AI‑Powered Voice Phishing‑as‑a‑Service Harvests iPhone Passcodes and Bypasses Activation Lock
What Happened — Researchers uncovered “AnonyMousKIT,” a phishing‑as‑a‑service platform that uses voice‑AI agents to call iPhone owners, impersonate Apple Support, and solicit device passcodes, Apple‑ID credentials, and 2FA codes. The service has operated since early 2024, handling over 200 recorded calls and supporting a network of 506 domains and 168 reseller storefronts, primarily targeting victims in Brazil.
Why It Matters for Compliance & Audit Readiness
- The attack exploits the human element, directly testing the effectiveness of SOC 2 Access Control policies and Security Awareness Training programs.
- Continuous‑compliance programs must capture evidence that phishing simulations, especially emerging AI‑driven vectors, are regularly performed and that remediation actions are documented.
- Verisq’s Security Awareness Training capability provides a scalable way to embed AI‑phishing scenarios into training, generate audit‑ready evidence, and demonstrate due diligence to auditors.
Who Is Affected — Consumers and enterprises that issue iPhones, mobile‑device resellers, and any organization that manages Apple‑ID credentials for employees or customers.
Recommended Actions
- Incorporate AI‑voice phishing simulations into your security awareness curriculum and track completion as SOC 2 evidence.
- Enforce strict verification steps for Apple‑ID recovery (e.g., out‑of‑band confirmation) and monitor for abnormal activation‑lock bypass attempts.
- Maintain an auditable log of phishing test results and remediation actions to satisfy SOC 2 CC6.1 (Logical Access) and CC6.2 (User Training) controls.
Source: BleepingComputer
Technical Notes
- Attack vector: Phishing via voice‑AI calls (social engineering).
- No public CVE; the threat leverages legitimate Apple‑ID recovery flows and the Find My activation‑lock mechanism.
- Data harvested includes device passcodes, Apple‑ID usernames, passwords, and two‑factor authentication codes.
Source: BleepingComputer