Some Apple users are reportedly being targeted by a sophisticated attack, requesting them to hand over their Apple ID credentials over and over again.
According to KrebsonSecurity, the attack starts with unsuspecting Apple device owners getting dozens of system-level messages, prompting them to reset their Apple ID password. If that fails, a person pretending to be an Apple employee will call the victim and try to convince them into handing over their password.
SEE ALSO: Apple confirms dates for WWDC 2024This is exactly what happened to entrepreneur Parth Patel, who described their experience on Twitter/X. First, all of Patel's Apple devices, including their iPhone, Watch, and MacBook, started displaying the "Reset Password" notifications. After Patel clicked "Don't Allow" to more than one hundred requests, the fake Apple Support called, spoofing the caller ID of Apple's official Apple Support line. The fraudster Apple employee actually knew a lot of Patel's real data, including email, address, and phone number, but they got their name wrong, which had confirmed Patel's suspicions that they were under attack.
This Tweet is currently unavailable. It might be loading or has been removed.
While the attack was ultimately unsuccessful in this example, it's easy to imagine it working. The victim might accidentally allow the password reset (mistakes are easy to happen when you have to click on something hundreds of times), or they could fall for the fairly convincing, fake Apple Support call.
Patel's example isn't isolated, either; KrebsonSecurity has details on a very similar attack that happened to a crypto hedge fund owner identified by his first name, Chris, as well as a security researcher identified as Ken. In Chris' example, the attack persisted for several days, and also ended with a fake Apple Support call.
How did the attackers know all the data needed to perform the attack, and how did they manage to send system-level alerts to the victims' phones? According to KrebsonSecurity, the hackers likely had to get a hold of the victim's email address and phone number, associated with their Apple ID. Then they used an Apple ID password reset form, that requires an email or phone number, alongside a CAPTCHA, to send the system-level, password reset prompts. They also likely used a website called PeopleDataLabs to get information on both the victim and Apple employees they impersonated.
But there could also be a bug in Apple's systems, which should in theory be designed not to allow someone to abuse the password reset form and send dozens of requests in a short period of time (Apple did not respond to KrebsonSecurity's request for comment).
It appears that there's no easy or foolproof way to protect oneself from such an attack at this time, save from changing one's Apple ID credentials and tying them to a new number and email. It's hard to tell how widespread this attack is, but Apple users should be vigilant and triple-check the authenticity of any password reset request, even if it appears to come from Apple itself.
For on spammers and scammers, check out Mashable's series Scammed, where we help you navigate a connected world that’s out for your money, your information, or just your attention.
Copyright © 2023 Powered by
Apple users targeted by annoying 'Reset Password' attack-鼓盆之戚网
sitemap
文章
3648
浏览
785
获赞
5
AOC invited Bobby from 'Queer Eye' to help decorate her office
Queer Eye's master of decor, Bobby Berk, is in Washington, D.C., for a week and he has some big planKanye West's 'Ye Vs. The People' has everyone losing their minds
Oh, did you think Kanye West was done grabbing attention for the week? Pfffttt.Following the releaseMeghan Markle's nephew seems a little salty about not being invited to the royal wedding
Important question: would you go on television just to announce you haven't received an invitation tPrince Harry and Meghan Markle want people to donate to charity rather than sending wedding gifts
Kensington Palace have announced that Prince Harry and Meghan Markle would prefer for people to donaTwitter admits it went too far with '5G causes COVID
Even Twitter admits it was too heavy-handed with its misinformation labels for posts about COVID-19,Solange asked Twitter for advice on what to wear to the MET Gala
The Met Gala is Monday night, which means that it's time chastise those who don't stick to the themeThe latest Mercedes car concept is a sleek take on a classic design
Mercedes-Benz's newest concept car is shocking, to say the least.This is the Vision Mercedes SimplexDiamond and Silk get more time in the spotlight thanks to Zuckerberg
Over the past two days, Facebook founder and CEO Mark Zuckerberg has been bombarded with pointed queDyson's V11 Torque Drive is 20 percent more powerful than Cyclone V10
The future of vacuuming is cordless.A year after halting all new designs of its wired stand-up vacuuHow to watch Apple's big iPhone event
It's time for Apple's big iPhone event once again, folks. Tim Cook and friends are all set to grace13 camera tips and tricks every iPhone 11 owner should know
The iPhone 11 and 11 Pro/11 Pro Max are officially here — maybe even in your hands right now aKanye West's 'Ye Vs. The People' has everyone losing their minds
Oh, did you think Kanye West was done grabbing attention for the week? Pfffttt.Following the releaseGoogle Assistant can now use your voice to verify purchases
Making purchases with your voice is convenient, but it's far from secure. Google is attempting to chWoman refuses to snitch on her new buddy: Marvin the 7
As a tried and true Floridian, I can tell you that spotting lizards in areas where most people wouldPrince Harry and Meghan Markle want people to donate to charity rather than sending wedding gifts
Kensington Palace have announced that Prince Harry and Meghan Markle would prefer for people to dona