HomeIntelligenceBrief
BREACH BRIEF🟠 High ThreatIntel

AI‑Powered Voice Phishing‑as‑a‑Service Harvests iPhone Passcodes and Bypasses Activation Lock

AnonyMousKIT, a newly discovered phishing‑as‑a‑service platform, uses voice‑AI agents to call iPhone owners and steal passcodes, Apple‑ID credentials, and 2FA codes. The service’s scale and low cost make it a potent threat to any organization that manages Apple devices, highlighting the need for robust security awareness training and SOC 2‑aligned access‑control evidence.

LiveThreat™ Intelligence · 📅 August 26, 2026· 📰 bleepingcomputer.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
3 sector(s)
Actions
3 recommended
📰
Source
bleepingcomputer.com

AI‑Powered Voice Phishing‑as‑a‑Service Harvests iPhone Passcodes and Bypasses Activation Lock

What Happened — Researchers uncovered “AnonyMousKIT,” a phishing‑as‑a‑service platform that uses voice‑AI agents to call iPhone owners, impersonate Apple Support, and solicit device passcodes, Apple‑ID credentials, and 2FA codes. The service has operated since early 2024, handling over 200 recorded calls and supporting a network of 506 domains and 168 reseller storefronts, primarily targeting victims in Brazil.

Why It Matters for Compliance & Audit Readiness

  • The attack exploits the human element, directly testing the effectiveness of SOC 2 Access Control policies and Security Awareness Training programs.
  • Continuous‑compliance programs must capture evidence that phishing simulations, especially emerging AI‑driven vectors, are regularly performed and that remediation actions are documented.
  • Verisq’s Security Awareness Training capability provides a scalable way to embed AI‑phishing scenarios into training, generate audit‑ready evidence, and demonstrate due diligence to auditors.

Who Is Affected — Consumers and enterprises that issue iPhones, mobile‑device resellers, and any organization that manages Apple‑ID credentials for employees or customers.

Recommended Actions

  • Incorporate AI‑voice phishing simulations into your security awareness curriculum and track completion as SOC 2 evidence.
  • Enforce strict verification steps for Apple‑ID recovery (e.g., out‑of‑band confirmation) and monitor for abnormal activation‑lock bypass attempts.
  • Maintain an auditable log of phishing test results and remediation actions to satisfy SOC 2 CC6.1 (Logical Access) and CC6.2 (User Training) controls.

Source: BleepingComputer

Technical Notes

  • Attack vector: Phishing via voice‑AI calls (social engineering).
  • No public CVE; the threat leverages legitimate Apple‑ID recovery flows and the Find My activation‑lock mechanism.
  • Data harvested includes device passcodes, Apple‑ID usernames, passwords, and two‑factor authentication codes.

Source: BleepingComputer

📰 Original Source
https://www.bleepingcomputer.com/news/security/anonymouskit-phaas-uses-voice-ai-agents-to-phish-iphone-passcodes/

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Security Awareness

Phishing and social engineering are a people-and-policy problem.

The Verisq AI Trust Operations platform pairs Security Awareness Training with policy adoption tracking, so human-risk controls are documented and audit-ready.

Explore the Verisq AI Trust Operations platform →