/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

How thieves watch iPhone owners tap their passcodes in public before stealing their phones to lock victims out of accounts, access data, and loot financial apps

4 digit, 6 digit, alphanumeric — regularly! Joe Rossignol / @rsgnl : I've been reporting on Apple for over a decade and I didn't know or long forgot that you can reset an Apple ID password on an iPhone by simply entering the four-digit passcode - no other steps required! Keep your iPhone and passcode very safe. Reyhan Ayas / @reyhan_ayas : @rsgnl I tried all of those, but I was still targeted. You need to understand that people who want to steal can still steal. Joe Rossignol / @rsgnl : I think this report does a great job educating people on the danger of entering your iPhone's passcode in public absent-mindedly. - Use Face ID or Touch ID as much as possible - Hide your passcode with your hands if you can - Consider switching to an alphanumeric passcode https://twitter.com/... Filipe Espósito / @filipeesposito : This (thieves stealing phones to access bank apps) has been a problem for a long time in Brazil. But now that it's affecting people in the US, maybe Apple will care more and do something to change this. Filipe Espósito / @filipeesposito : First of all, there shouldn't even be an option to reset the Apple ID password using the iPhone's PIN code. https://twitter.com/... Joanna Stern / @joannastern : If this has happened to you or a friend, I'd like to hear about it. For months I have been interviewing people and it's clear not enough are talking about it—whether to law enforcement, banks and more. You know where to find me! https://www.wsj.com/... (🧵 7/7)

Wall Street Journal

Context & Ripple Effects

The report identifies the iPhone passcode as a single point of failure: once thieves obtain both the device and the code, they can reset the Apple ID password and take over account-linked data and financial apps. It extends a longer record of attacks aimed at separating iPhones from their owners’ iCloud accounts, including illicit iCloud-unlocking schemes.

Apple’s later Stolen Device Protection beta directly addresses the reported path by limiting sensitive actions away from familiar locations. Related coverage also shows that recovery controls can create their own lockout risk, as users said an optional Recovery Key made it difficult to regain access after theft.

First-order effects

  • iPhone owners whose passcodes are observed face immediate account takeover after a device theft: the same code can be used to reset an Apple ID password, block the owner, and reach account-linked data and financial apps.
  • Apple faces a security-design problem in which a credential intended to unlock a device also authorizes high-impact account changes.

Second-order effects

  • Apple’s later protection feature shifts sensitive actions from passcode-only authorization toward location-aware checks, adding friction precisely when a stolen phone is used outside a familiar location.
  • Account-recovery processes become more consequential: the reported theft path and users’ recovery-key lockout complaints show that stronger takeover defenses can also make legitimate recovery harder.

Third-order effects

  • If passcode-observation theft remains a recurring attack pattern, mobile-account security will move toward separating routine device unlock from authorization for irreversible identity and financial actions.
  • The broader security trade-off is a layered recovery model: reducing the value of a stolen passcode without making victims permanently dependent on credentials they may lose during the same incident.

The trend: Consumer-device security is shifting from treating possession plus a passcode as sufficient proof toward risk-based safeguards for high-impact account actions.