How thieves watch iPhone owners tap their passcodes in public before stealing their phones to lock victims out of accounts, access data, and loot financial apps
4 digit, 6 digit, alphanumeric — regularly! Joe Rossignol / @rsgnl : I've been reporting on Apple for over a decade and I didn't know or long forgot that you can reset an Apple ID password on an iPhone by simply entering the four-digit passcode - no other steps required! Keep your iPhone and passcode very safe. Reyhan Ayas / @reyhan_ayas : @rsgnl I tried all of those, but I was still targeted. You need to understand that people who want to steal can still steal. Joe Rossignol / @rsgnl : I think this report does a great job educating people on the danger of entering your iPhone's passcode in public absent-mindedly. - Use Face ID or Touch ID as much as possible - Hide your passcode with your hands if you can - Consider switching to an alphanumeric passcode https://twitter.com/... Filipe Espósito / @filipeesposito : This (thieves stealing phones to access bank apps) has been a problem for a long time in Brazil. But now that it's affecting people in the US, maybe Apple will care more and do something to change this. Filipe Espósito / @filipeesposito : First of all, there shouldn't even be an option to reset the Apple ID password using the iPhone's PIN code. https://twitter.com/... Joanna Stern / @joannastern : If this has happened to you or a friend, I'd like to hear about it. For months I have been interviewing people and it's clear not enough are talking about it—whether to law enforcement, banks and more. You know where to find me! https://www.wsj.com/... (🧵 7/7)
Context & Ripple Effects
The report identifies the iPhone passcode as a single point of failure: once thieves obtain both the device and the code, they can reset the Apple ID password and take over account-linked data and financial apps. It extends a longer record of attacks aimed at separating iPhones from their owners’ iCloud accounts, including illicit iCloud-unlocking schemes.
Apple’s later Stolen Device Protection beta directly addresses the reported path by limiting sensitive actions away from familiar locations. Related coverage also shows that recovery controls can create their own lockout risk, as users said an optional Recovery Key made it difficult to regain access after theft.
First-order effects
- iPhone owners whose passcodes are observed face immediate account takeover after a device theft: the same code can be used to reset an Apple ID password, block the owner, and reach account-linked data and financial apps.
- Apple faces a security-design problem in which a credential intended to unlock a device also authorizes high-impact account changes.
Second-order effects
- Apple’s later protection feature shifts sensitive actions from passcode-only authorization toward location-aware checks, adding friction precisely when a stolen phone is used outside a familiar location.
- Account-recovery processes become more consequential: the reported theft path and users’ recovery-key lockout complaints show that stronger takeover defenses can also make legitimate recovery harder.
Third-order effects
- If passcode-observation theft remains a recurring attack pattern, mobile-account security will move toward separating routine device unlock from authorization for irreversible identity and financial actions.
- The broader security trade-off is a layered recovery model: reducing the value of a stolen passcode without making victims permanently dependent on credentials they may lose during the same incident.
The trend: Consumer-device security is shifting from treating possession plus a passcode as sufficient proof toward risk-based safeguards for high-impact account actions.