/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

A scammer details how voice phishing groups are abusing Apple's support line to generate “account confirmation” message prompts from Apple to their customers

Besieged by scammers seeking to phish user accounts over the telephone, Apple and Google frequently caution … Bluesky: @crowslabyrinth.com , @lilithsaintcrow.com , @metacurity.com , @kryton3298 , @its-tom-williams , @mxannelise , and @schul.dev Mastodon: @j12t@j12t.social , @briankrebs@infosec.exchange , and @technotenshi@infosec.exchange Bluesky: @crowslabyrinth.com : TL;DR  —  If you get notifications on your Apple devices about password resets and you suddenly get a call by Apple Support to ‘help you out’: hang up.  —  Read the full story below.  It's worth checking out.  [embedded post] Lili Saintcrow / @lilithsaintcrow.com : “In essence, the voice phishers are using an automated Apple phone support line to send notifications from Apple and to trick people into thinking they're really talking with Apple.” Cynthia Brumfield / @metacurity.com : This is an incredible piece from Brian Krebs that outlines an elaborate voice phishing attack.  I'm so cynical but I could see myself falling for it.  —  krebsonsecurity.com/2025/01/a- da... Dale Ryder / @kryton3298 : KrebsOnSecurity recently told the saga of a cryptocurrency investor named Tony who was robbed of more than $4.7 million in an elaborate voice phishing attack.  The crooks appear to have initially contacted him via Google Assistant, an AI-based service that can engage in two-way conversations. Tom Williams / @its-tom-williams : This is wild - #cybersecurity journo Brian Krebs has published a recording of what appears to be musician Charlie Puth having his Apple account accessed in a phishing attack.  —  He can be heard speaking with scammers and confirming his name.  —  Full story here: krebsonsecurity.com/2025/01/a- da... Annelise / @mxannelise : More news you can use (and hopefully will never have to) about an elaborate phishing scheme involving impersonation of Google or Apple security personnel krebsonsecurity.com/2025/01/a- da... David M. Schulman / @schul.dev : i wouldn't call it extremely sophisticated, but this is an extremely well-coordinated crypto phone phishing scheme.  moral of the story: if you get a call pressing you to take an action, hang up and call the company directly.  even @mcuban.bsky.social fell for this  —  krebsonsecurity.com/2025/01/a- da... Mastodon: Johannes Ernst / @j12t@j12t.social : How sophisticated are phishing scams these days?  More than you might think.  —  https://krebsonsecurity.com/ ... BrianKrebs / @briankrebs@infosec.exchange : If you're an Apple user and I spoof your phone number in a call to the legitimate Apple Customer Support line (800-275-2273), I can force Apple to send you a system level “Apple Account Confirmation” prompt to all of your signed-in devices. … @technotenshi@infosec.exchange : Phishing groups like “Crypto Chameleon” are abusing Apple and Google systems to trick victims into thinking they're receiving legitimate alerts.  Krebs' deep dive into this evolving threat shows how scammers steal millions through voice phishing, with leaked methods revealing their operations. …

Krebs on Security Brian Krebs

Context & Ripple Effects

This attack adapts a familiar social-engineering pattern: prior research showed how Siri suggestions could lend phishing a veneer of familiarity, while fraud operations have also used bots to capture authentication codes at scale through SMS-based 2FA theft.

What changes here is the use of a legitimate support workflow to create a device-level prompt, then pairing it with a spoofed support call. That combination narrows the gap between a real security signal and an attacker’s scripted instruction.

First-order effects

  • Apple account holders can receive authentic-looking confirmation prompts initiated by an attacker, making a concurrent spoofed Apple Support call more credible.
  • Apple and Google face immediate pressure to examine support and account-recovery flows that can be triggered with victim identifiers, rather than treating the prompt itself as sufficient evidence of a legitimate interaction.

Second-order effects

  • Support teams may need to add clearer provenance, rate limits, or stronger friction around remotely initiated confirmation and recovery events; those controls can also add burden for legitimate users seeking help.
  • Phishing crews can reuse the playbook across brands whose security notifications, phone channels, and recovery processes can be made to appear coordinated.

Third-order effects

  • The security boundary is shifting from whether a notification is genuine to whether the person or process requesting the next action is genuine—a recurring weakness in authentication-code theft as well as voice phishing.
  • If support-triggered alerts remain easy to weaponize, account security will increasingly depend on binding sensitive recovery actions to stronger proof of personhood rather than to a convincing call and a real-looking prompt.

The trend: Trusted account-security notifications are becoming attack surfaces when criminals can trigger them and supply a believable human explanation in parallel.

Discussion

  • @crowslabyrinth.com @crowslabyrinth.com on bluesky
    TL;DR  —  If you get notifications on your Apple devices about password resets and you suddenly get a call by Apple Support to ‘help you out’: hang up.  —  Read the full story below.  It's worth checking out.  [embedded post]
  • @lilithsaintcrow.com Lili Saintcrow on bluesky
    “In essence, the voice phishers are using an automated Apple phone support line to send notifications from Apple and to trick people into thinking they're really talking with Apple.”
  • @metacurity.com Cynthia Brumfield on bluesky
    This is an incredible piece from Brian Krebs that outlines an elaborate voice phishing attack.  I'm so cynical but I could see myself falling for it.  —  krebsonsecurity.com/2025/01/a- da...
  • @kryton3298 Dale Ryder on bluesky
    KrebsOnSecurity recently told the saga of a cryptocurrency investor named Tony who was robbed of more than $4.7 million in an elaborate voice phishing attack.  The crooks appear to have initially contacted him via Google Assistant, an AI-based service that can engage in two-way c…
  • @its-tom-williams Tom Williams on bluesky
    This is wild - #cybersecurity journo Brian Krebs has published a recording of what appears to be musician Charlie Puth having his Apple account accessed in a phishing attack.  —  He can be heard speaking with scammers and confirming his name.  —  Full story here: krebsonsecurity.…
  • @mxannelise Annelise on bluesky
    More news you can use (and hopefully will never have to) about an elaborate phishing scheme involving impersonation of Google or Apple security personnel krebsonsecurity.com/2025/01/a- da...
  • @schul.dev David M. Schulman on bluesky
    i wouldn't call it extremely sophisticated, but this is an extremely well-coordinated crypto phone phishing scheme.  moral of the story: if you get a call pressing you to take an action, hang up and call the company directly.  even @mcuban.bsky.social fell for this  —  krebsonsec…