Fake AI‑Powered “Apple Support” Calls Harvest Passcodes & 2FA from Stolen‑Device Owners
What Happened — Researchers uncovered a phishing‑as‑a‑service (PhaaS) platform, dubbed AnonyMousKIT, that rents AI‑generated voice agents to call victims of iPhone theft. The callers impersonate Apple Support and demand the device’s passcode and two‑factor authentication (2FA) codes to bypass Activation Lock.
Why It Matters for Compliance & Audit Readiness
- This scenario is a textbook example of a credential‑compromise attack that SOC 2 CC6.1 (Logical Access Controls) is designed to prevent and evidence.
- Continuous monitoring of access‑control policies and documented security‑awareness training provide the audit trail needed to show due diligence when a social‑engineering incident occurs.
- Verisq’s Security Awareness capability helps organizations embed real‑world phishing simulations and policy enforcement into a continuous‑compliance program, turning a reactive response into proactive evidence.
Who Is Affected — Consumer device owners, enterprise‑issued iPhones, and any organization that permits BYOD or manages Apple devices (e.g., finance, health, education, retail).
Recommended Actions
- Map the incident to SOC 2 CC6.1 and verify that passcode/2FA handling policies are enforced and logged.
- Deploy regular, AI‑driven voice‑phishing simulations and update training to cover “Apple Support” impersonation tactics.
- Implement real‑time alerting on anomalous outbound calls from corporate telephony systems and enforce MFA for any remote‑device unlock procedures.
Source: The Hacker News
Technical Notes
- Attack vector: AI‑generated voice phishing (PhaaS) leveraging stolen‑device owners’ trust in Apple support channels.
- No CVE; the threat relies on social engineering rather than a software flaw.
- Data sought: device passcode, Apple ID password, and 2FA verification codes.