Cybersecurity

Fake Apple Support AI Calls Target Stolen-Device Owners for Passcodes and 2FA Codes

By Parviz Nasirov
Fake Apple Support AI Calls Steal iPhone Passcodes and 2FA Codes

Cybersecurity researchers have uncovered a phishing-as-a-service platform called AnonyMousKIT that targets owners of lost or stolen Apple devices with fake Apple Support emails, SMS messages, WhatsApp lures, recorded calls, and AI-generated voice agents. The goal is to steal device passcodes, Apple ID credentials, and live 2FA codes so criminals can remove Activation Lock and resell stolen devices.

Cybersecurity researchers have disclosed a sophisticated phishing operation that combines AI-generated voice calls, fake Apple Support pages, SMS, email, and WhatsApp messaging to target people whose iPhones or other Apple devices have been lost or stolen.

The platform, tracked as AnonyMousKIT, operates as a phishing-as-a-service business designed to help criminals remove Apple's Activation Lock from stolen devices.

Rather than relying on technical bypasses alone, the operation focuses heavily on social engineering.

Victims are contacted by attackers pretending to be Apple Support and are asked to provide:

  • The device's 4- or 6-digit passcode
  • Apple ID credentials
  • A live two-factor authentication code

Apple's official guidance explicitly states that the company will never ask users to provide passwords, device passcodes, or 2FA codes as part of support interactions.

AnonyMousKIT Operates Like a Criminal SaaS Business

Researchers say AnonyMousKIT is structured less like a traditional phishing kit and more like a small software business.

The platform includes:

  • Credit-based pricing
  • Subscription tiers
  • Customer support
  • Status tracking
  • Infrastructure replacement procedures
  • Multiple communication channels

According to the research, operators can launch lures through:

  • Email
  • SMS
  • WhatsApp
  • Recorded voice calls
  • AI voice agents

The AI voice-agent option reportedly costs 2 credits per use, while a recorded voice call costs 1 credit.

This type of service lowers the technical barrier for criminals because they do not need to build their own phishing infrastructure or voice automation system.

Stolen-Device Owners Are Specifically Targeted

The campaign focuses on people whose Apple devices have recently been lost or stolen.

Attackers use information extracted from the stolen hardware, including:

  • Apple internal model identifiers
  • Live Find My status
  • Device location information

Victims may receive messages claiming that their device has been found.

If they follow the link, they are taken to an Apple-themed phishing page that may even display an animated map showing the device's reported location.

This makes the social-engineering lure highly convincing because the victim already expects communication related to the missing device.

AI Voice Agents Impersonate Apple Support

One of the most significant findings is the use of AI-generated voice agents.

Researchers recovered:

  • 200 call records
  • 55 transcripts
  • Five configured AI personas

All five voice personas reportedly used the same identity: “Alice from Apple Support”, delivered in English, Spanish, and Portuguese.

The calls were placed between August 31, 2025 and May 30, 2026.

Out of 200 documented calls, 179 targeted phone numbers in Brazil.

During the calls, the AI agent asked victims to confirm ownership of the device, requested the phone's 4- or 6-digit passcode, and then repeated the digits back for confirmation.

The bot could also continue the conversation by claiming that someone had visited an Apple Store to remove Activation Lock and by asking whether the victim had received a recovery link via SMS.

AI Makes Vishing Extremely Cheap

The economics of the campaign are particularly concerning.

Researchers estimated that the 200 AI calls cost only $19.24 in total, or approximately 9.6 cents per call.

That dramatically changes the economics of voice phishing.

Traditional vishing campaigns require human operators to call victims individually.

AI voice agents can instead:

  • Call hundreds of victims automatically
  • Speak multiple languages
  • Follow scripted conversation flows
  • Collect passcodes
  • Operate continuously
  • Scale at very low cost

This allows cybercriminals to conduct personalized voice phishing campaigns at a fraction of the cost of human call centers.

Activation Lock Makes Stolen iPhones Difficult to Resell

Apple introduced Activation Lock with iOS 7.

The feature ties an Apple device to the owner's Apple ID and prevents the device from being activated by another person unless the original account is removed.

This makes stolen iPhones significantly less valuable.

Criminals therefore have a strong financial incentive to convince the legitimate owner to reveal the information needed to remove the lock.

Instead of breaking Apple's hardware security directly, attackers target the human owner.

The Attack Chain

A typical attack can follow a sequence like:

Device stolen
→ Find My information obtained
→ Victim receives “Your device has been found” message
→ Fake Apple Support page opened
→ Device passcode requested
→ Apple ID credentials stolen
→ Live 2FA code requested
→ Activation Lock removed
→ Stolen device becomes resellable

This illustrates why social engineering can sometimes be more effective than trying to technically exploit Apple's device security.

Thousands of Phishing Attempts Recorded

Researchers identified 506 domains associated with the broader phishing-kit family.

Among these:

  • 30 distinct installations were identified
  • They were reachable across 42 domains
  • 188 of the 506 domains were still live

The specific AnonyMousKIT deployment logged 691 send attempts between March and July 2026.

Across the wider family of related infrastructure, researchers observed 6,092 send attempts.

“Your Device Has Been Found” Is the Most Common Lure

The most common phishing email subject was:

“Your device has been found”

Researchers observed this subject in 308 of the 691 AnonyMousKIT email sends.

Another common subject was:

“Alert”

Display names impersonated:

  • Apple
  • Find My
  • Apple Support
  • Apple Assistance

Most emails also contained a location token naming a city, further increasing the appearance of legitimacy.

Attackers Abuse Gmail for Delivery

A large majority of the documented AnonyMousKIT emails were sent through a single free Gmail account.

Researchers found that 627 of 691 sends used the same Gmail relay account.

This demonstrates how threat actors can combine commercial AI services, free email providers, phishing infrastructure, and stolen-device data into a highly automated fraud operation.

No Confirmed Count of Stolen Credentials

It is important to distinguish attempted phishing activity from confirmed compromise.

The research documents large numbers of calls and phishing attempts, but it does not provide a confirmed total of passcodes, Apple IDs, or 2FA codes successfully captured.

For the 200 AI voice calls analyzed:

  • 100 victims hung up
  • 48 calls ended in silence timeouts
  • 24 were not answered
  • 28 encountered errors or busy lines

The report therefore demonstrates operational scale, but not a verified number of successful account takeovers.

Apple Says It Will Never Ask for These Codes

Apple's security guidance is extremely clear.

Apple says it will never ask users to:

  • Enter credentials on an unfamiliar website
  • Provide their Apple Account password
  • Provide their device passcode
  • Provide a two-factor authentication code
  • Approve an unexpected 2FA prompt

Users receiving such requests should assume the interaction may be fraudulent.

How Apple Users Can Protect Themselves

Owners of Apple devices should follow several precautions, particularly after a device has been lost or stolen:

  • Never provide your iPhone passcode to someone claiming to be Apple Support.
  • Never share a two-factor authentication code over the phone.
  • Do not enter Apple credentials through links received by SMS, email, or WhatsApp.
  • Access Find My directly through Apple's official apps or website.
  • Keep Activation Lock enabled.
  • Do not remove the stolen device from your Apple account simply because someone asks you to.
  • Verify support interactions directly through Apple's official channels.
  • Treat unexpected calls claiming a stolen device was found as suspicious.
  • Use hardware security keys for high-value Apple accounts where appropriate.
  • Report Apple-branded phishing messages to Apple's official phishing-reporting address.

Hardware security keys can provide additional protection against real-time 2FA interception because possession of the physical security key is required for authentication.

Analysis and context

The AnonyMousKIT campaign demonstrates a major change in phishing economics.

The important innovation is not simply that attackers are using synthetic voices.

The bigger issue is that AI makes personalized social engineering inexpensive enough to automate at scale.

AI Turns Vishing Into Automation

Traditional voice phishing is expensive.

Attackers need:

  • Call-center operators
  • Language skills
  • Scripts
  • Training
  • Time

AI voice systems eliminate much of that overhead.

For less than ten cents per call in the observed campaign, attackers could automatically contact stolen-device owners and attempt to guide them through a multi-step social-engineering process.

That means voice phishing can increasingly operate like email spam:

low cost + automation + large volume.

Context Makes the Attack Convincing

These calls are particularly dangerous because they are not random.

The victim actually has a missing or stolen Apple device.

The attacker may know:

  • Which device was stolen
  • Its model
  • Its Find My status
  • Its approximate location

Therefore, when someone calls saying:

“This is Apple Support. We found your iPhone.”

the story fits the victim's real situation.

This dramatically increases the credibility of the attack.

Humans Become the Activation Lock Bypass

Apple's Activation Lock is technically strong.

The campaign highlights an important security principle:

When a technical control is difficult to bypass, attackers often target the person authorized to disable it.

Instead of breaking the Secure Enclave or Apple's authentication architecture, criminals ask the owner for the necessary credentials.

This is often cheaper, faster, and more reliable.

2FA Is Not Immune to Social Engineering

Two-factor authentication significantly improves security, but real-time phishing can still defeat some forms of 2FA if the victim voluntarily provides the code.

This is why users should understand that:

A 2FA code is effectively a temporary password.

Anyone requesting it should be treated with extreme suspicion.

Phishing-resistant authentication methods such as hardware security keys are significantly stronger because the user cannot simply read a reusable code to the attacker.

AI Voice Changes the Meaning of “Trust Your Ears”

For years, users were taught that calling a company or speaking with a professional-sounding support representative offered additional reassurance.

AI voice generation weakens that assumption.

A calm, natural, multilingual voice is no longer strong evidence that a caller is legitimate.

Users increasingly need to validate identity through trusted channels, rather than through how convincing a voice sounds.

Phishing-as-a-Service Is Becoming More Professional

AnonyMousKIT also demonstrates how cybercrime increasingly resembles legitimate SaaS.

Features such as:

  • Pricing plans
  • Credit systems
  • Customer support
  • Subscription tiers
  • Multi-channel campaigns

allow less technically skilled criminals to conduct sophisticated fraud operations.

The technical capabilities are provided as a service.

The criminal customer only needs the victim information.

The Bigger Security Lesson

The wider lesson is that AI does not need to discover zero-days or create advanced malware to significantly increase cyber risk.

AI can make existing attack techniques cheaper, faster, and more scalable.

Voice phishing is a perfect example.

The attack technique already existed.

AI transforms the economics.

For users and security teams, this means identity verification procedures must adapt to a world where:

voices can be synthetic, support agents can be bots, and convincing personalized calls can be generated at industrial scale.

Source: SOCRadar Threat Research Unit, Apple security guidance, and reporting by The Hacker News, August 26, 2026.