AI Apple Support Calls Are Now Helping Thieves Unlock Stolen iPhones
- The Mess: A phishing-as-a-service platform called AnonyMousKIT uses AI voice agents, fake Apple pages, SMS, email and WhatsApp to trick owners of stolen iPhones into handing over their device passcode, Apple Account credentials and live 2FA codes.
- The Damage: Researchers linked the operation to 506 domains and 168 storefront brands, while recovered records showed 200 AI-assisted calls targeting victims, allowing criminals to bypass Activation Lock and resell stolen devices.
- The Fix: Never give Apple Support your device passcode, password or 2FA code, and ignore recovery links sent after a device is lost or stolen.
Your iPhone gets stolen.
A few hours later, someone calls you.
They know the model.
They know the device was reported missing.
They know you’re looking for it.
And the person on the phone sounds like Apple Support.
Except it’s an AI.
That’s AnonyMousKIT, a phishing-as-a-service operation built specifically to solve one problem for iPhone thieves:
Activation Lock.
The Stolen iPhone Is Only Half the Business
Apple’s Activation Lock makes stolen iPhones much harder to resell.
Even after a factory reset, the device remains associated with the owner’s Apple Account.
Without the correct credentials, the thief can’t simply wipe it and sell it as a normal phone.
So AnonyMousKIT attacks the owner instead.
The criminal enters information about the stolen device into the platform.
The service then launches a multi-channel campaign against its legitimate owner.
Email.
SMS.
WhatsApp.
Recorded calls.
AI-generated voice calls.
The objective is always the same:
get the credentials.
The Attack Knows Which iPhone You Lost
This isn’t generic phishing.
The platform can use information associated with the stolen device, including its model and Find My status.
The victim receives a message claiming the iPhone has been found.
A link leads to a fake Apple or Find My page.
The page can display information that makes the story look legitimate.
The victim is then asked for the device passcode.
Next comes the Apple Account.
Then the current two-factor authentication code.
That’s the entire keychain the thief needs.
Then the AI Calls
This is where AnonyMousKIT gets nasty.
Researchers recovered 200 call records and 55 transcripts from an AI voice platform.
Five voice personas were configured.
Several used the name Alice from Apple Support.
The AI doesn’t simply play a recording.
It follows a conversation.
It asks questions.
It reacts to answers.
It can resend the phishing link if the victim hasn’t received it.
And it keeps pushing until the victim provides the requested information.
179 Calls Went to Brazil
The recovered data shows how cheap automated vishing can become.
Of the 200 recorded calls, 179 targeted Brazilian numbers.
The calls were handled by AI rather than expensive human operators.
That makes the economics very different.
A criminal doesn’t need a call center full of people pretending to be Apple employees.
They need the platform.
The victims provide the rest.
This Is a Criminal SaaS Business
AnonyMousKIT isn’t just a phishing page.
Researchers describe it as a structured criminal service with:
- subscriptions
- credit-based pricing
- reseller storefronts
- customer support
- multiple delivery channels
- automated voice agents
- infrastructure replacement procedures
The operation has been linked to 506 domains and 168 storefront brands.
That’s closer to a software business than a traditional phishing kit.
Just with criminals as the customers.
The Scale Is Bigger Than the Calls
The voice calls are only one part of the system.
Researchers identified thousands of phishing emails and multiple backend systems supporting the operation.
The platform can contact a victim through several channels from the same stolen-device record.
If the email fails, try SMS.
If SMS fails, try WhatsApp.
Then call.
Then let the AI call.
The attacker keeps changing the delivery mechanism while targeting the same person.
The Prize Isn’t Just the iPhone
There is another problem.
A stolen Apple Account can expose far more than the phone itself.
Depending on what the victim has stored in iCloud and Apple Keychain, compromised credentials could expose:
- cloud backups
- saved passwords
- personal data
- work accounts
- authentication information
So the attacker may start with a stolen iPhone and end up with access to the victim’s digital life.
Apple Will Not Ask for This
The most important defensive rule is extremely simple.
Apple Support does not need your password, device passcode or 2FA verification code.
Anyone asking for them is asking for the keys to the account.
It doesn’t matter if they know your iPhone model.
It doesn’t matter if they know the device’s location.
It doesn’t matter if the caller sounds exactly like Apple Support.
And it definitely doesn’t matter if an AI voice tells you the phone has been recovered.
Hang up.
Verify independently.
Bugstoday Opinion
AI voice phishing has finally found a target that makes perfect criminal sense.
Stolen iPhones.
The thief already has the hardware.
The victim already wants it back.
The attacker knows enough information about the device to make the story believable.
Then an AI voice pretends to be Apple Support.
The victim isn’t being asked to click some random Nigerian phishing link.
They’re being told:
“We found your iPhone.”
That’s exactly the message someone desperately wants to hear after losing a phone.
And that’s why this works.
Bugstoday verdict: the next time someone claiming to be Apple Support calls about your missing iPhone, remember one thing — the person who really has your phone doesn’t need your password. The person asking for it probably wants to steal the phone twice.
Today’s Bugs. Tomorrow’s Breaches.




