Some Apple users are reportedly being targeted by a sophisticated attack, requesting them to hand over their Apple ID credentials over and over again.
According to KrebsonSecurity, the attack starts with unsuspecting Apple device owners getting dozens of system-level messages, prompting them to reset their Apple ID password. If that fails, a person pretending to be an Apple employee will call the victim and try to convince them into handing over their password.
SEE ALSO: Apple confirms dates for WWDC 2024This is exactly what happened to entrepreneur Parth Patel, who described their experience on Twitter/X. First, all of Patel's Apple devices, including their iPhone, Watch, and MacBook, started displaying the "Reset Password" notifications. After Patel clicked "Don't Allow" to more than one hundred requests, the fake Apple Support called, spoofing the caller ID of Apple's official Apple Support line. The fraudster Apple employee actually knew a lot of Patel's real data, including email, address, and phone number, but they got their name wrong, which had confirmed Patel's suspicions that they were under attack.
This Tweet is currently unavailable. It might be loading or has been removed.
While the attack was ultimately unsuccessful in this example, it's easy to imagine it working. The victim might accidentally allow the password reset (mistakes are easy to happen when you have to click on something hundreds of times), or they could fall for the fairly convincing, fake Apple Support call.
Patel's example isn't isolated, either; KrebsonSecurity has details on a very similar attack that happened to a crypto hedge fund owner identified by his first name, Chris, as well as a security researcher identified as Ken. In Chris' example, the attack persisted for several days, and also ended with a fake Apple Support call.
How did the attackers know all the data needed to perform the attack, and how did they manage to send system-level alerts to the victims' phones? According to KrebsonSecurity, the hackers likely had to get a hold of the victim's email address and phone number, associated with their Apple ID. Then they used an Apple ID password reset form, that requires an email or phone number, alongside a CAPTCHA, to send the system-level, password reset prompts. They also likely used a website called PeopleDataLabs to get information on both the victim and Apple employees they impersonated.
But there could also be a bug in Apple's systems, which should in theory be designed not to allow someone to abuse the password reset form and send dozens of requests in a short period of time (Apple did not respond to KrebsonSecurity's request for comment).
It appears that there's no easy or foolproof way to protect oneself from such an attack at this time, save from changing one's Apple ID credentials and tying them to a new number and email. It's hard to tell how widespread this attack is, but Apple users should be vigilant and triple-check the authenticity of any password reset request, even if it appears to come from Apple itself.
For on spammers and scammers, check out Mashable's series Scammed, where we help you navigate a connected world that’s out for your money, your information, or just your attention.
Copyright © 2023 Powered by
Apple users targeted by annoying 'Reset Password' attack-违心之论网
sitemap
文章
32
浏览
18778
获赞
28125
The wildest things from the other Trump
A lot of folks anticipated the indictment of former Donald Trump campaign manager Paul Manafort on MThe power is out at CES 2018, and brands have hilarious responses
CES, the world's largest trade show, brings together the world's innovators, influencers, and enthusEric Schmidt steps down as chairman of Alphabet
One of Google's longest-running executives is stepping away from the tech giant's parent company AlpHoliday card family member is each and everyone one of us
When it comes to family holiday gatherings, you can pretty much expect the same old typical questionApple Park's obsessively designed Visitor Center opens to the public
Steve Jobs' last big project is finally ready for the public -- but you have to go to Cupertino to sFootage of dog being rescued from frozen creek will thaw your ice cold heart
2017 is in dire need of heartwarming tales, so here's one about a dog that fell into a frozen creekSouth Carolina women's basketball team declines White House invite
Too little too late, Trump.The South Carolina women's basketball team, which won its first NCAA natiNetflix is 'exploring the opportunity' to stream on Nintendo Switch
Hold your horses, you Netflix-loving Nintendo Switch players: There's still hope that your favoriteThese screenshots of unread emails will fill you with horror
There are two types of people in this world: those who live at inbox zero, and those whose inboxes aMicrosoft and Johnson Controls announce Cortana thermostat for CES
Hey, remember Microsoft Cortana, the digital assistant who's always at your beck and call? Well, nowBrands have no idea how to deal with being caught in a political firestorm
Coffeemaker wreckage, political pizza purchases, and erratic boycott calls flooded social media thisAustralian MP Tim Wilson proposes to his partner while speaking on marriage equality in parliament
Australia's long road to marriage equality is almost at an end, with the bill to legalise same-sex mChild bride uses Facebook evidence to annul her illegal underage marriage
Thanks to Facebook evidence, an Indian child bride has convinced a court to dissolve her illegal marEllen DeGeneres, Uma Thurman speak out against Roy Moore
Alabama heads to the polls Tuesday, and the Senate race between Democrat Doug Jones and beleagueredThe NSA literally deleted 'trust' and 'honesty' from its core values
The National Security Agency -- which as whistleblower Edward Snowden revealed, hasn't been truthfu