Phishing

Real-time vishing exploits Apple Pay

(Credit: ink drop – stock.adobe.com)

Apple users have been targeted with an advanced voice-based phishing intrusion that weaponizes Apple Pay fraud alerts to facilitate real-time login credential and two-factor authentication code compromise, reports Cybernews.

Fake yet highly convincing Apple Pay fraud alert emails warning users of irregular high-value transactions and potential account risks in the event of inaction have been delivered to lure targeted users into contacting a provided phone number that connects to a bogus Apple Billing & Fraud Prevention agent, according to Malwarebytes researchers. After verifying targets' names, phone numbers, owned Apple devices, and other personal information, the agent proceeds to confirm their Apple ID email addresses and verification codes to evade 2FA, while demanding for their bank account and Apple Pay card details.

"At scale, campaigns like this work because Apple's brand carries enormous trust, Apple Pay involves real money, and users have been trained to treat fraud alerts as urgent and to cooperate with 'support' when they're scared," said Malwarebytes, which urged immediate Apple ID password replacements and Wallet transaction monitoring for those who have already been victimized.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds