Some Apple users are Redemption Porn Moviereportedly being targeted by a sophisticated attack, requesting them to hand over their Apple ID credentials over and over again.
According to KrebsonSecurity, the attack starts with unsuspecting Apple device owners getting dozens of system-level messages, prompting them to reset their Apple ID password. If that fails, a person pretending to be an Apple employee will call the victim and try to convince them into handing over their password.
SEE ALSO: Apple confirms dates for WWDC 2024This is exactly what happened to entrepreneur Parth Patel, who described their experience on Twitter/X. First, all of Patel's Apple devices, including their iPhone, Watch, and MacBook, started displaying the "Reset Password" notifications. After Patel clicked "Don't Allow" to more than one hundred requests, the fake Apple Support called, spoofing the caller ID of Apple's official Apple Support line. The fraudster Apple employee actually knew a lot of Patel's real data, including email, address, and phone number, but they got their name wrong, which had confirmed Patel's suspicions that they were under attack.
This Tweet is currently unavailable. It might be loading or has been removed.
While the attack was ultimately unsuccessful in this example, it's easy to imagine it working. The victim might accidentally allow the password reset (mistakes are easy to happen when you have to click on something hundreds of times), or they could fall for the fairly convincing, fake Apple Support call.
Patel's example isn't isolated, either; KrebsonSecurity has details on a very similar attack that happened to a crypto hedge fund owner identified by his first name, Chris, as well as a security researcher identified as Ken. In Chris' example, the attack persisted for several days, and also ended with a fake Apple Support call.
How did the attackers know all the data needed to perform the attack, and how did they manage to send system-level alerts to the victims' phones? According to KrebsonSecurity, the hackers likely had to get a hold of the victim's email address and phone number, associated with their Apple ID. Then they used an Apple ID password reset form, that requires an email or phone number, alongside a CAPTCHA, to send the system-level, password reset prompts. They also likely used a website called PeopleDataLabs to get information on both the victim and Apple employees they impersonated.
But there could also be a bug in Apple's systems, which should in theory be designed not to allow someone to abuse the password reset form and send dozens of requests in a short period of time (Apple did not respond to KrebsonSecurity's request for comment).
It appears that there's no easy or foolproof way to protect oneself from such an attack at this time, save from changing one's Apple ID credentials and tying them to a new number and email. It's hard to tell how widespread this attack is, but Apple users should be vigilant and triple-check the authenticity of any password reset request, even if it appears to come from Apple itself.
For on spammers and scammers, check out Mashable's series Scammed, where we help you navigate a connected world that’s out for your money, your information, or just your attention.
Topics Apple Cybersecurity
Previous:Keeping Hope Alive
Next:Robin Triumphant
Larry David's Super Bowl ad for FTX is dividing peopleToday Is the Final Day for Our Joint Subscription DealThe Misanthrophy of R. S. ThomasMeta AI: The new ChatGPT rival was trained on your sh*tpostsSave 20% sitewide on Tile trackers when you spend $75China Has Ripped Off Anish Kapoor’s “Bean” SculptureThe 20 scariest movies streaming for freeTwitter/X CEO didn't seem to know about Elon Musk's mandatory fee planThe Budding Discipline of Agnotology'Maus' publisher Penguin Random House wants the book removed from the Internet ArchiveMeta Quest 3 is getting a new bodyRemembering Gordon Bishop'Maus' publisher Penguin Random House wants the book removed from the Internet ArchiveChevy resurrected 'The Sopranos' for a Super Bowl commercial. The internet loved it.'Selling the OC' Season 2 is compulsive viewing at its most painfulOur Ongoing Battle with JetlagMeta Quest 3 vs. Quest 2: What are the differences?RIP Pot Roast, the TikTok cat of our dreamsTwitter / X is losing daily active users. CEO Linda Yaccarino confirmed it.Google Doodle for Valentine's Day lets you reunite two lovesick hamsters Facebook teams up with Xiaomi, Qualcomm on new Oculus Go VR headset Tom Hardy's first 'Venom' photo is of a wholesome Eddie Brock Razer unveils Project Linda, a laptop dock for your Razer Phone New Zealand police radio hacked to play NWA's 'F**k tha Police' Guillermo Del Toro loved Natalie Portman's 'all Millie Bobby Brown set to star in 'Elona Holmes Mysteries' movies The cryptocurrency craze is causing a shortage that gamers aren't going to like Omron's Forpheus robot will put your ping pong skills to shame Comic super villain Peter Thiel reportedly submitted a bid for Gawker Snapchat redesign updates in Canada, Australia, U.K., users are angry Snow falls on the usually quite hot Sahara Desert Facebook's newest tested feature pushes local news and events Gillian 'Scully' Anderson is officially leaving 'The X Spyware creator arrested for allegedly creeping on thousands for 13 years Uber and Bell Helicopter show off passenger drone concept at CES 2018 The one iPhone feature I use to calm my raging anxiety Intel CEO addresses Spectre, Meltdown at CES keynote Girl plays ‘Star Wars’ Cantina theme with a pencil, is groundbreaking math genius The Central Hall at CES 2018 just lost power, and people cheered Kodak announces its own cryptocurrency and sees shares rocket
2.8532s , 10132.5703125 kb
Copyright © 2025 Powered by 【Redemption Porn Movie】,Wisdom Convergence Information Network