Apple IDs on iPhones are the subject of a new hack. Here's how to keep yourself safe.
According to a warning from security software provider Symantec, thieves are aiming to employ a “phishing” effort to gain people’s Apple IDs in a fresh cyberattack that targets iPhone users. This campaign, dubbed “smishing,” sends out false texts purporting to be from Apple in an attempt to obtain the victims’ login credentials.
Cybercriminals have been sending these malicious SMS messages to iPhone users across the U.S. These messages appear to come from Apple but are actually attempts to trick recipients into revealing their Apple ID information. Symantec warns that “phishing actors continue to target Apple IDs due to their widespread use, which offers access to a vast pool of potential victims.” The value of these credentials is significant as they provide control over devices, access to personal and financial information, and potential revenue through unauthorized purchases.

The trust consumers place in communications from reputable brands like Apple is being exploited by these criminals. Symantec, owned by Broadcom, highlights that users are more likely to trust messages that appear to come from a well-known company. The malicious messages prompt recipients to click on a link and sign in to their iCloud accounts. A typical phishing text might read: “Apple important request iCloud: Visit signin[.]authen-connexion[.]info/icloud to continue using your services.” To enhance the illusion of legitimacy, recipients are asked to complete a CAPTCHA challenge before being directed to a fake iCloud login page.
This method of cyberattack is termed “smishing” because it involves using SMS (short message service) to conduct phishing schemes. These attacks aim to lure individuals into providing personal information, such as account passwords and credit card details, by posing as reputable organizations.

Opening any text messages purporting to be from Apple should be done with caution in order to safeguard oneself against these kinds of attacks. Make sure you always check the source of messages; if they appear to be from an unknown phone number, they probably aren’t from Apple. Don’t click on websites that ask you to log into your iCloud account either. Visit the official login pages straight away instead.
Apple provides guidelines on how to avoid scams, stating, “If you’re suspicious about an unexpected message, call, or request for personal information, such as your email address, phone number, password, security code, or money, it’s safer to presume that it’s a scam—contact that company directly if you need to.”
Enabling two-factor authentication for your Apple ID is another crucial step in enhancing security. This feature adds an extra layer of protection, making it more difficult for unauthorized individuals to access your account from another device. Apple emphasizes that this feature is “designed to make sure that you’re the only person who can access your account.”
Apple also reassures users that its support representatives will never send a link to a website asking them to sign in, nor will they request your password, device passcode, or two-factor authentication code. “If someone claiming to be from Apple asks you for any of the above, they are a scammer engaging in a social engineering attack. Hang up the call or otherwise terminate contact with them,” Apple advises.

The Federal Trade Commission (FTC) also recommends setting up your computer and mobile phone to update security software automatically. This ensures you are protected against the latest threats and vulnerabilities.

It’s critical to exercise caution and adhere to security best practices in order to protect your personal information from these sophisticated phishing and smishing attacks that specifically target iPhone users. Use security measures like two-factor authentication to safeguard your accounts and always confirm the legitimacy of correspondence asking for personal information. You may greatly lower your chance of being a victim of these cyberattacks by implementing these safety measures.
If you like the article please follow on THE UBJ.