A phishing service running since 2024 uses synthetic voice agents to talk theft victims into reading out the passcode that makes their stolen phone resellable.

 

What happened

Researchers have documented a phishing-as-a-service platform called AnonyMousKIT that automates the retrieval of codes needed to unlock stolen Apple devices, BleepingComputer reported. Active since early 2024, the service supports a wider trade that sells stolen iPhones, harvests Apple Account credentials, and reaches iCloud backups and Keychain, the built-in store holding a user's saved passwords. Investigators mapped 506 domains connected to the platform and 168 separate storefront brands operating as resellers. Campaigns tied to it have run internationally, with a small share of messages reaching government and corporate organizations.

 

Going deeper

The service exists because of a security feature working as designed. Activation Lock switches on automatically when Find My is enabled and ties the handset to its owner's Apple Account, so a stolen phone stays locked to that account even after a factory reset and needs a valid authorization code before anyone can set it up again. Devices that cannot be unlocked get broken down for parts, while unlocked ones sell for considerably more, particularly when the previous owner's data comes with them. AnonyMousKIT pulls the owner's contact details from Lost Mode, the feature that displays a message and phone number on a missing device, then uses them to make contact by email, text, messaging app, or telephone. The approach impersonates Apple and states the device has been found, quoting the correct model and IMEI, the unique serial number identifying a specific handset, which is a detail no ordinary scam would have. Victims are then routed to a counterfeit Find My or Apple page asking for the device passcode, account credentials, and the two-factor authentication code.

 

What was said

A compromised Apple Account "could expose iCloud backups, Keychain passwords, work email, and other corporate information stored on personal or employer-issued Apple devices," researchers warned in findings reported by BleepingComputer. Once the codes are handed over, operators reach the owner's data, wipe the device, remove it from Find My, and sell it.

 

In the know

Investigators recovered records of 200 calls placed to victims between August 2025 and May 2026, along with 55 distinct conversation transcripts handled by a voice AI agent working through five separate personas. One script has the agent introduce itself as "Alice from Apple Support" and tell the victim that someone attempting to unlock the phone brought it into an Apple store, where staff held onto it. The agent then asks the person to confirm ownership by reading out their passcode, before steering them to the phishing page for the rest. Each call cost the operator roughly ten cents, which is the figure that explains why an approach this labor-intensive scales at all.

 

The big picture

A survey of 343 resident physicians published in a peer-reviewed journal found 98.3% used a smartphone during clinical practice while only 4.5% had been given one by their employer, and roughly three-quarters of those using their phones for professional communication rarely used a compliant messaging service. Separate research on hospital device policy found clinicians routinely working around the rules, using consumer messaging apps to share patient photographs and clinical information because patient care takes precedence over data handling in the moment. A phone lost or stolen from that population carries work email, saved credentials for clinical systems, and potentially images and messages containing patient information, none of which appears in any organizational inventory. Healthcare organizations should establish what remote wipe capability they hold over personal devices used for work, and staff should be told that any contact about a lost device claiming to be from a manufacturer is a social engineering attempt until verified through the company's own app or website.

 

FAQs

Does Apple ever call people about a recovered device?

No. Notifications about a device located through Find My appear in the app and through account alerts, not through unsolicited calls or messages requesting a passcode. No legitimate support process asks anyone to read out a device passcode.

 

What does an attacker get from a passcode beyond unlocking the phone?

The device passcode can be used to reset the Apple Account password on the handset itself, which unlocks iCloud backups, stored payment methods, and saved passwords in Keychain. Access extends well past the physical device to every account whose credentials it holds.

 

Should a stolen work-linked phone be treated as a security incident?

Yes. If the device held email, clinical applications, or messages containing patient information, the organization assesses whether protected health information was accessible, and the answer depends on whether the device was encrypted, whether remote wipe succeeded, and how quickly the loss was reported.

 

What is the value of enrolling personal devices in management software?

Mobile device management allows an organization to enforce encryption and passcode requirements, separate work data from personal data, and wipe the work portion remotely without touching the owner's photographs or messages. Clinicians frequently resist enrollment over privacy concerns, which is why explaining that separation matters as much as the technical capability.