Home › Intelligence › Brief
BREACH BRIEF🟠 High ThreatIntel

AI‑Powered Voice Phishing‑as‑a‑Service Harvests iPhone Passcodes to Bypass Activation Lock

AnonyMousKIT automates AI‑generated voice calls that impersonate Apple Support to steal iPhone passcodes, enabling thieves to bypass Activation Lock. The service highlights the need for robust SOC 2 access‑control evidence and continuous security‑awareness training.

LiveThreat™ Intelligence · 📅 August 26, 2026· 📰 helpnetsecurity.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
2 sector(s)
✅
Actions
3 recommended
📰
Source
helpnetsecurity.com

AI‑Powered Voice Phishing‑as‑a‑Service Harvests iPhone Passcodes to Bypass Activation Lock

What Happened — Researchers at SOCRadar uncovered “AnonyMousKIT,” a phishing‑as‑a‑service platform that uses AI‑generated voice calls impersonating Apple Support to trick victims into revealing the four‑ or six‑digit passcode that unlocks an iPhone’s Activation Lock. The service automates the entire workflow, from harvesting device identifiers to delivering multilingual voice‑agent scripts, and has operated across 506 domains and 168 storefront brands since early 2024.

Why It Matters for Compliance & Audit Readiness

  • The attack exploits a classic credential‑compromise scenario that SOC 2’s CC6.1 – Logical Access Controls is designed to mitigate and evidence.
  • Continuous monitoring of phishing‑resistance training and verification of incident‑response playbooks provides the audit‑ready documentation that regulators expect.
  • Verisq’s Security Awareness Training capability helps organizations embed realistic, AI‑driven phishing simulations into a repeatable control‑testing program, delivering defensible evidence for the “Security Awareness” control family.

Who Is Affected — Consumers of Apple devices worldwide; enterprises that issue iPhones to employees (e.g., finance, healthcare, field services) are at risk of credential leakage that could lead to data exfiltration or device takeover.

Recommended Actions

  • Map the incident to SOC 2 CC6.1 and CC6.2 controls; capture training completion records and phishing‑test results as audit evidence.
  • Deploy AI‑enhanced phishing simulations that mimic voice‑call scenarios to validate employee response procedures.
  • Review and harden incident‑response playbooks for credential‑theft alerts, ensuring rapid revocation of compromised Apple IDs. Source: Help Net Security

Technical Notes

  • Attack vector: AI‑generated voice calls (phishing) using “bare relative paths” coding flaw to expose internal logs and reseller rosters.
  • No CVE; the vulnerability is a process/implementation error in the PhaaS platform.
  • Data types stolen: Apple ID credentials, Activation‑Lock passcodes, device serial/IMEI numbers. Source: Help Net Security
📰 Original Source
https://www.helpnetsecurity.com/2026/08/26/anonymouskit-phishing-stolen-iphone/ ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Security Awareness

Phishing and social engineering are a people-and-policy problem.

The Verisq AI Trust Operations platform pairs Security Awareness Training with policy adoption tracking, so human-risk controls are documented and audit-ready.

Explore the Verisq AI Trust Operations platform →