Watch out, iPhone fans – a new SMS attack could steal your Apple ID. Here’s how to stay safe

The best iPhones are hugely popular devices, and that makes Apple fans key targets for scammers and fraudsters. Fall victim and you could end up losing your Apple ID (now called an Apple Account), your money and more.
That’s been perfectly illustrated by a new attack that uses SMS messages to steal your Apple ID – and all the data it contains. First noted by Broadcom, the attack involves “a threat actor distributing malicious SMS messages in the United States.” This attack – known as “smishing” – tells recipients that they need to sign in to iCloud to “continue using your services.” It then directs you to a spoof website that imitates the real iCloud site. If users log in, their usernames and passwords are stolen.
Apple is keenly aware of threats to its customers, and the company has just released a slate of tips and advice on how to avoid falling victim to malicious tricksters. In a new post on the company’s support website, Apple explains what social engineering scams are, including phishing SMS messages of the type identified by Broadcom, as well as fraudulent calls masquerading as coming from support staff. The article also contains a wide range of tips and advice on how to avoid falling for scammers’ tricks and losing vital information that could be exploited by bad actors.
If you’re worried about the incident spotted by Broadcom, Apple has a key piece of advice: “If you’re suspicious about an unexpected message, call, or request for personal information, such as your email address, phone number, password, security code, or money, it’s safer to presume that it’s a scam – contact that company directly if you need to.” Erring on the side of caution could be the difference between safety and scam.
How to stay safe
Phishing is a very common tactic that usually involves tricking you into believing that a scammer is a genuine company representative, with the goal of inducing you to hand over important private info. The fraudster could send you an email stating that you need to claim a (fake) prize or might call you pretending to be from Apple support and asking you to hand over your account password, for example.
Usually, social engineering scams are all about two things: trust and urgency. The scammer wants you to believe that they are trustworthy so that you’ll feel comfortable giving them money or vital login details. As well as that, they want you to feel rushed so that you don’t have time to consider if you are being taken advantage of.
With that in mind, Apple’s article contains information on what you can do to protect yourself and how you can report a scam attempt, whether or not it was successful. For instance, Apple says that if a scammer’s email is not sent from the web address of the company it claims to be from, it is probably fraudulent. You can mark suspicious messages and calendar invitations as junk, report scam calls to the FTC, and block unwanted callers from your phone. Apple’s guide also provides a list of official Apple email addresses you can contact to report scams of various types.
Sign up for breaking news, reviews, opinion, top tech deals, and more.
Importantly, if you believe your Apple ID (or any other account) has been compromised, you should change your password as soon as possible to lock the fraudsters out. Secondly, the Have I Been Pwned website lets you enter your email address to check if it’s been compromised, and it can be used hand-in-hand with Apple’s advice. Follow those tips and you’ll stand a greater chance of staying safe and beating the scammers.
You might also like
The best iPhones are hugely popular devices, and that makes Apple fans key targets for scammers and fraudsters. Fall victim and you could end up losing your Apple ID (now called an Apple Account), your money and more. That’s been perfectly illustrated by a new attack that uses SMS messages…
Recent Posts
- Balatro has had its PEGI 18 age rating overturned following appeal: ‘I hope this change will allow developers to create without being unfairly punished’
- Three years later, the Steam Deck has dominated handheld PC gaming
- Google Gemini’s AI coding tool is now free for individual users
- Attention, Kindle owners –today is your last chance to download backups of your ebooks
- Scooby-Doo is a good movie with a bad Rotten Tomatoes score – here’s why you should ignore the critics and watch it before it leaves Netflix
Archives
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- January 2023
- December 2022
- November 2022
- October 2022
- September 2022
- August 2022
- July 2022
- June 2022
- May 2022
- April 2022
- March 2022
- February 2022
- January 2022
- December 2021
- November 2021
- October 2021
- September 2021
- August 2021
- July 2021
- June 2021
- May 2021
- April 2021
- March 2021
- February 2021
- January 2021
- December 2020
- November 2020
- October 2020
- September 2020
- August 2020
- July 2020
- June 2020
- May 2020
- April 2020
- March 2020
- February 2020
- January 2020
- December 2019
- November 2019
- September 2018
- October 2017
- December 2011
- August 2010