An overseas security company has reported that a method has been confirmed in which an AI poses as a fake Apple supporter and asks for the passcode from the owner of a stolen iPhone. It appears to be operating as a large-scale phishing platform using over 500 domains, with the aim of unlocking anti-theft protection and reselling it.
Phishing service targeting stolen iPhones now available
The most distinctive feature of this method is that it is not a crime based on an individual’s imagination, but is structured as a “service” that undertakes the unlocking of stolen Apple products. According to an overseas security company, code related to the same mechanism has been observed since early 2024 and has developed into a shadowy platform that supports the unlocking and resale of stolen iPhones.
A total of 506 domains were confirmed, with 168 associated store brand names, and 188 domains were said to be in operation at the time of the investigation. It cannot be overlooked that the tools and automation are so well developed that even unskilled people can commit fraud.
Flow of inducement to steal Apple Account
The owner of the stolen iPhone is tricked into giving information little by little through a multi-step process that includes emails, SMS, and phone calls.
Contact using owner information
The criminals register the owner’s phone number, name, and device information in their system in advance, and then contact them pretending to be from Apple. Since contacts can be displayed on the iPhone’s lost mode, it is possible that the information was obtained from there, but this investigation has not determined the route by which the information was obtained.
AI voice supports 3 languages
The method of communication is not limited to email, SMS, and messaging apps, but also includes voice calls using AI. The investigation revealed that voices impersonating Apple support personnel were available in three languages: English, Spanish, and Brazilian Portuguese, and were sent automatically at a low cost of about 100 yen per call.
Collect passcodes and authentication codes
The first goal of an AI call is to trick the caller into saying a four- or six-digit passcode under the guise of confirmation. The attacker will then send you an SMS to a fake website where you will be tricked into entering your Apple Account (formerly Apple ID) password and two-factor authentication code.
If these items are present, the owner’s account may be hijacked and data on iCloud may be accessed.
The purpose is to unlock a stolen iPhone.
What the culprit wants to obtain is the ability to remove the iPhone’s “activation lock.” Activation Lock is a core anti-theft measure for your iPhone that is linked to your Apple Account and prevents others from using your iPhone after it has been stolen.
This lock can be unlocked using Apple Account credentials or the device’s passcode, which criminals can then try to steal through phishing.
What is the impact on iPhone users in Japan?
Approximately 90% of the 200 recovered AI calls were to Brazil, and did not include calls to Japan or Japanese voices. However, this is only the range of call records that were recovered, and it cannot be concluded that Japan is not targeted in the entire activity, including emails.
Overseas, there have been reports of people stealing iPhones and hijacking Apple Accounts by stealing passcodes, so it seems worth knowing how the trick works before it spreads.
Protecting your iPhone starts with everyday measures
The first thing you should know to prevent damage is that Apple will never ask for your password, passcode, or two-factor authentication code. Apple will never contact you to tell you that your lost iPhone has been found.
Apple’s official policies and common examples of scams are summarized in the table below.
| Check points | Apple official policy | Typical example of fraud |
|---|---|---|
| Notification that the device was found | Apple will not contact you | Report “found” |
| Password/Passcode/2FA code | don’t ask | ask for confirmation |
| Sign in from the link you received | don’t ask | open a fake website |
| Security features | Don’t ask for deactivation | Turn off “Search” etc. |
| phone or email | May also be used for formal communication | cannot be determined by means alone |
As shown in the table, it is not possible to distinguish between genuine and fake products by telephone or email. It is safe to make decisions based on the information requested.
In addition, the following settings should be reviewed on a daily basis.
- Enable “Stolen Device Protection”
- Set an easy-to-guess alphanumeric passcode to prevent prying eyes in public places
- If you receive a message from an Apple Account that you do not recognize, do not open the link in the email, instead check the Settings app or official website.
- If you lose your iPhone, don’t immediately delete it from Find My or your Apple Account
Phishing scams pretending to be Apple continue to change their methods, and examples like this one using AI have also been confirmed. Knowing how it works and arranging the daily settings will be the best way to protect your iPhone.
Source: iPhone Mania