Global Scam IntelligenceDaily updates on global scam news and tactics
Back to home
PhishingPublished: August 27, 2026🌐

AI-Powered Apple Support Scam Targets Stolen iPhones with 500+ Fake Domains

A large-scale phishing scam targeting stolen iPhones has been discovered, using AI voice calls to trick victims into revealing passcodes and authentication credentials. The criminal operation employs over 500 fake domains impersonating Apple Support in multiple languages, with the goal of bypassing Activation Lock to resell stolen devices.

How the Scam Works

A sophisticated fraud scheme targeting stolen iPhones has been discovered, operating as an organized service for bypassing Activation Lock. Rather than isolated incidents, this criminal operation has continuously evolved since early 2024 into a large-scale infrastructure. Researchers identified 506 domains, 168 associated brand names, with 188 domains actively operating at the time of investigation.

Step-by-Step Attack:

  1. Initial Contact: Criminals pre-register victims' phone numbers, names, and device information into their system, then contact them impersonating Apple Support via email, SMS, or phone calls.

  2. AI Voice Calls: Attacks include automated AI voice calls mimicking Apple Support representatives in English, Spanish, and Brazilian Portuguese. These low-cost automated calls request passcodes under the guise of verification.

  3. Credential Harvesting: After obtaining the passcode, victims are redirected via SMS to fake websites where they enter their Apple Account password and two-factor authentication codes.

  4. Activation Lock Bypass: With these credentials, criminals can remove Activation Lock—Apple's core anti-theft protection—allowing them to resell the stolen device.

How to Identify the Scam

What Apple Never Does:

  • Contact users to say a lost device has been found
  • Request passwords, passcodes, or 2FA codes
  • Ask users to sign in through received links
  • Demand users disable security features like Find My

Red Flags in Scam Attempts:

  • Requests for any of the above information
  • Redirects to suspicious websites
  • Artificial urgency or threats
  • Unsolicited phone calls or messages about device issues

Phone calls and emails alone cannot distinguish real from fake communications. Evaluate the information being requested—legitimate Apple support never asks for authentication credentials.

Prevention and Protection Tips

Device Settings:

  • Enable "Stolen Device Protection" in iOS settings
  • Set a strong passcode using numbers, letters, and symbols
  • Prevent shoulder surfing in public spaces
  • For unrecognized Apple Account communications, verify through Settings or Apple's official website rather than clicking email links
  • If your iPhone is lost, do not immediately remove it from "Find My" or your Apple Account, maintaining remote lock capabilities

Geographic Impact

Of approximately 200 recovered AI voice calls reviewed, about 90% targeted Brazilian phone numbers, with no Japanese-targeted calls detected. However, this reflects only recovered call records; the full scope of email and message-based campaigns may have broader geographic reach, including Japan.

Understanding these tactics and maintaining proper device security settings provides the strongest defense against evolving Apple-based phishing schemes.

Source: iPhone Mania

Share