Security News

Cybersecurity news aggregator

HIGH Attacks SC Media

Apple account notifications abused for iPhone purchase phishing scams

Threat actors are abusing Apple's legitimate account notification system to embed phishing text within the name fields of a malicious Apple ID, causing Apple's servers to send official-looking emails that contain fraudulent iPhone purchase alerts and a scam phone number. This method bypasses standard email security filters by leveraging trusted infrastructure. There is no patch for this social engineering technique; security teams should educate users to treat unexpected account alerts with extreme caution and to verify any claims through official channels rather than provided contact information.
Read Full Article →

Phishing , Email security Apple account notifications abused for iPhone purchase phishing scams April 20, 2026 Share By SC Staff (Photo by Feline Lim/Getty Images) As reported by Bleeping Computer, threat actors are exploiting a legitimate Apple account notification system to distribute sophisticated phishing scams, embedding fake iPhone purchase alerts within seemingly authentic emails sent from Apple's own servers. This tactic increases the credibility of the scam and improves its chances of bypassing spam filters. The phishing campaign involves creating an Apple ID and strategically placing scam text within the first and last name fields. When the attacker modifies the account's shipping information, Apple sends a notification email that the attacker then distributes to victims. This legitimate alert inadvertently includes the embedded phishing message, which falsely claims an $899 iPhone purchase was made via PayPal and provides a phone number to cancel the transaction. Victims are then prompted to call the number, where scammers attempt to gain remote access or steal financial information by claiming the account is compromised. This method is similar to previous campaigns that abused iCloud Calendar invites. The ability to bypass standard security measures by abusing legitimate infrastructure poses a significant challenge for both users and platform providers. Users should exercise extreme caution with unexpected account alerts, especially those urging immediate action or containing suspicious contact information, and verify any claims through official channels rather than provided links or numbers. Source: Bleeping Computer SC Staff Related Phishing Tycoon 2FA relinquishes crown to similar PhaaS platforms SC Staff April 20, 2026 Last month's takedown of over 300 active domains used by the Tycoon 2FA phishing-as-a-service platform, which was once the most prolific PhaaS kit, has prompted threat actors to transfer to the Mamba 2FA, Sneaky 2FA, and EvilProxy platforms that have since integrated Tycoon 2FA's tools, according to SecurityWeek. AI/ML Google uses Gemini AI to combat malicious ads SC Staff April 17, 2026 In 2025, Google blocked or removed 8.3 billion ads and suspended 24.9 million advertiser accounts, including 602 million ads associated with scams. Phishing ATHR platform automates voice phishing attacks with AI SC Staff April 17, 2026 ATHR, advertised for $4,000 plus a 10% commission, streamlines the entire telephone-oriented attack delivery (TOAD) process, according to Abnormal researchers. Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe Related Terms Bring Your Own Device (BYOD) Eavesdropping Email Spoofing Internet Message Access Protocol (IMAP) Post Office Protocol, Version 3 (POP3) Spam Store-and-Forward You can skip this ad in 5 seconds

Share this article