Home › Intelligence › Brief
BREACH BRIEF🟠 High ThreatIntel

Fake AI‑Powered Apple Support Calls Harvest Passcodes & 2FA from Stolen‑Device Owners

Researchers identified a phishing‑as‑a‑service platform that uses AI voice agents to impersonate Apple Support and solicit device passcodes and 2FA codes from theft victims. The threat highlights the need for robust SOC 2 access‑control policies and continuous security‑awareness training.

LiveThreat™ Intelligence · 📅 August 26, 2026· 📰 thehackernews.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
2 sector(s)
✅
Actions
3 recommended
📰
Source
thehackernews.com

Fake AI‑Powered “Apple Support” Calls Harvest Passcodes & 2FA from Stolen‑Device Owners

What Happened — Researchers uncovered a phishing‑as‑a‑service (PhaaS) platform, dubbed AnonyMousKIT, that rents AI‑generated voice agents to call victims of iPhone theft. The callers impersonate Apple Support and demand the device’s passcode and two‑factor authentication (2FA) codes to bypass Activation Lock.

Why It Matters for Compliance & Audit Readiness

  • This scenario is a textbook example of a credential‑compromise attack that SOC 2 CC6.1 (Logical Access Controls) is designed to prevent and evidence.
  • Continuous monitoring of access‑control policies and documented security‑awareness training provide the audit trail needed to show due diligence when a social‑engineering incident occurs.
  • Verisq’s Security Awareness capability helps organizations embed real‑world phishing simulations and policy enforcement into a continuous‑compliance program, turning a reactive response into proactive evidence.

Who Is Affected — Consumer device owners, enterprise‑issued iPhones, and any organization that permits BYOD or manages Apple devices (e.g., finance, health, education, retail).

Recommended Actions

  • Map the incident to SOC 2 CC6.1 and verify that passcode/2FA handling policies are enforced and logged.
  • Deploy regular, AI‑driven voice‑phishing simulations and update training to cover “Apple Support” impersonation tactics.
  • Implement real‑time alerting on anomalous outbound calls from corporate telephony systems and enforce MFA for any remote‑device unlock procedures.

Source: The Hacker News

Technical Notes

  • Attack vector: AI‑generated voice phishing (PhaaS) leveraging stolen‑device owners’ trust in Apple support channels.
  • No CVE; the threat relies on social engineering rather than a software flaw.
  • Data sought: device passcode, Apple ID password, and 2FA verification codes.
📰 Original Source
https://thehackernews.com/2026/08/fake-apple-support-ai-calls-target.html ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Security Awareness

Awareness is a control you can evidence too.

Verisq AI Trust Operations records training completion and policy adoption as audit evidence — turning 'we train our staff' into something you can actually prove.

See how Verisq AI Trust Operations covers awareness →