Fake “Apple Support” FaceTime Calls Drain Accounts

Malwarebytes · Medium sophistication
Last updated July 31, 2026

Apple warns that scammers are placing unsolicited FaceTime calls and sending urgent-looking messages that appear to come from “Apple Support” or a bank. The callers use pressure and fear (fraud alerts, refunds, account issues) to trick victims into sharing passwords, banking details, or one-time passcodes, and sometimes to install remote-access software.

How the attack worked

This attack relies on unsolicited FaceTime calls that appear to come from “Apple Support” or a bank. The caller claims there is fraudulent activity or a technical problem on the victim's account, creating a sense of urgency. Once the victim is engaged, the caller pressures them to “verify” card details, online banking credentials, or Apple ID information. In some cases, the attacker also asks the victim to share a one-time passcode or to install remote-access software so the caller can supposedly fix the problem.

Why it succeeded

Nothing in this process requires malware on the device. The exploit is human trust, reinforced by familiar branding, logos, and the immediacy of a real-time call, which tends to feel more legitimate than a text message or email. A live voice call also gives the attacker room to adapt in real time, respond to hesitation, and keep pressure on the target until they comply. Because the pretext touches on money, security, or account access, it taps directly into fear of loss, which tends to override normal skepticism.

What to watch for

  • An unsolicited FaceTime call claiming to be from Apple or a bank
  • Urgent language about fraud, refunds, or account problems that demands immediate action
  • Any request to “verify” a password, card number, banking credential, or Apple ID detail over the call
  • A request to read out or share a one-time passcode
  • A request to install remote-access software from someone who called unprompted

These red flags apply whether the contact starts as a FaceTime call or as a text message that leads into one.

How to build resistance

  • Treat any unexpected FaceTime call or message about payments, refunds, password resets, or personal information as untrusted, even if the caller ID looks legitimate
  • Never share passwords, banking credentials, card numbers, or one-time passcodes during an unsolicited call or text
  • Verify the request by contacting the organization directly through a known, trusted channel, not a number or link supplied by the caller
  • Report suspicious FaceTime calls by emailing a screenshot of the call information to reportfacetimefraud[@]apple.com
  • Encourage employees, especially in finance and executive roles, to report suspicious calls quickly so others can be warned before they are targeted

Because this technique targets judgment rather than technical defenses, awareness and a habit of independently verifying unexpected requests are the most effective safeguards.

Key findings

  • Scammers have been reported making unsolicited FaceTime calls that look like they come from “Apple Support” or a bank.
  • The pretext commonly involves claimed fraud, urgent account alerts, or refunds.
  • Attackers pressure victims to share card details, online banking credentials, Apple ID information, or one-time passcodes.
  • Some victims are persuaded to install remote-access software; malware is not required because the main exploit is human trust.
  • Apple advises treating unexpected FaceTime calls/messages as untrusted and reporting suspicious FaceTime calls via screenshot to reportfacetimefraud@apple.com.

Who’s being targeted

  • Commonly targeted roles: All employees, Finance, Executives, IT/Helpdesk.
  • Affected industries: Banking, Consumer finance, Technology (mobile device users).
  • Attack channels: vishing.
  • Impersonated: Apple Support (or a bank), Apple Support.

Red flags to watch for

  • Unsolicited FaceTime call claiming to be Apple or a bank
  • Pressure/urgency to “verify” sensitive details immediately
  • Requests for one-time passcodes or credentials over a call
  • Request to share a one-time passcode (OTP) over FaceTime/phone
  • Request to install remote-access software from an unsolicited caller
  • Caller uses Apple branding/trust cues to bypass normal verification
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

How do scammers use FaceTime to steal money?

Attackers place unsolicited FaceTime calls that appear to come from Apple Support or a bank, then use claims of fraud or account problems to pressure victims into sharing card details, banking credentials, Apple ID information, or one-time passcodes.

Do these scams require malware?

No. The attack relies on human trust rather than malicious software, though some victims are persuaded to install remote-access software or hand over one-time passcodes.

How can I verify if a FaceTime call from Apple Support is real?

Apple advises treating unexpected FaceTime calls or messages about payments, refunds, or personal information as untrusted and contacting companies directly through trusted channels rather than numbers or links provided by the caller.

What should I do if I receive a suspicious FaceTime call?

Apple recommends emailing a screenshot of the call information to `reportfacetimefraud[@]apple.com` so the report can be reviewed.

Read the video transcript

You get a FaceTime call: the screen says “Apple Support.” Fraud alert. Urgent. What do you do? The caller says, “Hi, this is Apple Support, there’s fraudulent activity on your account. I’ll send a verification code; read it back to me so we can secure your card and Apple ID.” Here’s the trick: real Apple Support will NOT ask for your Apple ID password, banking login, card details, or one-time passcodes over FaceTime or text, ever. If they do, it’s a scam draining your accounts, not helping you. If you get an unexpected FaceTime about payments or refunds, hang up. Then screenshot the call info and email it to reportfacetimefraud@apple.com, and let our security team know.

Similar attacks

Fake CoD Points Giveaway Steals Accounts

Fake CoD Points Giveaway Steals Accounts

A phishing campaign targets Call of Duty Mobile players by promising free Call of Duty Points (CP). Victims are tricked into entering their email, password,…

July 24, 2026