if they get an unexpected call from 'Apple' or 'Google' support?

Treat the call as suspicious, hang up, and contact the company using an official number looked up independently, rather than sharing any account details.

Read the video transcript

Someone calls saying, “This is Apple support, your account’s at risk.” For some people, that call ended with $245 million in crypto gone. Prosecutors say Malone Lam’s crew used stolen “who-has-money” data, then called crypto holders pretending to be Apple or Google reps, walking them through ‘verification’ to hand over login and recovery details. The worst step is when they say, “I’ll secure it for you, just install this remote desktop app.” One victim did that, let them in, and they quietly browsed his accounts and emptied his crypto. Aha test: if support calls you out of the blue about crypto, you hang up. Then you call Apple or Google back using a number you look up yourself. That’s the move that saves your wallet.

Similar attacks

Fake IT Helpdesk Tricks Users Into Remote Access

Fake IT Helpdesk Tricks Users Into Remote Access

This bulletin describes multiple real-world social engineering campaigns where attackers impersonate IT support or use trusted-looking sharing and “Allow” prompts to gain access. Several campaigns abuse Microsoft Teams and document-sharing lures to trick employees into installing remote tools or…

September 3, 2026
Fake Advisors, ClickFix, and Chrome Sync Spying

Fake Advisors, ClickFix, and Chrome Sync Spying

This roundup describes several real-world social-engineering and human-abuse techniques, including trojanized “installer” lures (ClickFix), large-scale phone-based investment fraud, and stalkers misusing Chrome Sync after brief physical access. The items include clear workflows that can be turned…

July 16, 2026
AI Voice “Apple Support” Phishing + Fake IT Helpdesk

AI Voice “Apple Support” Phishing + Fake IT Helpdesk

This news roundup describes real social-engineering operations where attackers impersonate trusted support teams to trick people into giving up secrets. One campaign uses email/SMS/WhatsApp plus AI voice calls pretending to be Apple Support to steal iPhone passcodes, while another uses phishing…

August 27, 2026
Fake IT Support Drives Pix Fraud in Brazil

Fake IT Support Drives Pix Fraud in Brazil

A financially motivated group called Breeze Comet targeted Brazilian financial and retail organizations by impersonating IT support and convincing staff to install remote-access tools. After gaining access, the attackers moved into internal payment systems (like Pix/STR/Boleto) and executed…

September 1, 2026
Teams Helpdesk Vishing Pushes Remote Control Tools

Teams Helpdesk Vishing Pushes Remote Control Tools

Researchers observed a coordinated social-engineering operation (“Spring Ring”) where attackers used external Microsoft Teams accounts to pose as internal IT help desk staff and start voice calls. Victims were pressured to install remote-control tools (like Quick Assist or other RMM software) or…

August 31, 2026
Fake Conferences Fuel OAuth and WhatsApp Phish

Fake Conferences Fuel OAuth and WhatsApp Phish

Google tracked three suspected Russia-linked groups running targeted phishing that abuses real login and authentication features (app passwords, OAuth, and device codes) to get into accounts. The lures often look like legitimate conference or diplomatic invitations, and some campaigns spoof…

August 21, 2026