Apple users have been targeted with an advanced voice-based phishing intrusion that weaponizes Apple Pay fraud alerts to facilitate real-time login credential and two-factor authentication code compromise, reports Cybernews.Fake yet highly convincing Apple Pay fraud alert emails warning users of irregular high-value transactions and potential account risks in the event of inaction have been delivered to lure targeted users into contacting a provided phone number that connects to a bogus Apple Billing & Fraud Prevention agent, according to Malwarebytes researchers. After verifying targets' names, phone numbers, owned Apple devices, and other personal information, the agent proceeds to confirm their Apple ID email addresses and verification codes to evade 2FA, while demanding for their bank account and Apple Pay card details."At scale, campaigns like this work because Apple's brand carries enormous trust, Apple Pay involves real money, and users have been trained to treat fraud alerts as urgent and to cooperate with 'support' when they're scared," said Malwarebytes, which urged immediate Apple ID password replacements and Wallet transaction monitoring for those who have already been victimized.
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds




