Blog Main Image
September 1, 2026

The Phishing Call That Is Telling You the Truth

The moment you realise your phone has gone is a particular kind of awful. You check the same pocket four times, then the bag, then the pocket again. A day later a message arrives saying the device has been located. It names the right model, it shows a map with a dot on it, and it asks you to confirm a few details. Almost everything in that message is true, which turns out to be the point.

Researchers at SOCRadar have published an analysis of AnonyMousKIT, a paid phishing platform built for a single job: persuading the owner of a stolen iPhone to hand over the passcode and Apple Account details needed to strip Activation Lock off the handset so it can be sold. It runs lures across email, SMS, WhatsApp and phone calls, and the calls are now placed by an AI voice agent for roughly ten cents each. This matters because the lure is not a lie about a problem the target does not have. It is an accurate description of one they do.

Why unlocking a stolen iPhone is worth this much effort

Activation Lock has been part of iOS since version 7. It switches on automatically when you set up Find My, and it ties the handset to the owner's Apple Account: the account password is required before anyone can turn Find My off, erase the device or reactivate it. A factory reset does not break that link. A thief who cannot supply the credentials is holding a phone worth parts money rather than resale money.

That single control turned phone theft into a two-stage business: take the handset, then get the credentials. Bypassing Activation Lock needs either a technical exploit or the owner's Apple ID, and since the second route runs through social engineering, that is where the market went.

How the attacker already knows so much about your phone

The kit's first step is profiling. Supporting tools resolve a handset's serial number or IMEI to its internal Apple model identifier and its live Find My status, so the operator knows what the device is and whether it is online before a single message goes out. Across the wider family of installations SOCRadar examined, campaign records covered 6,092 phishing emails, with 5,031 target devices showing as Online and 1,035 as Locked. The owner's phone number often comes from the owner: Lost Mode displays a contact message so an honest finder can get in touch, and the platform harvests exactly that.

The messages themselves are not sophisticated. Operators register ordinary Gmail or iCloud addresses such as noreplyapple00000@gmail.com and set the display name to "Apple", "Find My" or "Apple Support", which is all a phone shows on a narrow screen. One backend alone logged 691 send attempts, of which 603 reached inboxes. The email carries the correct model and IMEI, and the landing page shows an interactive map with the device's live Find My status on it. Then it asks, in sequence, for the device passcode, the Apple Account credentials and the two-factor code, streaming each one to the operator's panel and a Telegram webhook as it is typed.

Where the AI voice agent comes in

The most instructive part of the research is the voice channel, because the operator's account with a commercial voice-AI provider was recoverable. SOCRadar retrieved 200 call records placed between August 2025 and May 2026, plus 55 transcripts and five configured personas in English, Spanish and Brazilian Portuguese, all sharing one identity: "Alice Dias, Apple Support". Around 90 percent of the calls went to Brazil, the median call lasted 22 seconds, and the whole set of 200 cost the operator $19.24.

The system prompt reads like a contact centre script, because that is what it is. Alice opens by saying the call is recorded for quality and security purposes. She explains that someone attempting to unlock the device took it into an Apple store, where it was retained. She asks the target to confirm ownership by reading out the four or six digit passcode, repeats it back to check, confirms the SMS has arrived and pauses to resend it if not, then walks them through the page.

A criminal who speaks no Portuguese can now run a fluent Portuguese vishing call. That is the shift worth noting. The barrier used to be a convincing human being on the phone, and it is now a hosted service billed by the minute. We have written before about synthetic voice used against finance teams; this is the same capability sold at the bottom of the market.

Diagram showing a central stolen device profile feeding five phishing channels (email, SMS, WhatsApp, recorded voice and an AI voice agent) that all converge on a single capture page taking the passcode, Apple Account credentials and two-factor code.

One device profile drives every channel, and every channel lands on the same three-step capture page.

Nor is this one operator. Pivoting on a hash of the shared admin library, SOCRadar linked 1,416 archived captures to 506 domains and 168 storefront brand names, with the codebase first seen in February 2024. Those storefronts are resellers running one piece of software, which is why the same page keeps reappearing under new branding.

The bit that makes it hard

Most phishing advice asks the reader to find the falsehood. Check the sender, check the address bar, ask whether the story holds up. Run that process against one of these messages and it passes. The model is right, the IMEI is right, the map is right, and the phone genuinely is missing.

Only one element is false, the identity of whoever is contacting you, and it is the one thing a worried owner cannot test from inside the conversation. Apple's own guidance closes that gap with a flat statement worth memorising: Apple will never contact you to say that your iPhone or iPad has been found. The same page tells you not to enter contact details when you mark a stolen device as lost, because a thief can use them for social engineering, and not to remove the device from Find My, because that strips Activation Lock and does the attacker's work for them.

Why this reaches your organisation

It reads like a consumer scam, and mostly it is. But SOCRadar found that 9.3 percent of the traffic from the AnonyMousKIT backend went to non-consumer domains: 64 sends across 24 organisations, including 27 to South African government addresses and three to a university. The researchers are clear that those people were picked because their device was stolen, not because of their job.

The exposure is the account rather than the handset. An Apple Account under an attacker's control can reach iCloud backups, Keychain entries and work email. A stolen phone is an IT ticket. A stolen phone followed by a persuasive call is an identity incident, and the gap between the two is usually a day or so.

What to do about it

For individuals, the rules are short:

  • Report the theft through Find My at iCloud.com/find and mark the device as lost. Leave out the contact message.
  • Treat any contact claiming the device has been found as fraudulent, however accurate the details.
  • Never read out a passcode, password or verification code. Apple states plainly that it will never ask you to provide these, to enter them into a website, or to approve a two-factor prompt.
  • Change the Apple Account password from a trusted device and review the devices and recovery methods listed on the account.

For organisations, treat a reported device theft as the start of a countdown:

  • Give people one number to ring when a phone goes missing, out of hours included, and make reporting a lost device something nobody hesitates over.
  • On report, wipe or revoke the device through your mobile management platform and reset the credentials that were synced to it, rather than waiting to see whether it turns up.
  • Warn the owner explicitly that a convincing message or call is likely within days. A person who is expecting it is a very different target.
  • Remember that personal devices and personal Apple Accounts hold work material too. They sit outside your policy; the people using them do not.

The people who fall for this are not careless. They are anxious, they have been given accurate information, and they are being helped by someone patient and polite. Anyone can be walked into that. What protects them is knowing, in advance, that the call is coming and that no genuine part of Apple will ever make it.

Key takeaways

  • AnonyMousKIT is a subscription phishing platform aimed at stripping Activation Lock from stolen Apple devices, active in some form since February 2024.
  • Its lures are accurate because they are built from the stolen device itself: model identifier, IMEI and live Find My status.
  • AI voice agents let non-native speakers run fluent vishing calls in three languages for about ten cents a call.
  • Apple will never contact you to say a device has been found, and will never ask for a passcode, password or verification code.
  • A stolen work-connected phone should trigger credential resets and a warning to the owner, alongside the hardware replacement.

Frequently asked questions

Does this only affect iPhones?

The research covers Apple devices, because Activation Lock is what makes the credentials valuable. The pattern is not Apple specific, though. Any theft-deterrent feature that ties hardware to an account creates the same incentive to phish the account holder afterwards.

If the message has the correct IMEI, surely it is genuine?

No. Whoever holds the device can read its serial number and IMEI, and the platform resolves those to the model and Find My status automatically. Accurate hardware details tell you the sender has the phone, which is the opposite of reassuring.

Should I still use Lost Mode?

Yes. Apple's advice is to mark a stolen device as lost as quickly as possible, because that locks it and prevents changes to your account. The advice for a stolen device, as opposed to a mislaid one, is to leave the contact message blank so a thief cannot collect your number.

What if someone has already given away a passcode or code?

Change the Apple Account password immediately from a trusted device, check that two-factor authentication is on, and review the device list and recovery methods for anything unfamiliar. Then tell your IT or security team, since work email and saved credentials may have been reachable from that account.

Phishing Tackle offers the tools businesses need to strengthen their human risk strategies, with multi-platform testing, real-time behavioural insights, and actionable data to keep your organisation ahead of modern cyber threats.

Contact us today to learn how Phishing Tackle can help safeguard your organisation from the growing array of cyber risks.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Scroll To Top Arrow