
“Russian Coms” Vishing Platform Busted
UK authorities charged five people linked to “Russian Coms,” a vishing (phone-scam) platform used to make large volumes of spoofed calls that appeared to come…
Apple warns that scammers are using FaceTime calls, often with spoofed caller ID, to impersonate Apple or banks and pressure people into sharing passwords, security codes, and financial details. The callers use personal information to sound legitimate, then create urgency to keep victims from hanging up and verifying the request independently. Some scams also try to get victims to disable protections like 2FA or Stolen Device Protection to make account takeover easier.
Scammers place FaceTime calls with spoofed caller ID so the call appears to come from Apple or a bank. The pretext usually involves a claimed iPhone or iCloud compromise or unauthorized Apple Pay charges, with the caller offering to "help" stop the attacker or reverse the charges. To sound legitimate, the caller brings up personal information early, such as a home address, employer, or Social Security number, which helps establish trust before the ask begins.
Once trust is built, the caller shifts to urgency. Victims are told that hanging up and calling the company back will not help because the fraud will supposedly continue in the meantime, a claim that is false but effective at keeping people on the line rather than verifying independently. This pressure is used to extract credentials, security codes, or financial details, and in some cases to convince victims to disable protections like two-factor authentication (2FA) or Stolen Device Protection, framed as necessary to stop an "ongoing attack." In reality, disabling those features removes the very safeguards that prevent account takeover.
Treat unexpected calls claiming to be Apple or a bank as untrusted by default, even if the caller ID looks legitimate. If a call raises suspicion, the safer approach is to assume it is a scam and contact the company directly using a number found independently, not one provided by the caller. Employees, especially those handling finance or payments, should be reminded that legitimate support teams will never ask for passwords, passcodes, or 2FA codes, and will never ask someone to approve a 2FA prompt over the phone. Reinforcing that security features like 2FA and Stolen Device Protection should never be disabled at another person's request, particularly during an unplanned call, closes off the final step scammers rely on to complete account takeover.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
They spoof caller ID to appear as Apple or a bank, then use personal details like an address or employer to build credibility before pressuring victims for credentials, security codes, or financial information.
Callers falsely claim that hanging up and calling back will let the fraud continue, which is designed to keep victims on the line instead of independently verifying the request.
No. Apple has stated it will never ask users to log in to a website, approve a two-factor authentication prompt, or provide a password, passcode, or 2FA code.
They frame it as necessary to stop an ongoing attack, but disabling these protections actually removes the safeguards that would prevent account takeover.
You get a FaceTime call that says “Apple Support.” The person knows your address and employer, and says your iCloud is under attack. They say, “Don’t hang up, calling back won’t stop the fraud. Tap Accept on the code and tell me your password so we can reverse Apple Pay charges.” This is a FaceTime spoof scam. Here’s the trick: they use your personal details to sound legit, then rush you so you won’t hang up or call Apple or your bank yourself. Apple says they will never ask for your password, device passcode, or any two-factor code. If a call claims to be Apple or a bank and asks for codes or passwords, your move is simple: hang up, then call the company back using the number on their website.

UK authorities charged five people linked to “Russian Coms,” a vishing (phone-scam) platform used to make large volumes of spoofed calls that appeared to come…

Three crypto investors sued Apple after allegedly losing about $1.8 million in Bitcoin to an iPhone app that impersonated the legitimate (desktop-only) Sparrow…

Victims say they downloaded a fake “Sparrow Wallet” app from Apple’s App Store that impersonated a legitimate desktop-only crypto wallet. The app tricked users…

Apple warns that scammers are placing unsolicited FaceTime calls and sending urgent-looking messages that appear to come from “Apple Support” or a bank. The…

Microsoft reports billions of phishing attempts in Q2 2026, with attackers increasingly using attachments (PDF/DOC/HTML) and new formats like calendar invites…

The article highlights how attackers can quickly build convincing executive “profiles” from public information and use them to manipulate employees. It cites…