AnonyMous phishing campaign targets iPhone users with fake support calls
Fake Find My pages, Lost Mode contact details and AI voice calls are being used to pressure owners into handing over unlock credentials.

A new phishing operation is using stolen iPhone contact details, spoofed Find My pages and fake support calls to trick owners into revealing the passcode or Apple account credentials needed to unlock a device. The campaign has been active since early 2024, spans hundreds of domains and lists India among its focus markets, making it a relevant warning for Indian iPhone users.
Brand
Apple
Model
Apple support calls
Content Type
news
Launch Status
unknown
Availability
ongoing
Key News
Label
Campaign status
Value
The phishing activity has been active since early 2024 and is still ongoing.
Verification Status
reported
Label
Main tactic
Value
Attackers use fake Find My pages and support-style contact to steal unlock credentials.
Verification Status
reported
Label
Delivery methods
Value
Victims can be contacted by email, SMS, WhatsApp texts and AI-generated phone calls.
Verification Status
reported
Label
Scale
Value
The operation is linked with more than 500 domains and over 150 storefront brands.
Verification Status
reported
Label
India relevance
Value
India is listed among the campaign’s focus markets.
Verification Status
reported
Specification Highlights
Label
Contact channels
Value
Email, SMS, WhatsApp and voice calls
Verification Status
reported
Label
AI call personas
Value
Five
Verification Status
reported
Label
Recorded interactions
Value
55 transcripts
Verification Status
reported
Label
Observed calls
Value
Roughly 200
Verification Status
reported
Label
Infrastructure footprint
Value
More than 500 domains and over 150 storefront brands
Verification Status
reported
Label
Reported cost per call
Value
$0.10
Verification Status
reported
Confirmed Details
- Lost Mode can display the owner’s contact information on a lost iPhone.
- Activation Lock keeps a device tied to the owner’s Apple account after a reset.
- The campaign uses fake support contact to direct victims to spoofed pages.
- The operation has been active since early 2024.
- The observed calls were made through multiple AI personas and scripted transcripts.
Unconfirmed Details
- The supplied evidence does not confirm a public Apple response.
- No India-only victim count is available.
- The exact AI tooling and infrastructure are not fully disclosed.
- The evidence does not say whether specific Indian users have already lost money or access.
Timeline
Date
Early 2024
Event
Earliest known records of the AnonyMousKIT phishing operation appear.
Date
2025-08 to 2026-05
Event
Roughly 200 calls are recorded across multiple AI personas and interaction scripts.
Date
2026-08-26
Event
The campaign is described as ongoing and still under active tracking.
What happened
Security researchers uncovered a phishing operation built to target iPhone owners who have already lost a device. The campaign uses fake Apple support calls, spoofed Find My pages and stolen contact details from Lost Mode to convince victims that their phone has been recovered and that they need to verify their identity before it can be returned.
The key danger is that the scam is designed to look routine and helpful. Victims are contacted through email, SMS, WhatsApp messages or voice calls, then pushed to enter the passcode or Apple account details needed to unlock the device. Once those credentials are handed over, the attackers can remove the protections that normally keep a lost or stolen iPhone tied to its rightful owner.
How the scam works
The attack chain is simple but effective. A stolen or misplaced iPhone can show the owner’s contact details on the lock screen when Lost Mode is enabled. That feature is meant to help a finder return the device, but it also gives criminals a direct way to reach the owner. They can then use a fake support persona to claim the phone has been located and to pressure the victim into acting quickly.
The operation does not rely on just one channel. It can send emails, SMS messages, WhatsApp texts and even AI-generated phone calls. In the calls, the attacker may already know the model of the phone and the IMEI number, which makes the interaction sound credible. The victim is then directed to a spoofed Find My page and asked to confirm ownership. The moment the passcode or account credentials are entered, the attacker has what is needed to unlock the device and move on.
Why Apple’s protections are being abused
Apple’s anti-theft tools are designed to make stolen iPhones harder to resell. Find My can locate a device, make it play a sound, display its position on a map and remotely wipe it. Turning on Find My also enables Activation Lock, which keeps the phone tied to the owner’s Apple account even after a reset. In normal circumstances, that makes resale much harder for thieves.
Lost Mode adds another safety layer by allowing the owner to display contact details for a good-faith return. That is exactly the feature being turned against users. Instead of helping a finder return a phone, the contact information becomes the starting point for a highly personalised phishing attempt. The scam is effective because it starts with a real loss event, then mixes that with stolen device data and fake support language to lower the victim’s suspicion.
What is known about the scale
The campaign appears to be more than an ad hoc scam. The earliest records linked to the operation go back to early 2024, and since then it has grown into a large criminal setup with more than 500 domains and over 150 storefront brands acting as resellers and affiliates. That points to an organised phishing operation rather than a one-off website or a single fraudulent phone number.
The scale also shows up in the voice activity. Records of roughly 200 calls were identified between August 2025 and May 2026, with five different AI call personas and 55 interaction transcripts. The reported cost of each call was $0.10, which helps explain how cheaply large-scale vishing can be run once the tooling is in place. Most of the observed calls were directed at Brazilian victims, but the activity is described as global in reach and focused on several countries, including India.
Why Indian iPhone users should care
India is one of the countries named as a focus for the campaign, which makes this relevant for Indian iPhone users even if the largest observed volume has been elsewhere. The scam is especially risky for people who rely on Lost Mode after misplacing a phone at work, while travelling, in a cab or in a crowded public place. Once the lock-screen contact details are visible, criminals have a straightforward route to start a convincing conversation.
The broader lesson for Indian buyers is that anti-theft features are still worth using, but they should be treated as part of a defence plan rather than a guarantee of safety. A lost iPhone can still be turned into a phishing opportunity. That means any unexpected call, message or email about a found phone should be treated carefully, especially if it asks you to open a link, share an OTP-like code, enter your passcode, or sign in again to verify ownership.
What iPhone users should do now
If your iPhone goes missing, use only trusted Apple apps, a known browser session, or a device you control to check Find My. Do not trust a phone number, recovery link or call-back request that appears in an unsolicited message. A genuine recovery process should not require you to hand over your passcode to a stranger or to sign in through a page that arrived by text or WhatsApp.
Indian users should also keep their Apple account details strong and up to date, because the scam depends on speed, confusion and reused passwords. Use a unique Apple ID password, keep two-factor authentication enabled, and make sure recovery details are current. If a caller claims to be from support, end the call and verify independently through your own device or the official support route you already use.
What remains unknown
There are still important gaps in the public evidence. The supplied material does not show a public response from Apple, and it does not say whether the company has already taken steps against the domains or call infrastructure involved. It is also unclear how many victims successfully entered credentials, or whether Indian users have already been affected in meaningful numbers.
The technical details of the AI voice system are also only partly visible. The operation is described as using multiple personas and scripts, but the exact models, hosting setup and operator structure are not fully disclosed. The campaign appears to be ongoing, so the picture may change as more domains, transcripts and call patterns are discovered.
Final news summary
This campaign is a reminder that modern phishing no longer depends only on bad spelling or generic scam emails. By combining a real device-loss event, Apple-specific terminology, lock-screen contact details and AI-assisted voice calls, the attackers can make a stolen iPhone look as if it has simply been found and returned to the wrong channel.
For Indian iPhone users, the safest takeaway is straightforward: treat every recovery request with suspicion, verify through channels you start yourself, and never hand over the credentials that keep Find My and Activation Lock working. The scam succeeds only when the victim is rushed into trusting the wrong contact path.
FAQs
What is the AnonyMous phishing campaign?
It is a phishing operation that targets iPhone owners by using stolen device contact details, spoofed Find My pages and fake support messages or calls to steal the passcode or Apple account credentials needed to unlock a lost or stolen phone.
Why is Lost Mode being targeted?
Lost Mode can display the owner’s contact information on the lock screen so a finder can return the device. Attackers abuse that feature to contact the owner directly and make the scam feel personal and believable.
How can Indian iPhone users protect themselves?
Use Find My only through trusted devices or sessions, ignore unsolicited recovery links, never share your passcode or Apple ID password, keep two-factor authentication on, and verify any recovery claim through a channel you start yourself.
Should I trust a caller who knows my iPhone model and IMEI?
No. Knowing the model or IMEI does not prove that the caller is genuine. Scammers can use stolen data to sound convincing, so any unexpected support call should still be verified independently.