HomeIntelligenceBrief
BREACH BRIEF🟠 High ThreatIntel

Scammers Leverage FaceTime Calls to Trick Users into Revealing Banking Credentials

Attackers are making unsolicited FaceTime calls that impersonate Apple Support or banks, coercing victims to disclose banking credentials or install remote‑access tools. The scheme exploits human trust rather than a software flaw, highlighting the need for robust security‑awareness controls in SOC 2 programs.

LiveThreat™ Intelligence · 📅 July 14, 2026· 📰 malwarebytes.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
3 recommended
📰
Source
malwarebytes.com

Scammers Leverage FaceTime Calls to Trick Users into Revealing Banking Credentials

What Happened — Attackers are initiating unsolicited FaceTime video calls that appear to come from “Apple Support” or a bank. During the call they pressure the victim to disclose banking credentials, Apple ID passwords, or one‑time passcodes, and in some cases convince the user to install remote‑access tools. No malware is required; the exploit is purely social engineering combined with the trust users place in real‑time video calls.

Why It Matters for Compliance & Audit Readiness

  • SOC 2 CC6 (Logical Access) requires documented controls that prevent unauthorized credential disclosure; a social‑engineering event highlights gaps in user awareness and verification processes.
  • Continuous‑compliance programs must capture security‑awareness training evidence and demonstrate that policies are enforced and tested regularly.
  • The incident underscores the need for audit‑ready evidence that employees follow documented verification procedures for any request involving sensitive data.

Who Is Affected – Financial services firms, consumer‑technology providers, and any organization whose employees or customers use iOS devices for business communications.

Recommended Actions

  • Review and reinforce your “no‑share‑credentials over unsolicited contact” policy; ensure it is part of your SOC 2 access‑control documentation.
  • Conduct targeted security‑awareness training that includes simulated FaceTime‑based phishing scenarios.
  • Verify that all devices are running the latest iOS patches and that endpoint protection with real‑time threat detection is deployed.

Technical Notes – The attack vector is a classic phishing/social‑engineering campaign delivered via FaceTime, a legitimate Apple service. No specific CVE is cited; the risk stems from user trust rather than a software flaw. Source: Malwarebytes Labs

📰 Original Source
https://www.malwarebytes.com/blog/news/2026/07/warning-scammers-are-using-facetime-to-empty-bank-accounts

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Security Awareness

Phishing and social engineering are a people-and-policy problem.

The Verisq AI Trust Operations platform pairs Security Awareness Training with policy adoption tracking, so human-risk controls are documented and audit-ready.

Explore the Verisq AI Trust Operations platform →