A criminal service called AnonymousKit helps iPhone thieves turn stolen devices into cash by impersonating Apple and tricking victims into handing over their passcode, Apple ID, and two-factor codes. The workflow starts with a realistic “found your device” message (email or text) that includes a map, and can escalate to a phone call from “Apple Support.”
How the attack worked
This attack chain, tied to a criminal operation called AnonymousKit, is built around the emotional relief of recovering a lost or stolen iPhone. The victim receives an email or text claiming to come from Apple, stating that a lost device has been found. In the email version, a map is embedded directly in the HTML, showing a supposed last known location of the device. This visual detail is designed to make the message look authentic and lower the recipient's guard.
The end goal of the message is to get the victim to hand over their passcode, Apple ID, and two-factor authentication code. In some cases, the attack escalates further with a phone call from someone identifying themselves as Apple Support, adding a human layer of social pressure that reinforces the fake message and pushes the victim toward compliance.
Why it succeeded
The scam exploits a moment of high stress, having just lost a phone, and offers what feels like good news. That emotional relief short-circuits normal skepticism. The added realism of a map embedded in the message, combined with a follow-up phone call from a supposed support agent, gives the impression of a coordinated, legitimate recovery process rather than an opportunistic scam.
AnonymousKit is described as operating like a criminal SaaS platform, phishing as a service, where operators pay a subscription and the platform handles execution. This kind of packaged infrastructure allows the same convincing lure and follow-up call script to be reused at scale against many victims.
What to watch for
- An unexpected message claiming a lost device has been found, arriving by email or text
- Any request for a passcode, Apple ID, or two-factor authentication code
- Embedded maps or location details meant to make the message feel more credible
- A follow-up phone call from someone claiming to be Apple Support asking for verification details
How to build resistance
Treat any unsolicited
Key findings
- SOC Radar investigated an iPhone-theft-focused criminal operation called “AnonymousKit,” described as a “criminal SaaS operation.”
- AnonymousKit is positioned as “phishing as a service,” where criminals “pay a subscription” and the platform “does the rest.”
- The lure uses an Apple impersonation message: “Good news, we found your lost device,” including “a little map embedded in the HTML of the email.”
- The operation aims to capture “their passcode, their Apple ID … and their 2FA code as well.”
- The attack may add a follow-up phone call: “you get a call from someone called Alice from Apple Suppor...” (Apple Support impersonation).
Who’s being targeted
- Commonly targeted roles: All employees, Executives, Helpdesk / IT support (to advise users during device-loss events), Finance (high-value targets likely to have sensitive apps on phones).
- Affected industries: Consumers / individuals (smartphone owners).
- Attack channels: email, smishing, vishing.
- Impersonated: Apple, Apple Support.
Red flags to watch for
- Unexpected “found your device” message soon after a loss (high emotional pressure)
- Request for passcode/Apple ID/2FA codes (Apple should not need your passcode)
- Email content designed to look “real” with embedded map to lower suspicion
- SMS purporting to be Apple about a lost device
- Pressure to act quickly to recover a valuable device
- Any request for 2FA codes is a strong sign of fraud
- Inbound call after a “found device” message pushing you to share credentials
- Caller asks for passcodes or one-time codes
- Caller identity cannot be independently verified
Frequently asked questions
How does the fake Apple lost iPhone scam work?
Victims get an email or text claiming to come from Apple saying a lost device was found, often with a map embedded in the HTML, and are pressured into entering their passcode, Apple ID, and 2FA code.
What is AnonymousKit?
AnonymousKit is described as a criminal SaaS operation, or phishing as a service, where criminals pay a subscription and the platform handles the fraudulent messaging and infrastructure.
Does the scam ever involve a phone call?
Yes, the attack can escalate with a follow-up call from someone posing as Apple Support who asks the victim to provide credentials or a 2FA code to verify identity.
What information should I never share if I get a lost device message?
Never share your device passcode, Apple ID password, or any two-factor authentication code, since these are exactly what attackers need to take over an account or device.
Read the video transcript
You’ve just lost your iPhone… then ping: “Good news, we found your lost device,” from “Apple,” with a little map. Behind that message is a criminal SaaS called AnonymousKit. Thieves pay a subscription, it sends Apple-lookalike emails and texts, then funnels you to a fake page to grab your passcode, Apple ID, and even your 2FA code. The twist: after the email or text, you might even get a call from “Alice from Apple Support,” calmly asking you to read out your 2FA code to “secure your phone.” That one code lets them take everything. If you ever see “Good news, we found your lost device,” ignore the link and the call, open the Find My app or iCloud.com yourself and check there.