Apple fans deluged with phony password reset requests
ID: f9817959-5bf3-5f67-b5e4-c976ea4a4c99
STIX ID: report--f9817959-5bf3-5f67-b5e4-c976ea4a4c99
Feed Name: The Register (Security)
Apple users are being targeted by a coordinated MFA 'bombing' campaign: attackers send large volumes of iForgot password-reset requests that generate system-level approval notifications, then follow up with spoofed Apple Support phone calls to socially engineer victims into providing one-time reset codes. The campaign leverages harvested personal data (reportedly from a data broker) and may exploit insufficient rate-limiting on Apple's reset flow, increasing the risk of account takeover.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
