Stolen iPhone Scam Warning: AI “Apple Support” Calls Can Steal Your Passcode

Stolen iPhone Scam Warning: AI “Apple Support” Calls Can Steal Your Passcode


The theft is only step one. What comes after is designed to make you finish the job yourself.

Security researchers at SOCRadar have uncovered AnonyMousKIT, a phishing-as-a-service operation built specifically to help criminals steal Apple credentials and disable Activation Lock on stolen iPhones. SOCRadar describes it as less like a conventional phishing kit and more like “a small software business with a criminal customer base.”

That distinction matters because the person calling you may not be a person at all. AnonyMousKIT can profile a stolen iPhone, build that information into a convincing Apple-themed lure, then use AI voice agents to call the owner and pressure them into handing over the credentials the thief needs. The scam is industrialized, multilingual and cheap enough to run at scale.

Your Stolen Phone Becomes Bait

Attackers can pull information about the stolen iPhone, including its exact model, associated identifiers and live Find My status. That information then gets fed into the attack. Victims who follow the resulting lure encounter Apple-themed pages with anti-bot checks, localized content and animated maps designed to create the impression that their missing phone has actually been located.

“AnonyMousKIT is a phishing-as-a-service platform specifically targeting Apple devices, with capabilities that include phishing pages, SMS, email and AI-powered voice calls,” SOCRadar says in its analysis of the operation. AnonyMousKIT runs five AI voice-agent personas across English, Spanish and Brazilian Portuguese. Three use the name “Alice Dias, Apple Support.”

SOCRadar describes the voice system as an automated, LLM-driven attack that can conduct dynamic vishing across multiple languages using the same structured information already supplied through email and SMS lures.

In other words, the criminal doesn’t need to speak Portuguese. They don’t need to maintain a convincing accent. They don’t even need to make the call themselves.

The Scam Runs On Pennies

AnonyMousKIT uses a credit system. SOCRadar found that an email costs 1.5 credits, a recorded voice call costs one credit and an AI voice-agent call costs two. Researchers recovered 200 call logs and 55 transcripts and calculated that the entire batch cost the operator just $19.24.

SOCRadar researchers found that 200 recovered calls and 55 transcripts cost the operator approximately $19.24 in total, showing how cheaply the AI-assisted operation can conduct voice phishing at scale. Of those 200 recovered calls, 179 went to Brazil.

The voice channel is only one part of the operation. SOCRadar identified 6,092 phishing emails across 30 related backends, targeting more than 5,000 devices that were still showing as online and more than 1,000 marked as locked. The researchers traced the infrastructure back to early 2024, and the campaign remained active through August 2026.

This is what changes when voice phishing becomes software. The attacker no longer needs to spend significant time persuading one victim. The same pretext can be delivered repeatedly, in different languages, using details specific to each stolen phone.

Activation Lock Still Works

There is an important misconception to avoid here: AnonyMousKIT does not break Apple’s Activation Lock.

“Activation Lock helps to prevent unauthorised users from reactivating an iPhone or iPad if it’s lost or stolen,” Apple says, noting that the protection remains enabled even after the device is erased. That’s precisely why the scam exists.

If criminals can’t defeat the protection technically, they can try to convince the person who controls it to defeat it for them.

A caller who knows your exact iPhone model or tells you that your device is currently showing as lost on Find My may sound legitimate. It isn’t. Those details are not proof that the caller works for Apple. They are proof that someone has information about your stolen phone.

That is the psychological trick at the center of the campaign. The more accurate the caller sounds, the easier it becomes to mistake stolen information for authentication.

Never Give Them The Code

“Apple will never ask you to log in to any website, or to tap Accept in the two-factor authentication dialogue, or to provide your password, device passcode or two-factor authentication code,” Apple says.

“If your iPhone or iPad has been stolen, put your device in Lost Mode as quickly as possible,” Apple advises. Apple also warns users not to remove a stolen device from Find My because doing so removes Activation Lock.

Don’t click the link they send. Don’t scan a QR code because the caller says it will help recover the phone. And don’t let accurate details about your device override the basic question: Did you contact Apple, or did someone contact you? If you need support, initiate the conversation yourself through Apple’s official channels.

The Human Is The Target

At roughly ten cents per AI voice attempt in the recovered sample, a criminal no longer needs to speak the target’s language fluently, maintain a believable accent or sit behind a phone for hours. The same structured story can be delivered repeatedly while the operator does something else.

That collapses a major cost and skill barrier in voice phishing. The technical defenses haven’t suddenly failed. Find My still works. Activation Lock still works. Apple’s account protections still work.

And that’s why a call that sounds exactly like Apple Support can be more dangerous than a badly written phishing email. The machine doesn’t need to break Apple’s security. It only needs to convince you to open the door.



Source link

Posted in

Liam Redmond

As an editor at Forbes Europe, I specialize in exploring business innovations and entrepreneurial success stories. My passion lies in delivering impactful content that resonates with readers and sparks meaningful conversations.

Leave a Comment