The fake Apple Support campaign built around AnonyMousKIT is particularly important because it combines physical device theft, phishing, real-time credential interception and AI-generated voice calls into one integrated criminal workflow. The objective is not merely to steal an Apple Account password. The platform is designed to help criminals convince owners of lost or stolen Apple devices to surrender the information needed to remove Apple’s Activation Lock and convert an otherwise difficult-to-resell device into usable merchandise. This makes the attack especially effective because it exploits a real event in the victim’s life. The person genuinely lost a phone, genuinely wants it back, and is therefore much more likely to believe a message or call claiming that the device has been found.

Activation Lock is one of Apple’s most important anti-theft controls. When Find My is enabled, an iPhone, iPad or other supported Apple device remains associated with the owner’s Apple Account even after the device is erased. A thief cannot simply reset the phone and resell it as a fully functional unlocked device. That protection significantly reduces the resale value of stolen hardware, which creates a strong financial incentive for criminals to attack the owner rather than trying to defeat the device technically. AnonyMousKIT effectively industrialises this social-engineering process by providing criminals with phishing pages, messaging infrastructure, campaign management, voice calls and AI-powered conversational agents.

The platform reportedly supports multiple channels including email, SMS, WhatsApp, prerecorded voice calls and AI-generated voice interactions. This is important because the attack is no longer confined to one phishing email that a user can identify and ignore. A victim may first receive an email stating that the missing device has been located, then a text message, and finally a phone call from someone claiming to be Apple Support. Each channel reinforces the others. The victim sees several apparently independent signals all supporting the same story, making the fraud much more believable.

The targeting is also highly contextual. Attackers may know the model of the stolen phone, information associated with the device and potentially its location. Victims can be shown Apple-branded pages with maps or device details that appear to prove that the caller has legitimate access to Find My information. This is far more persuasive than a generic message claiming that an Apple Account has been compromised. The attacker is exploiting a real theft and using genuine contextual information to create trust.

The typical attack attempts to collect secrets progressively. The victim may first be asked for the four- or six-digit device passcode, then their Apple Account credentials, and finally a live two-factor authentication code. Each piece of information increases the attacker’s ability to control the device or associated account. The device passcode is especially sensitive because many users think of it merely as a screen-unlock PIN, when in reality possession of the device plus knowledge of the passcode can provide substantial authority over account and security settings.

A simple defensive principle is therefore extremely important: legitimate support personnel should never need the secret that protects the user from impersonation. Users should never disclose their Apple Account password, device passcode or two-factor authentication code to anyone calling, texting or emailing them. If a person claiming to represent Apple requests any of these, the interaction should be treated as fraudulent regardless of how convincing the caller sounds or how much accurate information they appear to know.

The AI voice component is one of the most interesting aspects of the campaign because it removes one of the traditional limitations of telephone-based social engineering: the need for a human scammer on every call. The attackers can deploy synthetic support agents that communicate naturally, ask follow-up questions, react to the victim’s answers and maintain the appearance of a real customer-service interaction. Recovered examples reportedly included personas such as “Alice from Apple Support” and could operate in multiple languages.

This changes the economics of vishing significantly. Traditional voice scams require recruitment, training and management of human operators. AI-generated calls can be launched at much larger scale and at very low marginal cost. Hundreds of personalised calls can be conducted for relatively little money, and the system can operate continuously without needing a correspondingly large call centre. The attack therefore becomes less limited by labour and more limited by how many targets the criminal can obtain.

That does not mean AI automatically makes the scam successful. Many victims still hang up or ignore the calls. But attackers do not require a high success rate when each attempt costs almost nothing. Even a very small conversion rate can become profitable if thousands of targets can be contacted. This is the same economic principle that made spam and phishing viable for decades, except AI adds much better personalisation and conversational capability.

The voice interaction also creates psychological pressure that static phishing lacks. A caller can reassure the victim, explain why each step is supposedly necessary and respond to hesitation. If the victim questions why a passcode is needed, the AI agent can provide a convincing explanation. If the victim reads digits incorrectly, the system can repeat them back. This conversational feedback makes the experience feel more like dealing with a genuine support representative.

Another important lesson is that knowing personal information should no longer be treated as proof of legitimacy. In this campaign, criminals may already possess details about the stolen device. A caller who knows the model of the phone, the city where it was located or the victim’s phone number may simply be demonstrating that they control the stolen device or associated data. Accurate personal information increasingly proves that information has been exposed, not that the caller is trustworthy.

The same principle applies to caller ID. A call that appears to originate from a legitimate or familiar number should not be considered authenticated. Telephone caller ID was never designed as a strong cryptographic identity mechanism and can be spoofed. Users should authenticate organisations independently rather than relying on whatever number appears on the screen.

Two-factor authentication remains essential, but this attack illustrates the limitations of OTP-based authentication. A six-digit code protects against an attacker who merely stole a password, but it does not protect against a victim who is persuaded to read the code aloud in real time. This is why phishing-resistant authentication methods such as passkeys and hardware security keys provide a stronger model. They bind authentication to the legitimate site and cannot simply be dictated over the phone.

The attack also demonstrates how effective contextual phishing can be. A generic security message may be ignored, but a message saying “Your stolen iPhone has been found” reaches a victim who is already worried, hopeful and actively waiting for information. Attackers exploit that emotional state. Security awareness should therefore teach users that the most convincing fraud often appears immediately after a real incident such as a device theft, delivery problem, bank transaction or account reset.

Users should always verify stolen-device information independently. If a message claims that an iPhone has been found, they should open Find My directly from a trusted device or manually access the legitimate Apple service. They should never use a link provided in the suspicious message. If the information is genuine, the status should be visible through the legitimate account.

The same approach should be used for telephone support. If someone calls claiming to represent Apple, the user should end the call and independently contact Apple through official support channels. They should not call back a number contained in the message or provided by the caller. Breaking the attacker-controlled communication channel is one of the simplest ways to defeat social engineering.

Users should also never remove a stolen device from their Apple Account because someone claims that doing so is necessary to locate, verify or return it. Removing the device can disable Activation Lock and provide the thief with exactly what they need. The device should remain associated with the legitimate account even if recovery appears unlikely.

Organisations managing corporate Apple devices need stronger procedures. A stolen corporate phone should be treated not only as a hardware-loss event but also as a potential identity-security incident. Employees should immediately report the theft, remotely lock or erase the device where appropriate, revoke sensitive sessions, contact the carrier and receive explicit warning that follow-up phishing or vishing attempts may occur.

Security teams should expect criminals to contact the employee after the theft. Password-reset attempts, unusual MFA prompts and suspicious authentication activity associated with the affected employee should receive additional monitoring. A stolen phone may provide attackers with enough contextual information to launch attacks against corporate SSO, email or help-desk processes.

Corporate security awareness should therefore include a specific stolen-device procedure. Employees should know that no legitimate IT department or vendor support team will ask them to provide passwords, device passcodes or one-time authentication codes during an unsolicited call. Help desks should also use strong identity-verification procedures so attackers cannot exploit the stolen device and associated employee information to reset corporate credentials.

Email, DNS and web-security controls can reduce exposure to phishing infrastructure associated with these campaigns. Lookalike domains, newly registered Apple-themed domains and suspicious device-recovery pages can be blocked. However, technical blocking alone cannot keep pace with rapidly changing criminal infrastructure. The more durable defence is to ensure that users do not surrender secrets even when the phishing page reaches them.

Phishing-resistant authentication is especially valuable because it changes the security model from “teach the user to recognise every fake website” to “make the credential unusable on the fake website.” That is a much stronger design because humans are inconsistent, while cryptographic origin validation is considerably less impressed by a convincing Apple logo.

The campaign also has broader implications for AI service providers. Commercial voice platforms have legitimate uses, but the same capability can be used to automate impersonation and fraud. Providers need abuse-detection mechanisms capable of identifying suspicious patterns such as large numbers of calls impersonating major brands, repeated requests for passwords or authentication codes, and identical scripts targeting unrelated individuals.

AI does not need to invent a completely new cyberattack to have a major impact. Its value to criminals may simply be reducing cost, increasing scale and improving personalisation. That can be enough to transform an existing fraud technique into a significantly larger threat.

The AnonyMousKIT operation also demonstrates how mature cybercrime-as-a-service has become. Criminal customers can purchase infrastructure rather than develop it. One actor may steal the physical device, another may operate the phishing platform, a third may provide voice infrastructure, and another may resell the unlocked phone. Each participant specialises in one portion of the attack chain.

This resembles the evolution of ransomware-as-a-service, where malware developers separated themselves from the operators conducting intrusions. Phishing-as-a-service and AI-enabled fraud are following the same path. Sophisticated capabilities are increasingly packaged into commercial services that relatively unskilled criminals can operate.

The security implications extend beyond Apple. Similar AI-assisted social-engineering services can impersonate banks, Microsoft, Google, telecom providers, government agencies or corporate help desks. Any workflow in which a human can be persuaded to reveal a reusable secret can potentially be automated.

This suggests a broader defensive principle: security systems should increasingly minimise the number of human-disclosable secrets. Passwords, OTPs and recovery codes are useful, but if someone can simply read them aloud to a convincing caller, they remain vulnerable to social engineering. Authentication methods should move toward cryptographic mechanisms that cannot be transferred verbally or replayed on another site.

The economics uncovered by campaigns like this should make organisations rethink assumptions about targeted social engineering. Sophisticated personalised calling was once relatively expensive because it required human labour. AI reduces that cost substantially. Security programs should therefore assume that convincing, multilingual and interactive voice phishing can now be deployed at scale.

The attack is also a reminder that security controls often shift attacker behaviour rather than eliminate attacks. Activation Lock makes stolen iPhones harder to resell, so criminals attack the owner. MFA makes stolen passwords less useful, so criminals request the OTP. Better email filters push attackers toward SMS and phone calls. Effective defence therefore needs to anticipate the next path attackers will choose once the obvious one is blocked.

For individual users, the practical rules remain straightforward: never disclose an Apple Account password, device passcode or 2FA code to anyone claiming to provide support; never authenticate through a link received after a device is stolen; independently verify device status through Find My; keep Activation Lock enabled; and independently contact Apple if support is needed.

If a caller asks for the device passcode, end the call. If they ask for a two-factor authentication code, end the call. If they tell the user to remove the device from Find My, end the call. None of those actions should be necessary to help recover a stolen device.

For organisations, the response should combine mobile-device management, strong identity controls, phishing-resistant authentication, stolen-device procedures, employee awareness, session revocation, threat monitoring and independent help-desk verification.

The broader lesson from AnonyMousKIT is that AI is making social engineering less dependent on human attackers. The attack itself is familiar, but the scale and economics are changing. A synthetic voice can sound professional, know the correct device details, speak the victim’s language and patiently explain why a security code is supposedly required.

None of that proves identity.

The most durable defence is therefore not trying to determine whether the caller sounds real. It is designing authentication and recovery processes so that even a perfectly convincing caller cannot obtain a secret that gives them control.


Cybersecurity researchers have disclosed details of a phishing-as-a-service (PhaaS) platform built to strip Apple's Activation Lock from stolen devices, using rented AI voice agents that call theft victims posing as Apple Support and ask for their device passcode. SOCRadar Threat Research Unit (STRU) said the platform, which it tracks as AnonyMousKIT, is credit-metered and drives lures across

Source: Fake Apple Support AI Calls Target Stolen-Device Owners for Passcodes and 2FA Codes via The Hacker News — published 26 Aug 2026.