Fake “Apple Found Your iPhone” Phish Steals Codes

Graham Cluley · Medium sophistication
Last updated September 3, 2026

A criminal service called AnonymousKit helps iPhone thieves turn stolen devices into cash by impersonating Apple and tricking victims into handing over their passcode, Apple ID, and two-factor codes. The workflow starts with a realistic “found your device” message (email or text) that includes a map, and can escalate to a phone call from “Apple Support.”

How the attack worked

This attack chain, tied to a criminal operation called AnonymousKit, is built around the emotional relief of recovering a lost or stolen iPhone. The victim receives an email or text claiming to come from Apple, stating that a lost device has been found. In the email version, a map is embedded directly in the HTML, showing a supposed last known location of the device. This visual detail is designed to make the message look authentic and lower the recipient's guard.

The end goal of the message is to get the victim to hand over their passcode, Apple ID, and two-factor authentication code. In some cases, the attack escalates further with a phone call from someone identifying themselves as Apple Support, adding a human layer of social pressure that reinforces the fake message and pushes the victim toward compliance.

Why it succeeded

The scam exploits a moment of high stress, having just lost a phone, and offers what feels like good news. That emotional relief short-circuits normal skepticism. The added realism of a map embedded in the message, combined with a follow-up phone call from a supposed support agent, gives the impression of a coordinated, legitimate recovery process rather than an opportunistic scam.

AnonymousKit is described as operating like a criminal SaaS platform, phishing as a service, where operators pay a subscription and the platform handles execution. This kind of packaged infrastructure allows the same convincing lure and follow-up call script to be reused at scale against many victims.

What to watch for

  • An unexpected message claiming a lost device has been found, arriving by email or text
  • Any request for a passcode, Apple ID, or two-factor authentication code
  • Embedded maps or location details meant to make the message feel more credible
  • A follow-up phone call from someone claiming to be Apple Support asking for verification details

How to build resistance

Treat any unsolicited

Key findings

  • SOC Radar investigated an iPhone-theft-focused criminal operation called “AnonymousKit,” described as a “criminal SaaS operation.”
  • AnonymousKit is positioned as “phishing as a service,” where criminals “pay a subscription” and the platform “does the rest.”
  • The lure uses an Apple impersonation message: “Good news, we found your lost device,” including “a little map embedded in the HTML of the email.”
  • The operation aims to capture “their passcode, their Apple ID … and their 2FA code as well.”
  • The attack may add a follow-up phone call: “you get a call from someone called Alice from Apple Suppor...” (Apple Support impersonation).

Who’s being targeted

  • Commonly targeted roles: All employees, Executives, Helpdesk / IT support (to advise users during device-loss events), Finance (high-value targets likely to have sensitive apps on phones).
  • Affected industries: Consumers / individuals (smartphone owners).
  • Attack channels: email, smishing, vishing.
  • Impersonated: Apple, Apple Support.

Red flags to watch for

  • Unexpected “found your device” message soon after a loss (high emotional pressure)
  • Request for passcode/Apple ID/2FA codes (Apple should not need your passcode)
  • Email content designed to look “real” with embedded map to lower suspicion
  • SMS purporting to be Apple about a lost device
  • Pressure to act quickly to recover a valuable device
  • Any request for 2FA codes is a strong sign of fraud
  • Inbound call after a “found device” message pushing you to share credentials
  • Caller asks for passcodes or one-time codes
  • Caller identity cannot be independently verified
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

How does the fake Apple lost iPhone scam work?

Victims get an email or text claiming to come from Apple saying a lost device was found, often with a map embedded in the HTML, and are pressured into entering their passcode, Apple ID, and 2FA code.

What is AnonymousKit?

AnonymousKit is described as a criminal SaaS operation, or phishing as a service, where criminals pay a subscription and the platform handles the fraudulent messaging and infrastructure.

Does the scam ever involve a phone call?

Yes, the attack can escalate with a follow-up call from someone posing as Apple Support who asks the victim to provide credentials or a 2FA code to verify identity.

What information should I never share if I get a lost device message?

Never share your device passcode, Apple ID password, or any two-factor authentication code, since these are exactly what attackers need to take over an account or device.

Read the video transcript

You’ve just lost your iPhone… then ping: “Good news, we found your lost device,” from “Apple,” with a little map. Behind that message is a criminal SaaS called AnonymousKit. Thieves pay a subscription, it sends Apple-lookalike emails and texts, then funnels you to a fake page to grab your passcode, Apple ID, and even your 2FA code. The twist: after the email or text, you might even get a call from “Alice from Apple Support,” calmly asking you to read out your 2FA code to “secure your phone.” That one code lets them take everything. If you ever see “Good news, we found your lost device,” ignore the link and the call, open the Find My app or iCloud.com yourself and check there.

Similar attacks

Scammers Shift Lures to Email, Text, and Social

Scammers Shift Lures to Email, Text, and Social

Malwarebytes reports that scammers are increasingly tailoring different scams to the platforms where they work best, like unpaid-toll lures via email/SMS, romance scams via social media, and IRS scams via phone calls. The report highlights heavy brand and celebrity impersonation (including MrBeast)…

September 2, 2026
AI Voice “Apple Support” Phishing + Fake IT Helpdesk

AI Voice “Apple Support” Phishing + Fake IT Helpdesk

This news roundup describes real social-engineering operations where attackers impersonate trusted support teams to trick people into giving up secrets. One campaign uses email/SMS/WhatsApp plus AI voice calls pretending to be Apple Support to steal iPhone passcodes, while another uses phishing…

August 27, 2026
AI “Apple Support” Calls Steal iPhone Passcodes

AI “Apple Support” Calls Steal iPhone Passcodes

Researchers say a phishing-as-a-service platform called AnonyMousKIT targets people who recently lost or had an iPhone stolen by pretending to be “Apple Support.” The operation uses email/SMS/WhatsApp and AI-assisted voice calls to convince victims to share their iPhone passcode and follow a…

August 26, 2026
AI “Apple Support” Calls Steal Passcodes & 2FA

AI “Apple Support” Calls Steal Passcodes & 2FA

Researchers uncovered a phishing-as-a-service platform (“AnonyMousKIT”) used by phone thieves to trick victims into handing over iPhone passcodes, Apple ID passwords, and live 2FA codes so thieves can remove Apple’s Activation Lock. The operation uses Apple-branded emails/pages and AI voice agents…

August 26, 2026
Fraud Ring Targets Crypto Users via Phone + Phish

Fraud Ring Targets Crypto Users via Phone + Phish

Researchers described a real fraud operation that first verified which phone numbers were tied to cryptocurrency exchange accounts, then targeted confirmed owners. The attackers used phishing emails, vishing calls, and fake wallet apps while impersonating popular hardware/software wallet brands,…

August 18, 2026
SafePal Data Exposure Sparks Targeted Phishing Risk

SafePal Data Exposure Sparks Targeted Phishing Risk

SafePal disclosed that nearly 40,000 customers had personal and order information exposed due to an authorization flaw in an order-tracking plug-in. While wallet secrets were not exposed, SafePal warned that criminals can use the leaked order details to run highly convincing scams (fake support,…

August 17, 2026