top of page

AI-Powered Phishing Service Targets Stolen iPhones and Apple IDs

  • 15 hours ago
  • 3 min read


Researchers have uncovered a sophisticated phishing-as-a-service (PhaaS) platform called AnonyMousKIT, which uses AI-powered voice agents, phishing websites and automated messaging to trick victims into revealing Apple account credentials, device passcodes and two-factor authentication (2FA) codes. According to SOCRadar, the platform has been operating since early 2024 and is linked to over 500 phishing domains and more than 160 reseller storefronts, supporting a large-scale ecosystem focused on unlocking stolen iPhones and accessing associated user data.The service exploits Apple's Activation Lock security feature, which is designed to prevent stolen devices from being reused. Even after a factory reset, an iPhone remains tied to the owner's Apple account until the correct credentials are supplied. This significantly reduces the resale value of stolen devices, making account compromise a lucrative objective for cyber criminals.


To bypass these protections, attackers extract information from stolen devices, including contact details displayed through Apple's Lost Mode feature. Victims are then contacted via email, SMS, WhatsApp or phone calls that appear to originate from Apple. The messages often claim that a missing device has been recovered and include legitimate details such as the device model and IMEI number to increase credibility. A notable feature of the operation is its use of AI-generated voice agents. In cases analysed by SOCRadar, victims received calls from an automated persona claiming to be "Alice from Apple Support." The caller informed victims that their device had been recovered and requested verification of ownership by providing the device passcode. Victims were then directed to convincing phishing websites designed to mimic Apple's Find My or account portals, where they were prompted to enter Apple ID credentials and authentication codes. Once attackers obtain this information, they can remove Activation Lock, access iCloud backups, compromise Keychain-stored passwords and reset the device for resale. Beyond personal impacts, the compromise of an Apple account can also expose business email, corporate documents and other organisational data stored on personally owned or employer-issued devices.


AI voice technology enables threat actors to conduct highly convincing interactions at very low cost, while automation allows campaigns to be launched across multiple countries simultaneously. SOCRadar has found evidence of activity targeting victims globally, with concentrations reported in Brazil, South Africa, Indonesia, India, Kenya and Italy.

While the campaign primarily targets consumers whose devices have been lost or stolen, researchers also identified phishing activity directed at corporate and government email addresses. This highlights the growing risk that personal-device compromises can lead to broader organisational security incidents, particularly where mobile devices are used to access work applications, cloud services and email accounts.


The UK National Cyber Security Centre (NCSC) advises organisations and individuals to remain vigilant against phishing attempts that seek to obtain passwords, passcodes or authentication codes through emails, text messages or phone calls. The NCSC notes that criminals increasingly use convincing social engineering tactics and trusted brands to persuade victims to disclose sensitive information.


Key Advice includes:

  • Never share passwords, device passcodes or authentication codes with anyone who contacts you unexpectedly, even if they claim to be from a trusted organisation.

  • Treat unsolicited emails, texts and phone calls with caution, particularly those creating urgency or requesting account verification.

  • Enable multi-factor authentication (MFA) on all accounts to reduce the risk of credential compromise.

  • Verify requests independently by contacting the organisation through official channels rather than using links or phone numbers provided in the messages.

  • Report suspected phishing messages to your organisation's IT team or relevant reporting channels and delete them if confirmed as malicious. You can report text messages by forwarding them to 7726 and you can report phishing emails to the NCSC by forwarding them to report@phishing.gov.uk


The emergence of platforms such as AnonyMousKIT demonstrates how cyber criminals are leveraging AI and automation to industrialise phishing operations. As voice-based social engineering becomes more convincing, users should assume that legitimate organisations will never ask for account credentials, authentication codes or device passcodes over email and text message or call you out of the blue.

bottom of page