The Scary New iPhone Scam You NEED to Know About
Brandon Butch
8 min, 8 sec
The video discusses a rampant phishing attack exploiting a vulnerability in Apple's system, providing details on the mechanism of the attack, personal accounts of those affected, and measures for protection.
Summary
- A new phishing attack, known as multi-actor bombing, is hijacking Apple accounts by overwhelming users with authentication requests.
- Scammers spoof Apple support's caller ID and request the one-time code sent to users to gain access to their accounts.
- Users report being unable to use their devices due to the bombardment of notifications and difficulty in stopping the attack even after taking preventive measures.
- To protect oneself, it is advised to remove personal information from people search websites, use unique email addresses, and be wary of unsolicited calls claiming to be from Apple support.
Chapter 1
The video introduces a new phishing attack targeting Apple users and explains its difference from past attacks.
- The phishing attack, known as multi-actor bombing, overwhelms users with authentication requests.
- The alerts users receive during the attack are legitimate notifications from Apple.
Chapter 2
Victims share their experiences with the phishing attack, highlighting its persistence and sophistication.
- A user on Reddit detailed being bombarded with over a hundred notifications, disrupting the use of their Apple devices.
- Scammers spoof Apple support, making it appear as a legitimate call, and gather personal information to gain trust.
- Even after changing devices and account details, users still received password reset requests, indicating the attack's resilience.
Chapter 3
An explanation of how the phishing attack operates, using Apple's password reset system.
- Attackers use 'forgot Apple ID password' page to trigger the attack, which requires the associated email or phone number.
- They bypass the page's CAPTCHA, allowing them to send mass requests and exploit the system's vulnerability.
Chapter 4
The video outlines steps individuals can take to protect themselves from falling victim to the phishing attack.
- Removing personal information from people search websites is crucial for preventing attackers from obtaining contact details.
- Using email aliases and VoIP numbers for Apple accounts can provide an additional layer of security.
- Being aware that Apple support rarely initiates outbound calls can help users avoid falling for fake support calls.
Chapter 5
The video concludes with a summary of the phishing threat and encourages viewers to take proactive security measures.
- The phishing attack targets all Apple users, with public figures at higher risk.
- Secure online practices and awareness of Apple's communication protocols are emphasized.
- Viewers are encouraged to share the video and sign up for a newsletter containing more information.
More Brandon Butch summaries
iOS 17.2 - This isn’t right..
Brandon Butch
A detailed rundown of the latest features in iOS 17.2, upcoming Apple product releases, and news including iMessage on Android and a unique AirTag story.