AI‑Powered Voice Phishing‑as‑a‑Service Harvests iPhone Passcodes to Bypass Activation Lock
What Happened — Researchers at SOCRadar uncovered “AnonyMousKIT,” a phishing‑as‑a‑service platform that uses AI‑generated voice calls impersonating Apple Support to trick victims into revealing the four‑ or six‑digit passcode that unlocks an iPhone’s Activation Lock. The service automates the entire workflow, from harvesting device identifiers to delivering multilingual voice‑agent scripts, and has operated across 506 domains and 168 storefront brands since early 2024.
Why It Matters for Compliance & Audit Readiness
- The attack exploits a classic credential‑compromise scenario that SOC 2’s CC6.1 – Logical Access Controls is designed to mitigate and evidence.
- Continuous monitoring of phishing‑resistance training and verification of incident‑response playbooks provides the audit‑ready documentation that regulators expect.
- Verisq’s Security Awareness Training capability helps organizations embed realistic, AI‑driven phishing simulations into a repeatable control‑testing program, delivering defensible evidence for the “Security Awareness” control family.
Who Is Affected — Consumers of Apple devices worldwide; enterprises that issue iPhones to employees (e.g., finance, healthcare, field services) are at risk of credential leakage that could lead to data exfiltration or device takeover.
Recommended Actions
- Map the incident to SOC 2 CC6.1 and CC6.2 controls; capture training completion records and phishing‑test results as audit evidence.
- Deploy AI‑enhanced phishing simulations that mimic voice‑call scenarios to validate employee response procedures.
- Review and harden incident‑response playbooks for credential‑theft alerts, ensuring rapid revocation of compromised Apple IDs. Source: Help Net Security
Technical Notes
- Attack vector: AI‑generated voice calls (phishing) using “bare relative paths” coding flaw to expose internal logs and reseller rosters.
- No CVE; the vulnerability is a process/implementation error in the PhaaS platform.
- Data types stolen: Apple ID credentials, Activation‑Lock passcodes, device serial/IMEI numbers. Source: Help Net Security