Cybercriminals are using AI-generated voice calls to impersonate Apple Support and convince owners of stolen devices to surrender their passcodes, Apple ID credentials and two-factor authentication codes. The operation is designed to solve one of the biggest problems facing phone thieves: Apple’s Activation Lock makes a stolen iPhone significantly less valuable unless the legitimate owner’s account can be removed.
Researchers at SOCRadar uncovered the operation while investigating AnonyMousKIT, a phishing-as-a-service platform built specifically around stolen Apple devices. Rather than relying on a single phishing email, the service combines email, SMS, WhatsApp, prerecorded calls and AI voice agents into a coordinated social-engineering campaign.
Turning stolen phones into usable devicesActivation Lock ties an Apple device to its owner’s Apple ID through Find My. Even if a thief resets the phone, activating it again generally requires the legitimate account credentials. This dramatically reduces the resale value of stolen devices and has forced criminals to find ways of convincing victims to unlock the phones themselves.
AnonyMousKIT industrializes that process. Criminals enter information about a stolen device and its owner into the platform, which can then generate personalized messages claiming that the missing device has been found. The phishing pages can include the handset’s actual Apple model identifier, Find My status and an animated map showing its reported location, making the interaction considerably more convincing than a generic phishing message.
Victims are gradually asked for increasingly sensitive information: first the four- or six-digit device passcode, then Apple ID credentials and finally a live 2FA code. Obtaining that combination can potentially give the criminals what they need to take control of the account and remove protections from the stolen device.
AI makes vishing cheap enough to automateThe most interesting component is AnonyMousKIT’s use of commercial AI voice technology. SOCRadar recovered 200 call records and 55 transcripts, along with five configured personas used through the commercial voice platform Vapi. The agents impersonated “Alice from Apple Support” and operated in English, Spanish and Portuguese.
During calls, the AI agent asks the victim to verify ownership of the missing device before requesting its passcode. It can repeat the digits back for confirmation and continue the conversation by claiming that someone has attempted to remove Activation Lock at an Apple Store.
The economics are striking. Researchers calculated that the 200 documented AI calls cost the criminals just $19.24 in total—around 9.6 cents per call. Most were directed at Brazilian numbers, with 179 of the 200 calls targeting the country. Half of the recipients hung up, while others did not answer or remained silent; the research does not establish how many victims ultimately surrendered credentials.
This is where AI materially changes traditional voice phishing. Criminals have used fake support calls for years, but human operators are expensive and difficult to scale. AI allows a single campaign to maintain many simultaneous conversations, operate in multiple languages and repeat the same social-engineering script at negligible cost.
Phishing-as-a-service is becoming a professional businessSOCRadar describes AnonyMousKIT less as a conventional phishing kit and more as a small software company serving criminal customers. It offers credit bundles, subscriptions, published prices, customer support, campaign tracking and procedures for replacing infrastructure when domains are blocked.
Researchers identified 30 installations operating across 42 domains after examining a family of 506 domains associated with the technology. Across those backends, logs recorded 6,092 targeting attempts. The AnonyMousKIT installation itself generated 691 attempts between March and July 2026.
The campaign also demonstrates how specialized cybercrime services are becoming. A phone thief no longer needs to understand phishing infrastructure, build fake Apple websites or personally call victims. Those capabilities can be purchased as a service, turning the physical theft of a phone and the digital compromise of its owner into separate parts of the same criminal supply chain.
Social engineering beats increasingly strong hardware securityThe campaign exists largely because directly defeating modern Apple security has become difficult. More than 92% of the devices identified in the campaign used A12 processors or newer, putting most targets beyond older technical techniques based on the well-known checkm8 exploit.
That changes the attacker’s strategy. If breaking the security protecting the device is too difficult, manipulating the person who possesses the credentials becomes the easier option.
It is a familiar cybersecurity pattern. Strong encryption, Secure Enclave protections and Activation Lock can dramatically increase the technical cost of compromising an iPhone, but they cannot prevent its owner from voluntarily providing a passcode to someone convincingly impersonating Apple.
AI makes that human attack surface easier to exploit at scale.
Apple will never ask for these credentialsThe most important defensive rule is straightforward:Apple Support will not ask users to provide their Apple ID password, device passcode or two-factor authentication code. Apple also warns users that it will not ask them to enter this information into a website or approve an unexpected 2FA prompt as part of a support interaction.
This is particularly important immediately after a phone is stolen. Messages claiming that the device has suddenly been found can be emotionally persuasive because they arrive when the owner is actively trying to recover it. The inclusion of genuine information about the phone or its location should not be treated as proof that the caller represents Apple.
The AnonyMousKIT campaign illustrates a broader evolution in phishing. Generative AI does not need to invent a new technical exploit to make cybercrime more effective. It can instead make an old attack—calling someone and pretending to be technical support—cheap, multilingual, personalized and automated enough to operate at industrial scale.
And in the market for stolen iPhones, that may be more useful to criminals than finding another vulnerability in iOS.
Original report at The Hacker News