Current:Home > InvestNew cyberattack targets iPhone Apple IDs. Here's how to protect your data. -GrowthInsight
New cyberattack targets iPhone Apple IDs. Here's how to protect your data.
View
Date:2025-04-14 21:49:32
A new cyberattack is targeting iPhone users, with criminals attempting to obtain individuals' Apple IDs in a "phishing" campaign, security software company Symantec said in an alert Monday.
Cyber criminals are sending text messages to iPhone users in the U.S. that appear to be from Apple, but are in fact an attempt at stealing victims' personal credentials.
"Phishing actors continue to target Apple IDs due to their widespread use, which offers access to a vast pool of potential victims," Symantec said. "These credentials are highly valued, providing control over devices, access to personal and financial information, and potential revenue through unauthorized purchases."
Consumers are also more likely to trust communications that appear to come from a trusted brand like Apple, warned Symantec, which is owned by Broadcom, a maker of semiconductors and infrastructure software.
The malicious SMS messages appear to come from Apple and encourage recipients to click a link and sign in to their iCloud accounts. For example, a phishing text could say: "Apple important request iCloud: Visit signin[.]authen-connexion[.]info/icloud to continue using your services." Recipients are also asked to complete a CAPTCHA challenge in order to appear legitimate, before they're directed to a fake iCloud login page.
Such cyberattacks are commonly referred to as "smishing" schemes in which criminals use fake text messages from purportedly reputable organizations, rather than email, to lure people into sharing personal information, such as account passwords and credit card data.
How to protect yourself
Be cautious about opening any text messages that appear to be sent from Apple. Always check the source of the message — if it's from a random phone number, the iPhone maker is almost certainly not the sender. iPhone users should also avoid clicking on links inviting people to access their iCloud account; instead, go to login pages directly.
"If you're suspicious about an unexpected message, call, or request for personal information, such as your email address, phone number, password, security code, or money, it's safer to presume that it's a scam — contact that company directly if you need to," Apple said in a post on avoiding scams.
Apple urges users to always enable two-factor authentication for Apple ID for extra security and to make it harder to access to your account from another device. It is "designed to make sure that you're the only person who can access your account," Apple said.
Apple adds that its own support representatives will never send its users a link to a website and ask them to sign in, or to provide your password, device passcode, or two-factor authentication code.
"If someone claiming to be from Apple asks you for any of the above, they are a scammer engaging in a social engineering attack. Hang up the call or otherwise terminate contact with them," the company said.
The Federal Trade Commission also recommends setting up your computer and mobile phone so that security software is updated automatically.
- In:
- Apple
- iPhone
Megan Cerullo is a New York-based reporter for CBS MoneyWatch covering small business, workplace, health care, consumer spending and personal finance topics. She regularly appears on CBS News 24/7 to discuss her reporting.
veryGood! (32423)
Related
- John Galliano out at Maison Margiela, capping year of fashion designer musical chairs
- Jarren Duran suspended 2 games by Red Sox for shouting homophobic slur at fan who heckled him
- Disney Alum Skai Jackson Arrested for Misdemeanor Spousal Battery After Alleged Fight
- Wisconsin voters to set Senate race and decide on questions limiting the governor’s power
- Daughter of Utah death row inmate navigates complicated dance of grief and healing before execution
- Maryland extends the contract of athletic director Damon Evans through June 2029
- Judge rules against RFK Jr. in fight to be on New York’s ballot, says he is not a state resident
- Massachusetts fugitive wanted for 1989 rapes arrested after 90-minute chase through LA
- Paris Olympics live updates: Quincy Hall wins 400m thriller; USA women's hoops in action
- Detroit Lions RB Jahmyr Gibbs leaves practice with hamstring injury
Ranking
- Family of explorer who died in the Titan sub implosion seeks $50M-plus in wrongful death lawsuit
- Kourtney Kardashian, Blake Lively, and Kate Hudson's Favorite BaubleBar Halloween Earrings Are Back!
- News outlets were leaked insider material from the Trump campaign. They chose not to print it
- Rachael Lillis, 'Pokemon' voice actor for Misty and Jessie, dies at 46
- Mega Millions winning numbers for August 6 drawing: Jackpot climbs to $398 million
- Chicago-area school worker who stole chicken wings during pandemic gets 9 years: Reports
- NYC man charged with hate crime after police say he yelled ‘Free Palestine’ and stabbed a Jewish man
- 3 people killed in fire that destroyed home in small town northeast of Seattle
Recommendation
Meta releases AI model to enhance Metaverse experience
New metal detectors delay students’ first day of school in one South Florida district
Sur La Table Flash Sale: $430 Le Creuset Dutch Oven For $278 & More 65% Off Kitchen Deals Starting at $7
Wisconsin Capitol Police decline to investigate leak of state Supreme Court abortion order
Pressure on a veteran and senator shows what’s next for those who oppose Trump
Pennsylvania man accused of voting in 2 states faces federal charges
3 killed when a train strikes a van crossing tracks in Virginia
Blink Fitness gym chain files for bankruptcy, here's what it means for locations around US