AI Turns Stolen iPhones Into a Phishing Business
A new phishing as a service platform is using AI generated messages and voice calls to trick stolen iPhone owners into surrendering Apple credentials and two factor authentication codes. Researchers...
A new phishing as a service platform is using AI generated messages and voice calls to trick stolen iPhone owners into surrendering Apple credentials and two factor authentication codes. Researchers say the operation has expanded across hundreds of domains, showing how easily cybercrime is being packaged for less sophisticated criminals.
A new platform called AnonyMousKIT is turning stolen iPhones into an opportunity for account theft, using artificial intelligence, phishing and automated communications to trick owners into handing over the credentials needed to remove Apple’s Activation Lock, according to third party reporting by Cyber Security News, citing research from SOCRadar.
The platform reportedly combines email, SMS, WhatsApp, recorded calls and AI generated voice calls. Attackers can use information about a stolen device, including its model and Find My status, to create messages that appear connected to the victim’s missing phone.
The scale is notable. SOCRadar linked the operation’s code to 506 domains and 168 storefront brands, suggesting a wider reseller ecosystem rather than a single phishing operation. Researchers also identified 603 of 691 recorded email attempts reaching inboxes between March and July 2026.
The platform reportedly asks victims for their Apple ID credentials, device passcode and a current six-digit two factor authentication code. AI generated calls impersonating Apple Support are then used to make the scam appear more convincing.
Researchers recorded 200 AI generated calls, with 179 directed at Brazilian numbers. The operation reportedly had multiple backend installations and rotating infrastructure, making conventional domain blocking less reliable.
Compliance Analysis
The compliance risk goes well beyond a stolen phone.
Once an Apple ID is compromised, attackers may gain access to cloud backups, saved credentials, email accounts and other connected services. For employees using personal devices for work, the incident can quickly become a data protection, identity management and corporate security issue.
The emergence of phishing as a service also changes the risk calculation. Criminals no longer need advanced technical skills to run convincing campaigns. A platform can package the infrastructure, messaging and victim management into a service.
For businesses, that means employee awareness alone is not enough. Strong authentication, device management, privileged access controls and rapid incident response have to work together.
The most important lesson is simple: AI is making social engineering more believable, but weak identity controls are what allow the attack to become useful.
Compliance Takeaway: Organisations should treat compromised personal devices and credentials as potential corporate security incidents where employees use them for work. Authentication controls, device management, phishing detection and rapid account recovery need to be tested before an attacker does it for them.



No Comment! Be the first one.