Scammers Leverage FaceTime Calls to Trick Users into Revealing Banking Credentials
What Happened — Attackers are initiating unsolicited FaceTime video calls that appear to come from “Apple Support” or a bank. During the call they pressure the victim to disclose banking credentials, Apple ID passwords, or one‑time passcodes, and in some cases convince the user to install remote‑access tools. No malware is required; the exploit is purely social engineering combined with the trust users place in real‑time video calls.
Why It Matters for Compliance & Audit Readiness
- SOC 2 CC6 (Logical Access) requires documented controls that prevent unauthorized credential disclosure; a social‑engineering event highlights gaps in user awareness and verification processes.
- Continuous‑compliance programs must capture security‑awareness training evidence and demonstrate that policies are enforced and tested regularly.
- The incident underscores the need for audit‑ready evidence that employees follow documented verification procedures for any request involving sensitive data.
Who Is Affected – Financial services firms, consumer‑technology providers, and any organization whose employees or customers use iOS devices for business communications.
Recommended Actions –
- Review and reinforce your “no‑share‑credentials over unsolicited contact” policy; ensure it is part of your SOC 2 access‑control documentation.
- Conduct targeted security‑awareness training that includes simulated FaceTime‑based phishing scenarios.
- Verify that all devices are running the latest iOS patches and that endpoint protection with real‑time threat detection is deployed.
Technical Notes – The attack vector is a classic phishing/social‑engineering campaign delivered via FaceTime, a legitimate Apple service. No specific CVE is cited; the risk stems from user trust rather than a software flaw. Source: Malwarebytes Labs