Thieves are using fake Apple support AI calls to trick victims into handing over sensitive information, leaving their devices vulnerable to theft and financial loss.
In a disturbing trend, scammers have been posing as representatives from Apple’s technical support team, contacting individuals whose devices have been reported stolen or suspected of being compromised. The goal is simple: extract the owner’s passcode and two-factor authentication (2FA) codes, providing the thieves with unfettered access to the device.
These fake calls are often initiated by AI-powered systems designed to mimic real customer support interactions. Once established, the scammers use a combination of social engineering tactics and carefully crafted questions to elicit sensitive information from their targets. The stolen passcode and 2FA codes can then be used to unlock the device, allowing the thieves to access personal data, drain bank accounts, or even sell the device on the black market.
Victims are often unaware they’re being targeted by a scam, as the calls appear to come from genuine Apple support numbers. The scammers may even have access to some of the victim’s personal information, making their claims seem more convincing. This can include details such as the device’s serial number or the owner’s registered email address.
The threat is particularly concerning for individuals who use cloud-based services like iCloud, which store sensitive data and authentication tokens. If an attacker gains access to these credentials, they can reset passwords, take control of accounts, and potentially even reset security questions – further compromising the victim’s online identity.
This type of phishing campaign relies on exploiting the trust relationship between a device owner and their supposed support team. Scammers are taking advantage of this vulnerability by using AI-driven systems that mimic human-like conversations, making it increasingly difficult for victims to distinguish genuine from fake interactions.
As we’ve seen in recent years, cyber threats continue to evolve at an alarming rate. This particular tactic may seem sophisticated, but its underlying mechanics are relatively simple: social engineering and exploitation of trust. To avoid falling prey to such attacks, device owners must remain vigilant when receiving unsolicited calls – especially those claiming to be from support teams. Verification through multiple channels is crucial; it’s always better to contact the organization directly using a known number or method rather than relying on a caller who claims to be from their support team.
Source: The Hacker News — 2026-08-26