Apple has a security flaw
Criminals selling stolen iPhones and iPads face one big obstacle: Apple's Activation Lock, which ties a device to its owner's Apple ID. A criminal service called AnonyMousKIT automates the phishing calls, texts, and emails needed to trick device owners into handing over their passcode, Apple ID login, and a live two-factor code, so thieves can unlock and resell the hardware.
- Report priority
- Medium
- Targets
- iPhone+2 more
How it works
Operators load a stolen device's real model and Find My status into the platform, which then sends the owner a fake 'your device has been found' message by email, text, WhatsApp, or an AI-voiced phone call posing as Apple Support, and walks them through entering their passcode, Apple ID password, and current 2FA code on a lookalike Apple or Find My page.
What to do
If an Apple device of yours was recently lost or stolen and you then get an unsolicited message or call claiming to help you recover it or reporting it's been found, never enter your passcode, Apple ID password, or a 2FA code in response to an unexpected recovery message or call. Go directly to Apple's own or Find My app to check a device's status, and report a stolen device and lock it through Apple's official Find My tools instead of any link in a text, email, or call.
Technical details
A thief steals an iPhone and feeds its model and Find My status into the AnonyMousKIT panel. The platform emails the owner from an address disguised as Apple, with a subject like 'Your device has been found,' linking to a fake Find My page. The owner enters their device passcode, Apple ID password, and current 2FA code to 'recover' the phone, and that data lands in the criminal's dashboard within seconds, letting them strip Activation Lock and resell the device.
AnonyMousKIT is a phishing-as-a-service platform, exposed by SOCRadar's Threat Research Unit after researchers found production logs and source code left reachable through unauthenticated relative file paths in its own codebase. The platform profiles stolen Apple devices, then runs multi-channel lures (email, SMS, WhatsApp, and AI voice calls impersonating Apple Support in English, Spanish, and Portuguese) that funnel victims through a spoofed Apple/Find My page requesting passcode, Apple ID, and a live 2FA code. SOCRadar tied the family to 506 domains, 168 storefront brands, and 30 backend deployments across 42 domains, active since early 2024.