Apple Devices Being Warned Over New Threat

04/02/2024 07:19 pm

CUPERTINO, Calif.–Credit unions may want to caution their members, as well as employees, who are users of Apple devices and confident they don’t face the kinds of security risks as users of other devices—that they face a significant risk.

Apple

According to KrebsonSecurity, Apple users are being targeted by a sophisticated attack, requesting them to hand over their Apple ID credentials over and over again.

How it Starts

KrebsonSecurity said the attack starts with unsuspecting Apple device owners getting dozens of system-level messages, prompting them to reset their Apple ID password. If that fails, a person pretending to be an Apple employee will call the victim and try to convince them into handing over their password, according to the report.

Those who have been targeted say they are receiving messages on their iPhones, Apple watches and MacBooks telling them they must “reset password.” Some users said they have clicked “Don’t Allow” more than 100 times. They are then contacted by fake Apple Support, which spoofs the caller ID of Apple's official Apple Support line. The fraudsters often know of users’ real data, according to KrebsonSecurity.

How’d They Get the Information?

How did the attackers know all the data needed to perform the attack, and how did they manage to send system-level alerts to the victims' phones? According to KrebsonSecurity, the hackers likely had to get a hold of the victim's email address and phone number, associated with their Apple ID. Then they used an Apple ID password reset form, that requires an email or phone number, alongside a CAPTCHA, to send the system-level, password reset prompts.

They also likely used a website called PeopleDataLabs to get information on both the victim and Apple employees they impersonated, KrebsonSecurity reported.

Comments