No Result
View All Result
Global Finances Daily
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers
No Result
View All Result
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers
  • Login
Global Finances Daily
No Result
View All Result
Home Protection

This Surprisingly Convincing Phishing Scam Imitates Apple Support

December 5, 2025
in Protection
0
This Surprisingly Convincing Phishing Scam Imitates Apple Support



You may have a keen eye for spotting scams, but fraudsters are finding new ways to weaponize trusted systems to avoid detection. For example, threat actors are generating real Apple support tickets to phish two-factor authentication (2FA) codes and gain access to iCloud accounts.

The scheme, detailed on Medium by a security researcher and software product manager Eric Moret, shows how social engineering tactics can sow just enough fear and confusion to trick even those who know the red flags. (The money transfer scam that conned a financial advice columnist out of $50,000 is another example.)

How scammers are exploiting Apple’s support system

The Apple support scam started with a text message from Apple containing a 2FA code, followed by verification notifications across devices, indicating that someone was trying to log into Moret’s account. He then received an automated call from Apple with another 2FA code. The text was delivered from a five-digit short code, and the call from a toll-free number, both of which are used by legitimate businesses and not necessarily red flags of a scam.

The next call, however, came from an Atlanta-based 404 phone number. The caller claimed to be from Apple Support, stated that Moret’s account was under attack, and assured him that they were opening up a support ticket. During a follow-up call lasting 25 minutes, Moret received a real Apple Support case confirmation via email (it turns out anyone can create an Apple support ticket in someone else’s name) and was directed to reset his iCloud password.

He was then sent a link via text—from the 404 number this time—to close the ticket. After clicking through, Moret was directed to a phishing website that spoofed a real Apple page (the URL was appeal-apple[dot]com), where he was prompted to enter a 6-digit 2FA code he’d just received via text. An email to his inbox then alerted him that an unknown Mac mini had been used to sign into his iCloud account, which the rep on the phone told him was “expected as part of the security process” and “standard procedure.”

Moret then immediately reset his iCloud password again to kick the unauthorized device off.

It may be easy in hindsight to see the signs: the unsolicited call about an urgent security issue, the 404 number, the phishing link that isn’t a real Apple subdomain, the request for an authentication code. But the Apple support ticket—with a real case number and official emails from apple.com domains—lent just enough credibility, and the multiple 2FA notifications just enough urgency, to work.


What do you think so far?

That’s the problem with social engineering. It manipulates emotions and instincts that are stronger than logic and reason, leading to actions that are not in our interest.

How to stay safe

As always, you should be wary of anyone who calls, texts, or emails you about a security or account issue, even if you have received real security alerts or they have a legitimate case number. Don’t click links, enter credentials, or provide codes when prompted by these unsolicited callers. Don’t accept reassurance from anyone on the phone, no matter how calm and confident they sound.

If you are concerned, you should reach out directly using trusted contact information or open support tickets yourself. Always check URLs and subdomains carefully, as hackers can play tricks to make them look legit.

Also, know that simply having 2FA enabled isn’t enough to keep your accounts secure. Some forms are (obviously) easily phished, so if possible, you should use a multi-factor authentication method like a hardware key or WebAuthn credentials (biometrics and passkeys) rather than codes.



Editorial Team

Editorial Team

Related Posts

Your Instagram Conversations Won’t Be so Private Anymore
Protection

Your Instagram Conversations Won’t Be so Private Anymore

May 8, 2026
These Are The Best Ways to Rid Your Gmail Inbox of Spam
Protection

These Are The Best Ways to Rid Your Gmail Inbox of Spam

May 8, 2026
10 Hacks Every Google Meet User Should Know
Protection

10 Hacks Every Google Meet User Should Know

May 8, 2026
The Fitbit App Is Losing All These Features
Protection

The Fitbit App Is Losing All These Features

May 8, 2026
You Can Get $35 in Google Store Credit If You Preorder the Fitbit Air
Protection

You Can Get $35 in Google Store Credit If You Preorder the Fitbit Air

May 8, 2026
The Shokz OpenRun Pro 2 Are $40 Off Right Now
Protection

The Shokz OpenRun Pro 2 Are $40 Off Right Now

May 8, 2026
Load More
Next Post
Client Challenge

Client Challenge

Popular News

  • Josh Garber

    How to Contact Hilton Customer Service

    0 shares
    Share 0 Tweet 0
  • Authorities Freeze $41 Million in Crypto Tied to BG Wealth Sharing

    0 shares
    Share 0 Tweet 0
  • Chinese naval fleet heads to Strait of Hormuz amid US blockade tensions

    0 shares
    Share 0 Tweet 0
  • Hut 8 stock nears 35% surge after $9.8B AI data center lease

    0 shares
    Share 0 Tweet 0
  • Black Experts Debunk The Vitamin D & Sunscreen Myth

    0 shares
    Share 0 Tweet 0

Latest News

Dying with an HSA can leave a tax bomb for heirs

Dying with an HSA can leave a tax bomb for heirs

May 9, 2026
0

Adamkaz | E+ | Getty ImagesBuilding up a large balance in a health savings account can be a smart financial...

Pentagon's UAP files include Apollo moon photos - 1

Pentagon publishes 162 UAP files including Apollo photos

May 9, 2026
0

The Pentagon released 162 UAP files on May 8, including NASA Apollo moon photos and 1965 astronaut audio Summary The...

The unsinkable U.S. economy cruises on, despite headwinds from the Iran war

The unsinkable U.S. economy cruises on, despite headwinds from the Iran war

May 9, 2026
0

The economy keeps expanding in the face of macro obstacles.

Cardano

Here’s What The Cardano Founder Has To Say About The Widespread Criticism

May 9, 2026
0

Trusted Editorial content, reviewed by leading industry experts and seasoned editors. Ad Disclosure Cardano founder Charles Hoskinson has reacted to...

Global Finances Daily

Welcome to Global Finances Daily, your go-to source for all things finance. Our mission is to provide our readers with valuable information and insights to help them achieve their financial goals and secure their financial future.

Subscribe

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Use
  • Editorial Process

© 2025 All Rights Reserved - Global Finances Daily.

No Result
View All Result
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers

© 2025 All Rights Reserved - Global Finances Daily.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.