Some Apple users are Asian movies Archivesreportedly being targeted by a sophisticated attack, requesting them to hand over their Apple ID credentials over and over again.
According to KrebsonSecurity, the attack starts with unsuspecting Apple device owners getting dozens of system-level messages, prompting them to reset their Apple ID password. If that fails, a person pretending to be an Apple employee will call the victim and try to convince them into handing over their password.
SEE ALSO: Apple confirms dates for WWDC 2024This is exactly what happened to entrepreneur Parth Patel, who described their experience on Twitter/X. First, all of Patel's Apple devices, including their iPhone, Watch, and MacBook, started displaying the "Reset Password" notifications. After Patel clicked "Don't Allow" to more than one hundred requests, the fake Apple Support called, spoofing the caller ID of Apple's official Apple Support line. The fraudster Apple employee actually knew a lot of Patel's real data, including email, address, and phone number, but they got their name wrong, which had confirmed Patel's suspicions that they were under attack.
This Tweet is currently unavailable. It might be loading or has been removed.
While the attack was ultimately unsuccessful in this example, it's easy to imagine it working. The victim might accidentally allow the password reset (mistakes are easy to happen when you have to click on something hundreds of times), or they could fall for the fairly convincing, fake Apple Support call.
Patel's example isn't isolated, either; KrebsonSecurity has details on a very similar attack that happened to a crypto hedge fund owner identified by his first name, Chris, as well as a security researcher identified as Ken. In Chris' example, the attack persisted for several days, and also ended with a fake Apple Support call.
How did the attackers know all the data needed to perform the attack, and how did they manage to send system-level alerts to the victims' phones? According to KrebsonSecurity, the hackers likely had to get a hold of the victim's email address and phone number, associated with their Apple ID. Then they used an Apple ID password reset form, that requires an email or phone number, alongside a CAPTCHA, to send the system-level, password reset prompts. They also likely used a website called PeopleDataLabs to get information on both the victim and Apple employees they impersonated.
But there could also be a bug in Apple's systems, which should in theory be designed not to allow someone to abuse the password reset form and send dozens of requests in a short period of time (Apple did not respond to KrebsonSecurity's request for comment).
It appears that there's no easy or foolproof way to protect oneself from such an attack at this time, save from changing one's Apple ID credentials and tying them to a new number and email. It's hard to tell how widespread this attack is, but Apple users should be vigilant and triple-check the authenticity of any password reset request, even if it appears to come from Apple itself.
For on spammers and scammers, check out Mashable's series Scammed, where we help you navigate a connected world that’s out for your money, your information, or just your attention.
Topics Apple Cybersecurity
Trump claims it's a 'very scary time for young men in America' and... NO IT IS NOTEmma Watson pens moving open letter to Savita Halappanavar, who died after being denied an abortionTwitter reacts to The Ellen Show's last episodeA woman has just won the Nobel Prize in Physics for the first time in 55 yearsPeople are freaking out that Meghan Markle closed her own damn doorPresident Trump toasts the UN with a wine glass full of Diet CokeSamuel L. Jackson responds to viral mashup of the Kavanaugh testimonyEmma Watson pens moving open letter to Savita Halappanavar, who died after being denied an abortionKavanaugh hearing viewers call CEven Fox News admits Kavanaugh hearing is a disaster for Republicans'Lots of luck on his trip to the moon': Biden rips Elon Musk on plan to cut Tesla jobs'Wordle' today: Get the answer, hints for May 30The hearing's over, but Twitter isn't buying Kavanaugh's argumentRobert Mueller spotted at the Apple Store getting tech supportJulian Assange is no longer editorPhotos from Ukraine’s war5 wildest moments from Trump's press conferenceSnitch tagging is ruining TwitterCongrats to Brett Kavanaugh on getting to be angry'Mona Lisa' had a hell of a weekend Best coffee maker deal: Take $100 off the Keurig K Wordle today: The answer and hints for January 28, 2025 Wordle today: The answer and hints for January 26, 2025 Eagles vs. Commanders 2025 livestream: How to watch NFL online Denver Nuggets vs. Chicago Bulls 2025 livestream: Watch NBA online NYT mini crossword answers for January 27, 2025 Best Apple Watch deal: Save $60 on Apple Watch Ultra 2 Chiefs vs. Bills 2025 livestream: Watch NFL Conference Championships online Los Angeles Lakers vs. Golden State Warriors 2025 livestream: Watch NBA online Oklahoma Senator introduces bill to criminalize porn Vancouver Canucks vs. St. Louis Blues 2025 Iivestream: Watch NHL for free Best Hulu deals and bundles: Best streaming deals in January 2025 Dyson Hot+Cool Gen1 HP10 deal: $180 off at Dyson Shop the best Roku deals and save up to 40% Best Samsung TV deal: Save $1,000 on S85D OLED 4K TV at Best Buy Best gaming deal: Save $200 on the Asus Rog Ally Sabalenka vs. Keys 2025 livestream: Watch Australian Open final for free Best robot vacuum deal: Save $440 on iRobot Roomba j7+ Denon Soundbar deal: Save $64, or 26% at Amazon Swifties for Kamala: How Taylor Swift fans are creating a new blueprint for political organizing
1.3307s , 10136.5859375 kb
Copyright © 2025 Powered by 【Asian movies Archives】,Exquisite Information Network