Skip to main content
Security Products

Apple account change alerts exploited to send phishing emails from legitimate servers

Apple account change alerts exploited to send phishing emails from legitimate servers Image: Primary
Apple account change notifications are being abused to send fake iPhone purchase phishing scams from Apple's own servers, increasing their legitimacy and potentially allowing them to bypass spam filters. The campaign embeds phishing messages within legitimate security alerts sent by Apple when users modify their account information. Attackers create Apple IDs and insert callback phishing text into the first and last name fields, then trigger a shipping information change that generates an automated notification from Apple's infrastructure. The phishing emails appear to come from [email protected] and pass SPF, DKIM, and DMARC authentication checks, indicating they are legitimate emails from Apple's servers. Analysis of email headers shows the messages originate from Apple mail infrastructure at rn2-txn-msbadger01107.apple.com and are relayed through outbound.mr.icloud.com from Apple-owned IP addresses. A sample phishing email shared with BleepingComputer reads: "Dear User 899 USD iPhone Purchase Via Pay-Pal To Cancel 18023530761," followed by notification that account changes were made. The emails are designed to trick recipients into thinking their accounts were used for fraudulent purchases, scaring them into calling the scammer's "support" number. When victims call these numbers, scammers typically try to convince them their accounts have been compromised and may instruct them to install remote access software or provide financial information. In previous callback phishing campaigns, this remote access has been used to steal funds from bank accounts, deploy malware, or steal data. This campaign is similar to previous phishing operations that abused iCloud Calendar invites to send fake purchase notifications through Apple's servers. While Apple has been contacted about the abuse, it remains possible to exploit this notification feature. Security researchers advise users to treat unexpected account alerts claiming purchases or urging them to call support numbers with caution, especially if they did not initiate any recent changes or if the emails contain unusual addresses.
Sources
In this story
Published by Tech & Business, a media brand covering technology and business. This story was sourced from BleepingComputer and reviewed by the T&B editorial agent team.
Back to Newswire
Keep reading
Full wire
Capital
Capital

Anthropic nears $15 billion revolver ahead of IPO filing

Anthropic is set to finalize an expansion of its revolving credit facility to $15 billion, according to people familiar with the matter cited by Bloomberg. Morgan Stanley is leading the process, with Goldman Sachs, JPMorgan Chase ...

Infrastructure
Infrastructure

Firmus commits $300 million for Australia-US cable capacity

Australian AI cloud firm Firmus will invest $300 million to secure up to 150Tbps of dedicated capacity for 25 years on SubCo's planned APX East submarine cable system. The 16-fiber-pair cable, first announced in January, is inten...

AI
AI

G42 explores majority US ownership to protect chip access

Abu Dhabi-based AI company G42 has held exploratory talks about potentially selling a majority stake to American companies, according to people familiar with the matter. The reported discussions are aimed at securing the company's...

Infrastructure
Infrastructure

Meta brings Kuna AI-optimized data center online

Meta's Kuna, Idaho, data center is now serving traffic, according to the company's data-center development vice president. The facility is Meta's second AI-optimized site to come online and represents an overall investment of $1.2...

Infrastructure Policy
Infrastructure Policy

Russia bans crypto mining in Moscow region through 2032

Russia's government has banned cryptocurrency mining and mining-pool participation in Moscow, the surrounding region and parts of Kursk through the end of 2032 under Government Decree No. 936. The measure is intended to reduce pre...

Security
Security

CrowdStrike investigates Falcon privilege-escalation zero-day

CrowdStrike is investigating a reported zero-day exploit, dubbed FalconFlank, that can let an attacker obtain SYSTEM privileges on fully updated Windows 11 and Windows Server systems running its Falcon endpoint platform. The expl...