A Stolen iPhone Can Call Its Owner Pretending to Be Apple Support

25.08.2026 6 minutes Author: Newsman

Has your iPhone been stolen? Cybercriminals have built an entire AI-powered ecosystem designed to trick owners into unlocking their Apple devices.

According to a new study by SOCRadar, published on Monday, AI-powered phishing has reached a new level. Scammers are now specifically targeting owners of lost or stolen iPhones.

Cybercriminals have created a sophisticated phishing platform featuring an AI agent named Alice. It attempts to trick the rightful owners of stolen iPhones into revealing their device passcodes, allowing criminals to unlock the phones and resell or trade them through third-party marketplaces, including Telegram.

The AnonyMousKIT phishing kit operates under a Phishing-as-a-Service (PhaaS) model and uses artificial intelligence to steal device passcodes. The platform can repeatedly target the same victim through five separate, fully automated channels.

According to the SOCRadar Threat Research Unit (STRU), these channels include email, SMS, WhatsApp, prerecorded voice messages, and conversational AI agents capable of calling victims directly.

How AnonyMousKIT turns a stolen iPhone into a phishing target.

Your stolen iPhone has supposedly been found

A passcode unlocks an iPhone, while Apple’s Activation Lock ties the device to its owner’s Apple Account. This prevents another person from removing the owner’s account from the phone and using it normally.

To resell a stolen device, criminals need to bypass these security measures.

To make the phishing attack as convincing as possible, the scammers first gather information about the specific iPhone. They use the exact device model, its associated number, and even its current status in Find My.

Apple’s Find Me feature tracks the location of connected devices.

All the collected data is uploaded to the phishing kit, which creates a profile of the specific device. The AI then uses this information to target the iPhone owner through the communication channels mentioned above.

In one email uncovered by researchers, the victim was told that their iPhone 15 Plus had supposedly been detected near another Apple device in Johannesburg. The message also included a “View Location” button that directed the user to a phishing page.

In another case, the owner received a message on Telegram:

“Your lost iPhone 14 has appeared online. Its location has been identified.”

Fake messages used to lure owners of stolen iPhones.

According to SOCRadar, AnonyMousKIT alone was used in 691 phishing email attempts. Researchers recorded more than 6,000 such emails across related versions of the kit, including messages sent to government, educational, and corporate addresses.

The platform’s exposed logs also revealed thousands of attempted attacks through WhatsApp and records of 200 AI-powered voice calls.

Around 90% of these AI calls targeted users in Brazil. Two additional calls were made to numbers in Chile and one to either the United States or Canada, while the countries associated with 18 numbers could not be determined from their dialing codes.

Meet Alice from Apple Support

AnonyMousKIT takes the scam to a new level by using commercial conversational AI agents. They call victims directly and impersonate Apple employees.

One of these personas is Alice from Apple Support. The uncovered data indicates that Alice and other AI agents were actively used to call the owners of stolen devices.

Along with records of 200 calls, SOCRadar researchers obtained information directly from the platform about five separate AI personas, 55 call transcripts, and the internal instructions used to operate the voice agents.

Alice was programmed to verify the identity of the stolen device’s owner and inform them of an alleged attempt to disable Activation Lock. During the call, the AI agent asks for the iPhone’s four- or six-digit passcode and sometimes a two-factor authentication code. Alice ultimately directs the victim to a phishing link.

“Alice” from Apple Support asks the victim to provide the iPhone passcode during a voice call using artificial intelligence.

In one recovered conversation, the AI agent told the victim that their stolen iPhone 16 Pro Max had supposedly been brought to an Apple Store. According to the scammers’ story, store employees were holding the device after discovering that Lost Mode had been enabled.

The platform, which remains active, likely began operating in September 2025. However, the data indicates that its AI personas had been created several months earlier, in March 2025.

Each AI-agent call cost the developers only around 10 cents. The total cost of all 200 recorded calls was $19.24, making such attacks cheap and suitable for large-scale use.

The voice agent’s name may also contain a cybersecurity Easter egg. In examples used to explain encryption and network communication, the fictional characters Alice and Bob traditionally replace abstract labels such as A and B. They are often joined by Eve, an eavesdropper attempting to intercept their exchange without being detected.

Alice, Bob, and Eve are commonly used to explain secure communication and eavesdropping.

Phishing by subscription

“AnonyMousKIT is best understood not as a conventional phishing kit, but as a small software business with a criminal customer base,” the SOCRadar Threat Research Unit (STRU) said.

The service operates like a conventional subscription platform. A criminal uploads a stolen iPhone’s profile once and then pays to target its owner through different channels until one of the methods succeeds.

AnonyMousKIT resembles legitimate software. Its dashboard allows users to track orders, account balances, successful and blocked attempts, phishing links, and customer activity. Scammers purchase internal credits to access individual features.

SOCRadar researchers were able to examine the operation in such detail because of a basic coding mistake that exposed the platform’s entire backend.

The exposed data revealed a multilayered criminal supply chain involving the platform seller, its developer, buyers, phishing storefront operators, and hundreds of WhatsApp accounts.

Researchers also identified 30 separate backend installations across 42 domains. All of them used the same core codebase.

In addition, three different phishing storefronts were launched at exactly the same second on April 10th, 2026, using the same Gmail accounts. According to SOCRadar, this may indicate that a single buyer operated all three brands.

The AnonyMousKIT platform tracks phishing orders, attempts, and successful attacks.

What iPhone owners should watch out for

SOCRadar warns that a compromised Apple Account could give attackers access to iCloud backups, credentials stored in Keychain, and work-related information kept within the victim’s Apple ecosystem.

If an iPhone has been lost or stolen, owners should be cautious of unexpected emails, SMS messages, WhatsApp messages, and phone calls claiming that the device has been found. Messages containing links to check the phone’s location or arrange its return are particularly dangerous.

“No legitimate support service will ask for a device passcode or two-factor authentication code over the phone,” SOCRadar emphasized.

Subscribe
Notify of
0 Коментарі
Oldest
Newest Most Voted
Found an error?
If you find an error, take a screenshot and send it to the bot.